Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

811–820 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#811

Earlier quoted context omitted.

As someone who designs IoT devices like these for a living, the device manufacturers here are in many cases the smallest companies in the supply chain and have very little ability to influence things upstream of them, especially for specialty products or companies entering a new market. It's often a major win to get a chipmaker to pick up the phone and sell us their product, much less receive any support at all. I wi…

If it was forward looking, rather than retroactive then it would at least mean that chip manufacturers wouldn't be able to sell their undocumented/unsupported crap because all the buyers have to have it? If there are no buyers then their attitude should change.

This is incorrect, because you're assuming that all the buyers have to have it, when the chip manufacturer is selling into many industries/markets.

Since the specific "IoT device for the USA market" set of buyers is actually a small percentage of sales for most of the parts they sell, they really don't care to support their product from the IoT security perspective. This support is expensive, so it would very likely be cheaper for them to ignore the market completely.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#812
post #785

Earlier quoted context omitted.

Finishing dinner can be more important than the house not burning down. A burned down house is likely insured. A dinner with a potential business client is not.

Surely this has to be a joke.

Could be a reference to steamed hams

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#813
post #719

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

This is a very poor analogy. For one thing, casing someone's home is not interesting research. It's not news to anyone that locks only keep honest people out. You need physical access to break in. The legal system and the people nearby (neighbors and residents, and their firearms in the USA) are the main lines of defense here. Unlocked doors are a harm targeting one household. Conversely, with vulnerable IoT devices,…

Another analogy could be someone doesn't realize they left their back door open and these guys come and point it out.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#814

Earlier quoted context omitted.

I'd sure hate to have my system ransomware compromised, and when I try to restore from a backup drive, the ransomware encrypts it, too, as soon as I plug it in. I also have, on occasion, flipped the from and to parts of the command to restore from a backup. I'd really like to have a hardware switch to make the drive read-only.

They exist, but only as very expensive specialty gear for digital forensic investigators. https://digitalintelligence.com/store

These also exist for removable drives (not really any different price compared to normal drives, in wide use) in the govt/defense market, where using a hardware write switch when moving data between airgapped systems in a controlled way is common.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#815
I was expecting a straight up ban of products that don't meet the FCC criteria but oh boy - the full on refusal of an FCC sticker!

That'll teach them!

Are there any plans for a more impactful regulation like they'd come up with in Europe?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#816
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

The best alternative firmware example for true IOT devices is Tasmota [1]. Erase manufacturer firmware for every ESP devices the day after purchase to avoid those careless manufacturer firmwares.

[1] https://tasmota.github.io/docs/

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#817
post #577

Earlier quoted context omitted.

I think this is oversimplifying things. Is finishing the dinner more important than applying a patch that fixes actively exploited bug that locks your oven into cleaning mode and burns everything inside into ash over the next three hours? Or something that disables the safety checks and lets the oven overheat and burn your house down? (Granted, the latter shouldn't physically be possible because it should have physic…

These seem like very rare scenarios. If we're concerned about dire threats like this, the manufacturer needs a way to remotely send devices into an internet-disconnected "safe mode" before anyone's even talking about updates.

> If we're concerned about dire threats like this, the manufacturer needs a way to remotely send devices into an internet-disconnected "safe mode" before anyone's even talking about updates.

This was exactly my thought. Download the update then take the device offline until it's applied if the update contains a security vulnerability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#818
post #577

Earlier quoted context omitted.

I think this is oversimplifying things. Is finishing the dinner more important than applying a patch that fixes actively exploited bug that locks your oven into cleaning mode and burns everything inside into ash over the next three hours? Or something that disables the safety checks and lets the oven overheat and burn your house down? (Granted, the latter shouldn't physically be possible because it should have physic…

These seem like very rare scenarios. If we're concerned about dire threats like this, the manufacturer needs a way to remotely send devices into an internet-disconnected "safe mode" before anyone's even talking about updates.

If these are the kind of things we are worried about then the correct course of action is to ban needlessly internet connected devices. Your need for twitter on your fridge doesn't outweigh the botnet threat it poses.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#819

Earlier quoted context omitted.

The ability to pre-heat my oven without standing in front of it. That's really the big win. But also to be able to tell if spouse or children left it on.

But I can walk to my oven and turn it on, which wasn't a real problem even when I lived in a huge house. What am I missing?

> But I can walk to my oven and turn it on, which wasn't a real problem even when I lived in a huge house.

Rushing to get out the door, "Honey, did we turn off the stove?" Presumably you can then check with your phone.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#820

Earlier quoted context omitted.

If it was forward looking, rather than retroactive then it would at least mean that chip manufacturers wouldn't be able to sell their undocumented/unsupported crap because all the buyers have to have it? If there are no buyers then their attitude should change.

This is incorrect, because you're assuming that all the buyers have to have it, when the chip manufacturer is selling into many industries/markets. Since the specific "IoT device for the USA market" set of buyers is actually a small percentage of sales for most of the parts they sell, they really don't care to support their product from the IoT security perspective. This support is expensive, so it would very likely…

> This support is expensive

Most of IoT is that way. We had sales cycles that were 2-3 years long and they would in the end buy 300 units. I then go back to my suppliers and say 'hey support these 500 ic's that you sold me for 10 years from right now' They would laugh me out of the room unless I am showing up with big bags of cash. That instantly makes the whole project unviable to sell/support.

Post reply on HN