Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

551–560 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#551

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

> There is an inherent risk of your vulnerabilities being broadcasted somewhere either on purpose or accidentally once that information is collected and organized by the researcher. A legitimate researcher is going to promptly notify you of any vulnerabilities they discover and you as a large organization are going to promptly remediate them. But the trouble isn't that the law might impose a $100 fine on a smug profe…

I once found a vulnerability. I pressed F12 and saw unintended information in the source of a webpage. I just closed the tab, I didn't report it.

Our laws made it risky to do the right thing, so I didn't do the right thing.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#552

Earlier quoted context omitted.

Indeed, this is awesome. Not sure if you're able to comment on this, but is there anything in place to mitigate the risk of automated astroturfed commentary e.g via LLMs in this and other cases? Edit: on the fcc docket specifically, not on HN

> Not sure if you're able to comment on this, but is there anything in place to mitigate the risk of automated astroturfed commentary e.g via LLMs in this and other cases? Look at HN account age, karma, and comment histories.

What about new users?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#553
post #225

For those of you unfamiliar with the specific challenges IoT patching brings, here is a blog post from just last week on one aspect of the topic: http://tomalrichblog.blogspot.com/2023/08/british-cuisine-de... FTA: > I assumed that device manufacturers update the software in their device about every month...he said they do it annually. Those devices are at least _getting_ updates - there is a long tail of devices who…

> there is a startup hidden in the midst of all of this

There are already some companies that do this, but obviously adds to the cost to making these iot devices.

Ex: balena.io, and even AWS iot management does this.

Maybe there’s someway to get the AWS iot gorilla in the room the weigh in?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#554
post #159

Earlier quoted context omitted.

A relatively small group of people won't have an effect, that's why regulation plays an important role.

Perhaps we should respect the wishes of the large rest of the people who are outside that relatively small group?

Ignorance is not a wish. We're talking about users that don't know any better when buying products

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#555
I have two points. First, remember that things like cell phones are also IoT. Laptops are IoT. So make sure that your regulations make sense for all IoT and make sure they apply to all IoT.

Second, I tend to be libertarian. I'd prefer less regulation, not more. So if your concerns are about security update timeframes, I like your idea to treat it more like "Best if used by" labeling. That is, if somebody wants to bake some bread without any preservatives that should be consumed within 24 hours, that's ok. You don't force any lifetime. You just have that lifetime clearly displayed on the packaging.

Some people would prefer bread that "expires" sooner than later. It could become a badge of honor. Likewise, a cell phone or mesh router that "expires" later than sooner could become a badge of honor. It could become a thing. It could be a feature that affects sales.

Keep the regulation as light as possible and be smart about it so that it can still accomplish your desire. Give the labels some standard presentation and prominence like Nutrition Facts. I think it is a great idea.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#556
I'd like if all IOT devices had an offline mode where network access is shut off.

Most companies don't have the skills to make their devices secure. We should have the option to buy devices without network access. Devices that haven't been updated for a year should shutoff their network access automatically.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#557
Here's a few things that I would find useful for IoT device labeling:

1) An indication of whether it supports local control, or requires an internet connection. (I can control my Philips Hue lights from my phone even when the internet is down, as long as they're on the same network. However, my MyQ Garage Door opener can only be controlled from my phone when both the phone and the garage door have an internet connection.)

The reason this relates to security is that devices supporting local control can be completely firewalled, significantly reducing the attack surface.

2) A commitment of how long the device will receive updates.

It should probably be in the form of an end date, or a number of years from the date of purchase, because "5 years of support" currently often means "5 years from when the product was first sold, which was 4 years ago, so you really only get 1 year of support if you buy today".

Separate dates for features and security fixes would be acceptable.

There should probably be some provision for vendors to extend this, since they would generally want to for devices that sell better. They should just be prevented from shortening it without penalties (e.g. a full refund offered to all purchasers.)

3) A clear indication of what happens after the above date passes - does the device continue working? become completely inoperable? loose some features? etc.

4) Some indication of openness, ideally in a way that encourages it. Maybe an "A+" rating requires that the vendor make available everything needed to compile and install a new firmware.

Some differentiation could be made between devices that are open at the time of purchase and devices where the vendor has made a commitment to open it up after the support period ends.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#558

As a developer and a consumer, what I'd really like to see is: - Manufacturer voluntary guarantee of 1/3/5 years security updates with an expiration date. - Separation of functionality and security updates. - The ability to "turn off" connectivity and retain full local functionality. - An industry security certification like UL. - A single point way of identifying and validating devices. As it is, I avoid using IoT m…

>-The ability to "turn off" connectivity and retain full local functionality. >- An industry security certification like UL. I don't think those should be separated. UL is about safety and, while insecurity is roughly the software equivalent of a device's propensity to suddenly catch fire, reliability is also an important part of safety in all but the most frivolous applications, and local functionality is an importa…

Nest thermostat being one example, but myself I'm very happy I have IR remotes to the A/C at home, because I wouldn't want to be unable to turn on the cooling during one of the recent heatwaves over in Europe, just because Internet is down and the control app can't connect to the damn cloud.

(Not that I mind networking in general. Operating those A/C units via Home Assistant app is a glorious and pleasant experience - entirely unlike the vendor's official app.)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#559
My big concern is with devices being obsolete due to the cloud servers going down.

I am all for high security IoT, but only if the requirements don't make it harder to use local-first APIs, and don't add too much cost to these devices, or stop small companies from making open source devices.

In fact, I think I would even prefer that requirements do not apply at all unless the device communicates directly over the public internet, or over proprietary wireless networking, or where the device's failure could cause a safety hazard.

I would not want to see anything get in the way of, say, making a cheap motion sensor that connects to WiFi and allows open access via the already-private WiFi network, or a BLE sensor tag that broadcasts open data.

Not all devices need updates, or encrypted protocols.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#560
EU citizen here, but FCC regulations also apply to me indirectly :) Not sure if I am allowed to comment there.

I echo the many voices here that do not connect their devices to the Internet. Of course, I am in the minority that attaches a great deal of importance to these questions, so my devices either run free software (Tasmota and Esphome are two main ones), or have no Internet access (currently with ZigBee, though I have also used Vlans and separate Wi-Fi access points). The only service accessible from the outside (not firewalled) is HomeAssistant.

I can see manufacturers doing the same, with a direct line to their servers for controlling smart devices, but that's only as good as the manufacturer's cyber security practices, what if they are hacked?

Reducing internet exposure to "gateways" (HomeAssistant) in my case distributes a bit the problem, but also reduces the number of devices that have to be maintained up-to-date, so this may be an interesting avenue, especially if manufacturers are pushed to include a dedicated "IoT VLAN" and SSID in every (Wi-Fi) router that makes it easy for every consumer to adopt a separate network.

To summarize, here are the main elements that could help, in my opinion:

* Ensure that every IoT device (often sensors and actuators) has basic functionality available even when completely offline (including during initial setup).

* Ideally these bits of interaction should take place over a standardized interface (the Matter standard seems to fit this perfectly).

* Maybe consider strongly incentivizing gateways instead of directly connecting IoT devices to the Internet, and hold these to higher security standards?

Post reply on HN