Consumers consistently vote with their wallets on this, and based on their behavior, they don't care. They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more. If you want to make a difference, an FCC sticker…
I just don't agree with this at all. I specifically avoid all smart plugs that don't have a UL mark (or European equivalent mark). It's impossible to say that consumers don't care about a specific certification before it exists based on their existing behavior. Consumers _do not have any ability_ to distinguish on this axis at the moment. So, we can't say: "based on their behavior they don't care". They very well mig…
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
821–830 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#822What we need is regulation that controls spam and punishes cyber attacks.
We should not accept the constant round-the-clock break in attempts on every system in the country as just normal "background noise" on the Internet.
If people were going up and down every street testing the locks on every door we would do something about it instead of just saying "how can we coerce companies into selling stronger locks?"
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#823Earlier quoted context omitted.
Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn. Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen. This is literally a national security issue. We currently stifle security research on essential IoT device…
This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#824In an ideal world, IoT and smart device manufacturers would be required to pay for “end of life” insurance. Ridiculous that a company can brick your devices by shutting down their servers and/or going out of business. Some people have suggested forcing companies to open source their software on death so that someone, somewhere might be able to keep the smart devices alive but this is difficult implications for capita…
If a HW company is shutting down due to financial difficulties, the fact they previously paid to get a "license" to make smart devices won't be any incentive for them to continue operating. How does this help the situation other than to further raise the barrier of starting HW companies?
Making hardware companies even harder definitely isn’t great but I don’t see how else to deal with the fact that if I buy a toaster that connects to your toaster cloud and my toaster stops working when you go out of business- I am out one smart toaster that you sold me. Best case scenario I have a regular toaster and worst case I have a brick.
I’m not asking if that’s legal, mind you. I’m asking if that’s fair, if a reasonable person would call that fair? While the company itself is fully aware of the risk that it might not exist tomorrow, it’s customers typically aren’t.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#825Earlier quoted context omitted.
I'll bite - so how do we get all those "air gapped"? It's a leading question of course.
The example was "energy infrastructure", so network group in those firms use their skills to set it up. If any government group should be providing guidance and best practices on how to air gap devices, maybe NSA should write the standards. This FCC proposal looks like a ploy to spend the ever-growing pot (reportedly ten billion USD each year) from the regressive USF phone bill tax instead of reducing the USF tax. As…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#826One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…
Thank you for these thoughtful points. Some relevant responses from other threads: From https://news.ycombinator.com/item?id=37394188 : I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it mi…
These kinds of solutions exist, see for instance: https://docs.aws.amazon.com/freertos/latest/userguide/freert...
My concern is that these firmware update platforms will become oligopolies/monopolies because they will control a legal barrier and naturally accumulate the obligations of many manufacturers.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#827Earlier quoted context omitted.
Lucky guy, it sounds like you've never experienced overwhelming anxiety over having possibly left the oven on while out of the house.
Even if you left the oven on, I believe it’s very unlikely to burn down the house. These devices are designed to work for hours with minimal supervision. Given the size of the user base, IMO ovens are extremely reliable. And electricity prices are too low to be anxious about the costs.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#828Earlier quoted context omitted.
If it was forward looking, rather than retroactive then it would at least mean that chip manufacturers wouldn't be able to sell their undocumented/unsupported crap because all the buyers have to have it? If there are no buyers then their attitude should change.
This is incorrect, because you're assuming that all the buyers have to have it, when the chip manufacturer is selling into many industries/markets. Since the specific "IoT device for the USA market" set of buyers is actually a small percentage of sales for most of the parts they sell, they really don't care to support their product from the IoT security perspective. This support is expensive, so it would very likely…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#829I've dealt with this multiple times, so let me give my perspective. - It is hard for manufacturers to do this with small teams. Mostly because they do not always have good CI/CD or platforms available to keep being on top of vulnerabilities and so on and so forth. - Not all manufacturers write their own software and often contract it out to other experts in the field. This includes firmware and app developers. - If a…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#830I've dealt with this multiple times, so let me give my perspective. - It is hard for manufacturers to do this with small teams. Mostly because they do not always have good CI/CD or platforms available to keep being on top of vulnerabilities and so on and so forth. - Not all manufacturers write their own software and often contract it out to other experts in the field. This includes firmware and app developers. - If a…
> It is hard for manufacturers to do this with small teams. Mostly because they do not always have good CI/CD or platforms available to keep being on top of vulnerabilities and so on and so forth. "It is hard for hospitals to keep their ORs clean with small teams. Mostly because they do not always have good cleaning products or procedures available to keep being on top of contaminations and so forth". I do not believ…
I think your argument here undermines itself. I have not seen an operating room anywhere but a hospital, and hospitals are big. It couldn't really be said that hospitals represent a place with small teams or limited resources. Insurance money is involved, and if you are anywhere other than America, a great deal of government money as well. This is not the picture of a "small firm".
Therefore I must conclude that you either didn't mean to put that hole in the argument, or that you did and that therefore you claim that "small firms" should not create IoT devices.