Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

871–880 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#871

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

White Hat: Can I hack your website and services? Company: No we are super secure! No trying to find vulnerabilities. Black Hat: lol sells company data

The point is in enabling the conversation. We can make the laws whatever we want that would help it be fair

White hat: can I hack? Company: no

Later: Company has 100 security request denials Company info leaked Company gets sued Judge is presented with 100 instances where the company was offered free security testing and they refused Judge raises issue from possible negligence to gross negligence

We can also only allow companies to deny requests for specific reasons

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#872

Earlier quoted context omitted.

If your ISP determines there is a botnet from your home IP and you refuse their request to fix it, then it seems appropriate for your ISP to take action or "enact punishment".

Okay, let look at the reverse situation If my ISP charges me for 100 mbps but provides 10, can I enact punishment without government interfering and protecting ISP from my punishment?

Using rule of law and courts, it depends on your contract. Many residential providers have service as a best effort. Guaranteed service with penalties are typically possible, if you are willing to pay significantly more.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#873

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

> there needs to be consent from the company being probed for vulnerabilities So they never give consent and no vulnerabilities are ever discovered? If I make and sell bread, there could be a surprise food safety inspection in the middle of the night on Christmas Eve, but don't we dare inconvenience some software firm that holds intimate data on millions of people.

When you get a surprise food safety inspection, you are notified right? They don't just break into your business without your knowledge and look around. You can refuse them entry, even if it comes with consequences later. They also aren't a random civilian, they have some sort of qualification to be conducting these inspections

That's what I'm getting at. People keep assuming I am saying protect the business at all cost and it's not the case. I want security research to stop getting sandbagged by discussions of legality.

We should make a legal path forward for security research to be more accessible and to promote behavioral differences between someone conducting research and someone trying to exploit or abuse a vulnerability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#874

Earlier quoted context omitted.

Liability chain in many industries is a fantastic way to build a large legal moat to prevent competition from small players. The goal of any regulatory agency must be to ensure as much safety as can be done while preserving the ability of small players to enter the field and compete & while keeping the costs low for consumers. Otherwise, safety becomes a rationale that larger corporations are excellent at spinning to…

A fair point. However, what are we optimizing for? An open/fair market, or consumer safety? Balance is key, but I'm interested in any counter proposals that do a better job.

Consumer safety is long term optimized by having competition. Multi-goal optimization is essential. Try to optimize for just one thing and you’ll quickly go off the rails as a regulator.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#875

Earlier quoted context omitted.

The example was "energy infrastructure", so network group in those firms use their skills to set it up. If any government group should be providing guidance and best practices on how to air gap devices, maybe NSA should write the standards. This FCC proposal looks like a ploy to spend the ever-growing pot (reportedly ten billion USD each year) from the regressive USF phone bill tax instead of reducing the USF tax. As…

I'm talking way out of my pay grade here. > If any government group should be providing guidance and best practices on how to air gap devices, maybe NSA should write the standards. I guess this is a bad joke? It's hard to tell w/ the internet. > This FCC proposal looks like a ploy to spend the ever-growing pot (reportedly ten billion USD each year) from the regressive USF phone bill tax instead of reducing the USF ta…

UL tests and certifies electrical devices voluntarily. I would like to see improvement on a industry basis without more government regulation. Apparently people voluntarily purchase carbon offsets when purchasing airline tickets, do people pay for non-tangibles.

Open standards of tcpip allowed for tremendous innovation, unlike the old Bell System which regulated through monopoly what could be attached to the network.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#876

Earlier quoted context omitted.

If the attacker has total control, then all bets are off no matter what mechanisms you put in first. Adding a safe mode would at least allow manufacturer to stop any non-total exploit without relying on the more complicated update mechanism. Also, the appliance would more likely work in a kinda normal way in the meantime.

> If the attacker has total control, then all bets are off no matter what mechanisms you put in first. You could have a second SoC on the device running off ROM, whose only purpose is handling this safe mode and controlling internet access of the main device. Keep it simple and make it essentially just a fuse that can be blown (turning off internet access) by a signed message from the manufacturer. Keep the hardware…

Ideally yeah, the bar for critical appliances would be high enough for this. If not, disabling IP at the OS level would still be pretty good.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#877

Earlier quoted context omitted.

In my case, being able to start it heating when I'm ten minutes away from home, so that I can get the kids fed ten minutes sooner.

A timer to turn on an oven has been a thing for 25 years or more, probably there were clockwork ones before that. So it is down to very fine control on timing, or not turning the oven on, say, if you're in a traffic jam. I'd expect the network connection to go down and the oven not to turn on at least as often as 10 minute makes an operable difference.

Maybe you don't decide at the start of your day, rather it comes up later that the kids want something baked for dinner that is already prepared and just needs to go into the oven, and you also get home from work at like 7pm. Idk how niche that is, but if that's someone's situation, the remote control makes sense.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#878
post #790

Earlier quoted context omitted.

I hate it too, but the heart of this is that ownership is under question. People should not have agreed to buy things where there are parts of it they don't own that they don't even need, but they did. They did it a lot because it didn't matter to them and now those devices are prevalent everywhere and it's a PITA to try to buy the type of item you actually want - where you own it entirely. Ownership has never actual…

Out of curiosity - why should I be required to ask for permission from given company to probe company owned infrastructure? What I mean here is that if there's a bug / vulnerability on given company infrastructure, then that company should fix it and not put on a blame on a user that was affected by it (even if device that communicates with given infrastructure always follows happy path)

You need permission because

1) the probing almost always involves breaking the terms of the contract you made with that company.

2) it creates a paper trail of intent

3) it's not your property so why wouldn't you need permission to access it?

I am not sure how permission effects a companies ability or obligation to fix security bugs. I agree they should fix it.

We can make the law that not only does the company approve of the request but they have to disclose to you additional information that can help you find bugs. Idk, point is I'm advocating for creating a system where researchers work with the company rather than as vigilantes

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#879
One aspect that I am running into is managing the updates for air-gap systems. Some clients use IoT devices without a connection to the Internet. Currently working on a project to download and package OS and software updates for complete automation. Some operating systems and software updates require Internet access to perform these tasks. Updates and supporting tools should be supplied in an Online and Offline method to properly regulate the industry.

P.S. IoT is referring to devices that communicate through the Internet or other mediums such as ZigBee or Bluetooth. Why I prefer Communication of Things (CoT) over IoT.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#880

Earlier quoted context omitted.

This is incorrect, because you're assuming that all the buyers have to have it, when the chip manufacturer is selling into many industries/markets. Since the specific "IoT device for the USA market" set of buyers is actually a small percentage of sales for most of the parts they sell, they really don't care to support their product from the IoT security perspective. This support is expensive, so it would very likely…

> This support is expensive Most of IoT is that way. We had sales cycles that were 2-3 years long and they would in the end buy 300 units. I then go back to my suppliers and say 'hey support these 500 ic's that you sold me for 10 years from right now' They would laugh me out of the room unless I am showing up with big bags of cash. That instantly makes the whole project unviable to sell/support.

Yes, absolutely. This is the exact conditions of most of our higher-end products (500-1000 units sold of a particular configuration is common). It's funny to get laughed out of the room even asking some chipmakers "can you sell us 1000 parts, please?"
Post reply on HN