Live data from Hacker News

The FCC Might Ban Specific Operating Systems

prpl.works

121–130 of 140 posts

Re: The FCC Might Ban Specific Operating Systems

#121
post #102

A driver is not an OS, notwithstanding the legitimate and well-founded objections to driver signing as it affects open source operating systems...but I'm willing to firgive a little hyperbole in the pursuit of attention. On the other hand: I firmly and respectfully disagree. The user always knows their life better than anyone else. Linux exists because users could modify their device. OpenWrt exists because users cou…

> as soon as I begin broadcasting, I'm not just living my life any more, I'm affecting yours, too Do you have a wifi router? If so, you are already broadcasting. Have your neighbors complained that they can't use their wifi because of your broadcasting? The huge missing piece in this whole discussion, to me, is: how much of a problem actually exists? How many people actually have problems using wifi because someone e…

My neighbors haven't complained because I'm not doing anything particularly radical with my router. But if I started swamping their signals I imagine they would be annoyed about it. I thought this context was obvious in my post above.

The article suggests two: social norms, and aggressive enforcement against actual offenders--as in the Marriott case.

And people who disagree with our perspective thought the Marriott case was a big government shakedown. I am disinclined to rely on social norms, given that there are often substantial economic rewards for flouting them.

Re: The FCC Might Ban Specific Operating Systems

#122

Earlier quoted context omitted.

The FCC responded to Ars saying that the line about DD-WRT was clumsily worded. I'm under the impression that if the OEM/importer demonstrates in their filing that their proof of conformance documentation will always be representative (valid) of the device no matter what the user can do through user-accessible features and menus, i.e. they can prove that the radio module is locked down in some way other than the main…

Do you have a link for that? I'd like to see it... The original wording from the FCC about DD-WRT was pretty awful, and I don't see how their intent can be interpreted otherwise (although they may be backpedalling now): "2. What prevents third parties from loading non US versions of the software/firmware on the device? Describe in detail how the device is protected from "flashing" and the installation of third party…

    Do you have a link for that? I'd like to see it...
It's the very same document - I'd encourage everyone to read it in full. There are only 3 pages of content after all: "Software Security Requirements for U-NII Devices" [1]. But keep in mind - this is not representative of the actual license conditions and regulations, it is a piece of bureaucratic administrivia that helps the FCC staff process and assess your applications!

    "2. What prevents third parties from loading non US versions of the software/firmware on the device? Describe in detail how the device is protected from "flashing" and the installation of third party firmware such as DD-WRT."
Again, I think people are picking stuff at random and missing the context. I could find much scarier wording than this if you really wanted to FUD this up some more. This is part of a bureaucratic administrative process used to help assess applications.

It even says that follow-up questions may be asked. As someone familiar with regulatory compliance processes in another country (.au), just because you answer in the negative does not mean your application will be rejected - your other responses (see the rest of the questions to see how redundant they are) will be taken into consideration.

Even though we have the old joke where our equivalent of the FCC has an unofficial motto, "We're not happy until you're not happy", even bureaucrats have enough imagination to see that scripted questions can't capture every single possible way to meet the underlying requirements for a given regulatory compliance issue.

The questions are centered around identifying how the device is restricted from operating outside of the conditions asserted and tested in the conformance documentation submitted with the FCC registrant's application. That's not an unreasonable expection from a spectrum regulator's POV, but it is terrifying given that this will likely mean region-locked (or region-specific) devices - choosing a country from a drop-down list will become a thing of the past (after all, 5GHz is carved up quite differently in different parts of the world compared to 2.4GHz, where things are already a complete mess).

Whilst you might find that "OMG, these questions seem to assume that the FCC wants only OEM-approved firmwarez", as per the DD-WRT wording this is because the questionnaire has been written from the assumption that these drastic measures are necessary to meet the new regulations. If you read the proposed regs themselves, carefully [2], I don't see anywhere where the "host device" is explicitly required to control OS firmware unless this is the only means that the registrant can meet the U-NII security requirements.

It doesn't help that we have a whole new population of people trying to read and understand these documents (me included). They use the term "software" rather loosely, and you have to have some background understanding of how the existing FCC registration/approval/certification process works (difference between an approval for a host device vs module etc).

I even see people mixing up the SDR rules. Technically an SDR product must undergo a completely new FCC approval process with new validation test results/proof of conformance for every firmware update! There's no way WiFi router AP vendors are going to go down that path; this is reserved for things like mobile phone baseband firmware that change infrequently and are profitable enough (check out Qualcomm's profits) to actually afford to be able to do this.

