There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
61–70 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#62Hurrah, more red tape! Please let customers opt out of your proposed protection, if they want to. (And it sounds like that's already the status quo. So perhaps you could use your time to figure out where you can cut obsolete and cumbersome regulations instead of adding more mandatory bureaucracy that customers evidently don't want enough to pay for voluntarily?) There might be an argument to be made about negative ex…
What's stopping hobby/micro-developers from saying 'Not FCC approved, use at own risk'? I hack on ESP32 devices, I certainly have different expectations as a hobbyist and as a consumer or consultant.
OP is. Or rather, he wants to make it impossible to opt out. At least that's how I interpret these two paragraphs:
> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it. I fought hard for one of these criteria to be the disclosure of how long the product will receive security updates. I hope that, besides arming consumers with better information, the commitments on this label (including the support period) will be legally enforceable in contract and tort lawsuits and under other laws. You can see my full statement here [3].
> But it’s too early to declare victory. Many manufacturers oppose making any commitments about security updates, even voluntary ones. These manufacturers are heavily engaged at the FCC and represented by sophisticated regulatory lawyers. The FCC and White House are not likely to take a strong stand if they only hear the device manufacturer's side of the story.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#63How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.
I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#64They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more.
If you want to make a difference, an FCC sticker won't do it. Consumers will go for the cheaper one without the sticker. You'll have to mandate whatever minimal level of support you want these companies to provide.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#65We’ve seen manufacturers abuse ongoing access to devices to turn off features the device came with at the time of purchase or convert one-time-fee features into subscriptions. One of my concerns is that security updates are strictly defined in a way that prevents this type of regulation from being used as cover for these shenanigans.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#66Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#67How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#68Awesome! Thanks for engaging, where the rubber meets the road! Hopefully, you are also looking into other venues, as well. HN has a great group of folks that represent some of the most cutting-edge tech, but IT runs on Java 8[0]. [0] https://news.ycombinator.com/item?id=19877916
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#69What makes IoT devices special, and warrants carve outs for security / vulnerabilities? I guess I am not surprised there are security issues with these devices, because I think of most of them as coming from small companies, and wonder what the impact would be on the IoT space if only large players can work through more regulation. That said, I can't decide if I am more concerned about my Wyze camera sending data whe…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#70Earlier quoted context omitted.
As far as I remember FCC about 8 years ago didn't liked OpenWRT, and even enforced on TP Link to lock it.
IIRC the main objection was that it could be used to do something with the radio (boost power?) that caused the device to exceed FCC limits for a consumer radio? Something along those lines?
https://wireless.wiki.kernel.org/en/developers/regulatory/st... https://wireless.wiki.kernel.org/en/developers/regulatory
TLDR manufacturers and "serious" companies won't touch anything that could potentially be configured to emit signals that your local government doesn't like. So Linux has to pretend it doesn't allow to do that (even though anyone with 2 braincells can patch it)