Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

651–660 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#651

Earlier quoted context omitted.

In a healthy person, caring should pretty surely imply efforts to research the topic and eventual understanding.

Yes, but not caring could mean either not understanding or understanding but still not caring.

People can very easily understand but still not care. Caring about something is a zero sum competition for headspace. Throw in a newborn baby, a car wreck, a death in the family, and losing your passport, and see how much you care about your smart light bulb being secure.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#652

** THE REAL PROBLEM ** Is companies making shit that has not business connecting to the internet. _THAT_ needs to be regulated. Why does your car need an internet connection? Why does your fridge need an internet connection? What does your robovac need an internet connection? ALL of these items could work just fine with zero internet connect, or a simple LAN connection. If we could regulate that, we'd solve 95% of th…

I love this point. The current IoT free for all is not that productive, good for consumers, national security, or the environment. I would love to buy a mechanically well designed washing machine from 25 years over the smart crap that's out today.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#653
post #566

Earlier quoted context omitted.

This is being proposed as a completely voluntary program. No need to participate in it if you don't want an FCC cybersecurity label on your product.

right, so then people will not buy your product because you don’t have the label and you cannot afford to pay 10K-20K to some testing lab while vc backed startups or big tech can… so it takes away any chance for you as a small guy to compete in the market. no thanks.

I don't see why a small shop can't do this. The testing should be supported by the government. You don't need to be a food scientist to get FDA approval to sell a cookie.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#654

Earlier quoted context omitted.

The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.

This sums up the situation that government regulations don't work. These regulations put us on the path of trusting religious-like in government. We could be working toward push-button simple network segmentation with some kind of default filtering for install by the average home user.

> regulations put us on the path of trusting religious-like in government

We trust in government to set rules and punish rulebreakers. When that is not true, do we enact punishment ourselves? Results would be not pretty.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#655
post #607
post #365

Earlier quoted context omitted.

> doesn't it make IoT devices incredibly insecure for normal users How secure or insecure a device is is unrelated to whether its source code is public. Disclosure: I might be biased on this, as I'm a reverse engineer.

Releasing source code could lower the barrier a bit but the main thing I was calling out is releasing the keys - maybe they could be transferred to a trusted custodian instead.

In certain cases probably yes, but maybe still worth it? If you have the keys you still need to get your maliciously manipulated build on the customer's device... And this is assuming the manufacturer even bothered signing and verifying in the first place.

So this would be bad for manufacturers releasing secure well designed devices without security vulnerabilities.... But if you think about it for a second, isn't this good? As long as there is no known vulnerability, the manufacturer can say the device is still supported, and it costs them nothing, as they have no reason to release an update. And well, if there is a security issue, then it might be better to have the source and keys after all?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#656
post #475

Earlier quoted context omitted.

> "All I have to do is buy the company that owns the central server (or compromise it in some other less visible way) and I now have the ability to introduce malicious code to all devices that are receiving 'security updates.' You won't be able to make a rule to prevent asset transfer (correct me if I'm wrong) so you won't be able to close this hole." Has this actually been a problem in the past? I do not know of any…

Google's acquisitions of Nest and Dropcam are the two which impacted me personally. Data ended up in the hands of people I didn't want, features were removed that I found essential. Perhaps others can volunteer their stories, I've largely opted out of IoT because of these experiences and concerns.

Suppose you buy a car from manufacturer A. You lose both keys (perhaps you and your partner each bring one on a canoe trip and capsize) so you have no choice but to ask the dealer to assign new ones. You find that Google now owns the entire brand A including its dealer network, and they only offer rekeying service in conjunction with an update that installs what you consider spyware. Do you opt out of the motor vehicle industry?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#657

Speaking as someone who has several cheap cameras gathering dust in a box because I no longer trust them with network access... ...manufacturers are simply never going to be incentivized to take security seriously. The best you can hope for with a regulatory approach is to incentivize them to pay more lip-service to the idea, while hiding their backdoors better. Their incentive to spy on users is simply too profitabl…

I think open source firmware would be healthy for device manufacturers in the long term. Companies who build toasters should be competing on who can build the most reliable, energy efficient, long lasting, and aesthetically pleasing toaster possible, not on how much data they can harvest and sell. They're also not likely to recruit elite software engineers to write firmware, so the open source alternative will usually be of vastly superior quality.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#658
post #377

Earlier quoted context omitted.

The OEM could be allowed to choose their recertification period, perhaps with slight differences in requirements. Perhaps even different options offered by company size. For example 1-5 employee companies might get a "no recertification, provided as-is" option which releases automatically 3 years after filing. Vendors who re-certify every 6 months could get an extra mark on their stamp or whatever. There are tons of…

Agree this approach seems to be worth investigating further, but as a citizen of a non-US country, I'd like to see a solution that wasn't based on a US-centric set of controls and governance bodies. These days, with nationalism and populism rampant across the world, I think we need a solution where no one country (or country's leader) can simply decide to turn off critical infrastructure for the rest of the world and…

I completely agree that such a thing should not be US-only. There would need to be a clear distinction between one-gov't backdoor and voluntary regulatory certification, because ultimately the goal would be for other countries to follow suit and provide similar/identical certifications. You could look to standards bodies to provide standard implementation details on what "firmware escrow" is, what exact formats and files must be included, etc. IEEE, ISO, JIS, DIN, and all of them could write or adopt the document. But actually running the service and providing the certification is a little closer to a patent office than organizing standards which is why I propose doing it federally. Think Energy Star (which is a US gov't program based on EPA standards) which has been implemented successfully outside of the US.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#659

Earlier quoted context omitted.

> Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs. +1 for this at the consumer level. My oven may have a critical update, but - for right now - *nothing* is more critical than finishing dinner. I'll let the update apply the day after thanksgiving when I'm doing the dishes. There are a few connected appliances brands that do this well: updates…

I'm wondering why you'd have a smart oven in the first place. Seems like all risk and no reward.

Probably for some feature or astetic that's unrelated to the smart features, but is only available on the smart oven.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#660

Thanks for advocating for these issues. They are important. I'm the CTO of a small software studio who has worked almost exclusively in the IoT space for the last 8 years. We've worked on large, Fortune 500 companies, all the way down to startups. Half our projects have been for consumer IoT, the other half for B2B projects. There are two core financial realities that regulators need to understand: 1. From a purely f…

Thank you for this detailed feedback. In the long-run, it's worth asking whether a business that doesn't make money once externalities have been internalized is a business worth having. But this is a voluntary program, and we're just hoping to spur growth of a segment of the device market where these issues are properly accounted for. Hopefully as more and more purchasers begin insisting on higher-standards, maybe by…

> In the long-run, it's worth asking whether a business that doesn't make money once externalities have been internalized is a business worth having.

This is a good question. The short is is: of course it isn't. But it's difficult to know that up front at times.

Post reply on HN