> Accordingly, incorporating our modifications, we propose, for purposes of the IoT labeling program, to define an IoT device as: (1) an Internet-connected device capable of intentionally emitting RF energy that has at least one transducer (sensor or actuator) for interacting directly with the physical world, coupled with (2) at least one network interface (e.g., Wi-Fi, Bluetooth) for interfacing with the digital wor…
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
41–50 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#42A mechanism requiring disclosure of how long security updates are available seems like a great step. Another great step would be a guarantee of making the firmware Open Source after no more than a certain amount of time, and having that guarantee known at compile time. Effectively, that means the device will always be supportable.
So, as I work in this space, there needs to be realistic guidelines on this, does a security flaw need to have a CVE ? Do they need to fix every CVE ? What is the timeframe requirement ?
This kind of thing keeps me up at night.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#43But manufacturers shouldn't be allowed to have it both ways, with control post-sale over their customers' hardware AND no responsibility to support it. It should be directly linked by law.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#44Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#45Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#46This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence.
Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many other spheres with your knowledge and time that are closer to home and probably affect you more immediately.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#47Earlier quoted context omitted.
Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.
99% of users don't know their iot devices have firmware nor that it can be updated.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#48Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#49We’ve seen manufacturers abuse ongoing access to devices to turn off features the device came with at the time of purchase or convert one-time-fee features into subscriptions. One of my concerns is that security updates are strictly defined in a way that prevents this type of regulation from being used as cover for these shenanigans.
As such, I look to purchase relativity open devices. But, companies want to keep trying to inject themselves as a middleman, sometimes after the fact. In that case I'm let with a device that becomes e-waste. I don't know what other actions are being taken in regards to subscriptions, but it's a problem here.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#50commitments on this label (including the support period) will be legally enforceable in contract and tort lawsuits and under other laws. When it comes to U.S. laws that touch technology, enforceability is a mess. Spyware, spam, fraud, misleading labels, etc. are already governed by various state and federal laws, yet enforcement efforts are whack-a-mole at best. For IoT devices, having the proposed requirements sound…
I fear it is practically unenforceable, particularly for consumer-grade devices manufactured overseas
Also a good point. The way we handle this for RF interference is to look at distributors and importers, not just manufacturers, but there will probably always be an untrustworthy product tier out there.