Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

451–460 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#451

I think this is a bad idea which will lead to fewer and more expensive devices. I do not want the FCC regulating this. It is much more reasonable to have the market impose some discipline on manufacturers and their level of support. Plenty of consumers would favor less costly, less-supported devices.

Are you in favor of seat belt and airbag requirements? What about the bans on asbestos and lead paint?

  Are you in favor of seat belt and airbag requirements? 
No. The presence of these features is easy to document, and the harms are limited to the person making the $/risk tradeoff.

  What about the bans on asbestos and lead paint?
This is more justifiable. The harm is very far removed from the manufacture (time, place) and it is hard to evaluate whether a given space has these features when e.g renting.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#452
Here's what needs to happen:

The tech industry is not ready for pervasive internet enabled devices that have microphones, cameras, or control heavy machinery. It all needs to be taken out. Aside from the threat to human life (due to malfunctioning vehicle software), we're heading straight for a dystopia where you can get arrested for walking down the street and committing a thought crime because every house will have cameras facing the street hooked into some company like Amazon that will simply be commandeered by the government to "fight crime because if you aren't giving us access to your camera you aren't against crime".

I don't know what legal movements this needs, it has to be something that doesn't backfire. The obvious thing to do is just ban Amazon from selling products like Ring, and remove software and radio communication from home appliances and vehicles. Software in a television shouldn't be legal. It has environmental consequences too not just privacy (which right now is a problem since every TV just scans what your watching and reports back to the company.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#455
post #369

Earlier quoted context omitted.

High-quality comment. Thanks very much! I'll read your filing and think about it. But also, it's a great example of impactful public FCC commentary. I hope your work inspires others to make their mark in the record.

Thank you very much for reading. It was the first, and last time, I ever took place in the public process and political action. https://www.computerworld.com/article/2993112/vint-cerf-and-... We were within months of delivering a massive RFC8290-based fix for wifi performance and we´d been bricking routers left and right... and then got in a whole bunch that we could not modify... due to that proposed regulation... I…

Thanks again -- will review both links (especially the latter!)

The FCC hasn't traditionally been a cybersecurity agency and will, most likely, never really be one; however, we can certainly do things through rules to empower experts, the public, and the agencies with cybersecurity expertise. If that one thing is all you ever did at the FCC, sounds like the public owes you a big debt of gratitude.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#457
post #408

Marco Peraza, Not related to regulation of IoT security updates but since this is an AMA. How did you transition from software engineer into a cybersecurity lawyer?

Hi, the short of it is that I decided to go to law school and then looked for jobs focusing on cybersecurity. If you're interested in jumping over to law, I'm happy to talk about it more. You can find my email in the FCC directory https://www.fcc.gov/about-fcc/finding-people-fcc

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#458

As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…

This is a good point, some IoT devices really can't be designed to be physically serviceable, while still remaining reasonably compact, e.g. those that need very high levels of water resistance, especially saltwater resistance.

And adding any remote update mechanism at all would more then likely decrease overall security.

So there actually should be a counter mandate too, for devices that are impractical to design to be physically serviceable, while meeting certain size/weight/etc. requirements.

To make sure remote update mechanisms, of any kind, are never implemented, unless the manufacturer can guarantee that the update mechanism itself doesn't introduce new flaws.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#460

Earlier quoted context omitted.

I would like to add most of the IoT problem is no patches at all. The firmware they get is usually bog standard with some very minor tweaks out of china somewhere. It is a problem of vendor locked in products where you have to buy a hub to do an update. If there even is an update. If you want to get a good picture of how sideways updating can even be watch the linus tech tips on where he wanted (and has the tech abil…

> I would like to add most of the IoT problem is no patches at all. The firmware they get is usually bog standard with some very minor tweaks out of china somewhere. I was on a team that worked with a firmware vendor, from the US, for a bluetooth chip. We would send in bug reports, they'd send us firmware with fixes. Except it was obvious they did not use source control because they would sometimes base patches off o…

Those sorts of places are fun to interview at. 'So what sort of source control do you use'. You would think everyone does that by this point. An easy slam dunk question to ask and for them to answer. I had one say 'well sometimes we check it into sourcesafe but usually just copy it around the 5 of us on a fileshare' (this was like 4-5 years ago).
Post reply on HN