Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

531–540 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#531
This seems like a strange regulation. Companies would simply comply by doing pro forms updates for the sake of updating.

Additionally, the update process itself introduces security vulnerabilities.

An IoT device might have a lifespan of 20 years. Let’s say a company is required to update for a 10 years. For the subsequent 10, that process is nothing more than a vector for malware injection.

The most serious type of vulnerability is an unauthorized, unbounded, write operation.

One of the most secure architectures is “stateless.” That’s where the software is hardcoded into the software. This proposal would outlaw that approach. It’s not for all situations, but it should be seriously considered.

The real solution is to hold companies accountable for vulnerabilities.

I suspect this is better done by the FTC.

Perhaps your time would be better spent fighting DRM on broadcast television, or ensuring cell towers aren’t tracking people, or that phone calls have crypto enabled by default.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#532

As a developer and a consumer, what I'd really like to see is: - Manufacturer voluntary guarantee of 1/3/5 years security updates with an expiration date. - Separation of functionality and security updates. - The ability to "turn off" connectivity and retain full local functionality. - An industry security certification like UL. - A single point way of identifying and validating devices. As it is, I avoid using IoT m…

>-The ability to "turn off" connectivity and retain full local functionality.

>- An industry security certification like UL.

I don't think those should be separated. UL is about safety and, while insecurity is roughly the software equivalent of a device's propensity to suddenly catch fire, reliability is also an important part of safety in all but the most frivolous applications, and local functionality is an important consideration for reliability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#533

What does this mean for DIY hardware? For one I like my ESP32 and Arduino hardware because I can do whatever the heck I want with it. Will I be limited in choices if a bill/regulation is passed so as to make it restrictive on buying IoT hardware that’s not compliant with “security features “?

This will be a completely optional program. And the proposal is that even for participants of the program, they just have to disclose the update period, whatever it may be (could be zero-length).

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#534

Consumers consistently vote with their wallets on this, and based on their behavior, they don't care. They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more. If you want to make a difference, an FCC sticker…

I just don't agree with this at all. I specifically avoid all smart plugs that don't have a UL mark (or European equivalent mark). It's impossible to say that consumers don't care about a specific certification before it exists based on their existing behavior. Consumers _do not have any ability_ to distinguish on this axis at the moment. So, we can't say: "based on their behavior they don't care". They very well mig…

FWIW, I want to claim that I personally care deeply about a lot of this stuff; but, if I go to Home Depot and buy a piece of dumb equipment (such as a run of the mill light bulb or an outlet), it never occurred to me that I might have to check that there is a UL mark on it... I somehow assumed that Home Depot wasn't allowed to sell something that wasn't certified for at least basic electricity safety in the US.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#535
post #461

I have personally found several IoT vulns in everything from Zoom devices to Japanese robot hotels, and I run a security consulting firm. Swooping in with my 2c. Most of the time the engineers making these things -think- they are reasonably secure, but they tend to have little to no infosec experience and are moving too fast with no accountability. Worse, even when there is some accountability such as code review, th…

[deleted]

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#536

As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…

Thanks for this thoughtful feedback. I encourage you to file an official comment, especially regarding end-user control of update timing. Maybe my response here https://news.ycombinator.com/item?id=37394935 addresses some of your other concerns? We'd love to hear your thoughts.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#537

Earlier quoted context omitted.

Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn. Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen. This is literally a national security issue. We currently stifle security research on essential IoT device…

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

Do you believe that your proposal increases the cybersecurity of society as a whole?

You focus a lot on the rights and conveniences of a company, but the rights of a company are not more important that the security of society as a whole.

There are good guys and bad guys out there looking for vulnerabilities. What you propose reduces the number of good guys more than it reduces the number of bad guys (since bad guys are less likely to follow the law). What you propose shifts the balance towards the bad guys and makes it more likely that vulnerabilities will be discovered first by the bad guys. You also propose security through ignorance; security via hoping that nobody notices.

Again, I would really like to hear you assert that your proposal would increase the cybersecurity of society as a whole. I did not clearly see such an assertion in your comment. I want to see an argument focused on the security of society as a whole.

I assert that we currently reduce our national security for the convenience of companies.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#538
post #473

I've dealt with this multiple times, so let me give my perspective. - It is hard for manufacturers to do this with small teams. Mostly because they do not always have good CI/CD or platforms available to keep being on top of vulnerabilities and so on and so forth. - Not all manufacturers write their own software and often contract it out to other experts in the field. This includes firmware and app developers. - If a…

> If a producer goes out of business they should be forced to give out a signed firmware that disables the key checking, then they must put up their source code for any users who wish to build and flash it themselves.

Requiring an organization to do even a small amount of engineering as it is going under is simply not going to work in practice.

IMHO the only possible way for something like this to work is to require vendors to upload buildable firmware source into a third-party escrow system before you can ship devices to customers.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#539
post #319
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…

I have been thinking that something along these lines should apply to most embedded systems, from mobile phones to game consoles to IoT devices. And more, for cases when companies go under: industrial control automation, etc.

However, it's very hard to police: what if the company only provides a header file or so? Or the basic OS but not the UI?

Moreover, what counts as "support"? There have been cases where companies refuse to consider remote code execution a "security issue". What's to prevent token updates that let the company claim a product is supported while it's riddled with holes?

I could also see companies fighting teeth and nails against this if their devices share a common software base. But hey, you have your support incentive right there!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#540
I appreciate you for coming to this form and soliciting input. There are a lot of smart people here and they're likely to have good opinions.

My own opinion, though, is that regulations like this should only be written when no reasonable alternative to them exists and as a last resort. And I think there is still plenty of room and time for industry to come up with its own certification programs, kind of like organic certifications in food. What actions have you taken or do you plan to take to encourage industry to take care of this without being forced to at the point of a gun?

Post reply on HN