Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

941–944 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#942
It sounds like extra regulation, and thus a large spread out cost for society, for something that hasn't seemed like a real problem. I worry that this would stifle innovation in development of products by small companies and individual developers to meet regulatory burdens to get govt stamps of approval, while giving an advantage to large companies that can handle regulatory burdens.

IoT is an experimental field that is dominated by people fiddling in their garage.

If harm comes from their use, that is where tort law comes into play, and that doesn't seem to something that is a common occurrence except in the fantasy of doomsayers talking about ovens that are weaponized - all without thinking about companies that make ovens and how this would already be their primary concern.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#943

Earlier quoted context omitted.

You proposed requiring consent from the producer of a product/service to have their offering probed. And did so with an example of a house not owned by that producer. If the production company declines, that DOES remove pressure from that company. Companies that rush out rubbish products can presently be named and shamed by independent, uncooperative or even adversarial researchers. Your proposal considers that resea…

I proposed a preference for systemic solutions over a soft dependence on white hat hackers who operate identically to black hat hackers right up until they have a vulnerability to exploit and decide what to do with it. In this thread I expanded the detail to include the system to do this could (and imo should) be a legal framework that creates effective communication between companies and researchers. I also try to a…

Kinda. I think we agree on the need to protect researchers. And if researchers are aligned with consumers rather than manufacturers then that's preferable because it's not the manufacturer's property once it leaves the building.

If protection is in place, that alignment will work because manufacturers' declining to be scrutinised won't prevent researches from doing their job. But making protection conditional on manufacturer approval will suppress their work in those cases. And I don't know the practicality of establishing and enforcing this. So I oppose any conditionality generally.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#944

Earlier quoted context omitted.

It sounds like you're looking for a carve out so you don't have to upgrade your devices to have a modern microcontroller that supports remote updates and are using saltwater as a scary thing so no one challenges you on it. You can conformal coat a ESP32 with a sensor and battery and a wireless charger, and get remote updating. If hobbyists are doing that without commercial backing, what industry experts like you have…

Wouldn't a Starlink satellite qualify as an IOT edge device? How do you propose a user-servicable physical switch on a device in LEO? Not all devices have easy or cost-effective physical access -- that's why IOT is particularly effective at bridging the digital-physical divide.

Having a category for inaccessible things in LEO doesn't indict my point that things not in LEO are typically accessible.
Post reply on HN