Earlier quoted context omitted.
I've been not-buying IOT trash as hard as I can for decades. But nothing's changing... please tell me how to do this correctly!
Well, lots of people have been not-buying liquorice their whole life, but nothing's changing. The market for liquorice candy is alive and well. Less snarky: if other people still want to buy certain products, manufacturers will provide. But that's not a bad thing. Different folks have different preferences.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
441–450 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#442Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#443There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#444Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#445How is a small business going to be able to pay for this? This will be something that big tech can do but not startups that are bootstrapped.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#446Earlier quoted context omitted.
This is great for hackers but doesn't it make IoT devices incredibly insecure for normal users who wouldn't even know their device has reached end of support?
> doesn't it make IoT devices incredibly insecure for normal users How secure or insecure a device is is unrelated to whether its source code is public. Disclosure: I might be biased on this, as I'm a reverse engineer.
So you'd still need some mechanism to force-update devices in response to vulnerabilities found in open-source end-of-support firmware.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#447How is a small business going to be able to pay for this? This will be something that big tech can do but not startups that are bootstrapped.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#448If security is truly a concern, then all IoT devices connecting to the internet should be routed through a computer that the owner fully controls, which is likely to be running OpenWRT. Any tactics used by IoT vendors to evade traffic monitoring by the computer owner, e.g., discouraging self-signed TLS certificates, should be prohibited.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#449Earlier quoted context omitted.
Thanks, but, that FCC document clearly says it's about a "voluntary labeling program", and, the title of this HN post has the word "regulation" and the text has language like "require" [0]. And the phrase "oppose[...] even voluntary ones", which clearly sounds like someone's proposing non-voluntary stuff. I read your linked HN comment too, but: "legitimate interest in" [1] a thing and actual "authority" to do a thing…
Nathan's post and the proposed rulemaking are both quite explicit that the proposal under comment is a voluntary labeling scheme. Perhaps the intro could be better written to be clearer, but I don't really understand your complaint. There's no bamboozle. From above: "I’ve advocated for the FCC to require device manufacturers to support their devices with security updates for a reasonable amount of time [1]. I can't b…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#450Thank you for engaging with the community in this way. Many years ago, in a fight to preserve individuals ability to flash their own routers, Vint Cerf, and I, and a coalition of many others, filed this report: http://www.taht.net/~d/fcc_saner_software_practices.pdf (retaining the ability to reflash our own routers, allowed my research project to continue, and the resulting algorithm, fq_codel (rfc8290), now runs on…
The push to mandate certificates and other gatekeeping mechanisms that enforce obsolescence for the sake of digital security theatre is ultimately going to benefit corporate bottom lines (especially those of landfill operators), but it will indisputably harm consumers.
I guess I should turn that into a comment and submit it...