This [2] basically summarizes the intent behind the U-NII security requirements:

    Manufacturers must implement security features in any digitally modulated
    devices capable of operating in any of the U-NII bands, so that third parties
    are not able to reprogram the device to operate outside the parameters for which
    the device was certified. The software must prevent the user from operating the
    transmitter with operating frequencies, output power, modulation types or other
    radio frequency parameters outside those that were approved for the device.
    Manufacturers may use means including, but not limited to the use of a private
    network that allows only authenticated users to download software, electronic
    signatures in software or coding in hardware that is decoded by software to
    verify that new software can be legally loaded into a device to meet these
    requirements and must describe the methods in their application for equipment
    authorization.
[1] https://apps.fcc.gov/kdb/GetAttachment.html?id=1UiSJRK869Rsy...

[2] http://www.ecfr.gov/cgi-bin/retrieveECFR?gp=1&SID=9a15d7771e...

Edit: I guess you meant the Ars article! Here it is:

http://arstechnica.com/information-technology/2015/09/fcc-ac...

    Ars is attempting to schedule an interview with the FCC to explore this issue in
    more depth. So far, the commission has only told us that “versions of this open
    source software can be used as long as they do not add the functionality to
    modify the underlying operating characteristics of the RF [radio frequency]
    parameters. It depends on the manufacturer to provide us the information at the
    time of application on how such controls are implemented. We are looking for
    manufacturers of routers to take more responsibility to ensure that the devices
    cannot be easily modified.”

Re: The FCC Might Ban Specific Operating Systems

#123

Earlier quoted context omitted.

There seems to be some incredibly bizarre idea floating around here that it is illegal to MONITOR using the equipment (id est "listen") and that is simply not true, except for listening to cell frequencies. That is in American law, but here's the thing: They will not be able to determine that you're listening on those frequencies without looking at your equipment. You can possess and operate your equipment in monitor…

I've seen some of the enforcement actions - on a first offense they often just give you a stern warning unless it's clear you were doing it willfully and maliciously (interfering with a company's communications because you have a bone to pick, for instance). Amusingly, there's been a few cases local law enforcement has asked the ham community to RDF people using their frequencies - at least here most law enforcement…

RDF = Radio Direction Finder

Re: The FCC Might Ban Specific Operating Systems

#124
post #3

What I don't get it is, why make the software enforce certain frequencies? If the hardware should never be able to broadcast on a certain frequency, why not build the hardware with that limitation?

This goes beyond just frequency and power conformance. There's power negotiation, interference avoidance, instantaneous occupied bandwidth, instantaneous vs average power limits, spread spectrum/freq hopping performance, radar avoidance algorithms - it took a lot of effort to carve up the 5GHz bands, each part of the world has done it differently, and so there's a lot more strings attached.

Re: The FCC Might Ban Specific Operating Systems

#125

Earlier quoted context omitted.

This is because this is entirely intended for software defined radio and modular radio - around which the entire point is the RF component does not contain as much signal processing logic, and that is done in software. Restricting software defined radios to specific frequencies in hardware would take away the entire point of modular/software defined radio.

Did you miss the conversation about how this fucks over people who want to install custom firmware on their routers for legitimate administration and traffic-shaping? There are plenty of uses for radio software that don't involve going outside approved frequencies.

Contrary to the common interpretation, I've yet to see where in the new rules it is required that manufacturers implementing the new 5GHz U-NII device software security requirements is required to forbid 3rd-party firmware. Yes, there is an administrative document that asks questions about how such updates are prevented, but if you read the full document in context it also asks a lot of other redundant questions, and the FCC have since responded to Ars questions stating that it was not their intention to ban alt firmwares - just that the administrative processes starting up at the moment probably assumed that it would be necessary for the host device to do this to meet the new requirements. And since when does answering a regulatory compliance question in the negative mean that your application will automatically be rejected? All of the responses are used to help an FCC assessor arrive at a proper conclusion, potentially with further clarification sought on each point - it is not a hard script that you must always answer every requirement in the positive (in fact in many cases this would be impossible).

The new regs themselves do not state this requirement. It lists several possibilities for manufacturers to guarantee conformant emissions from their device, several which will continue to allow 3rd-party OS firmware.

Admittedly, the brave new world looks like region-locked devices and cheaper routers that truly are locked down in the exact ways we don't want, but that is not a hard FCC requirement, just a side-effect of the new regs on APs that have poor separation between OS and radio module.

    There are plenty of uses for radio software that don't involve going outside approved frequencies.
Except unlike ISM bands, U-NII 5GHz spectrum has been carved up with consultation of the 5GHz primary (licensed) users in each country and granted exclusively for U-NII conformant devices.

Unlike 2.4GHz ISM, nothing gives you the right to transmit on 5GHz U-NII bands (well, there's a bit that overlaps with secondary amateur spectrum) than otherwise permitted through the same FCC approvals process every device manufacturer must undergo.

That was the case before the new rules. Now the new rules are imposing sucky requirements for U-NII device software security.

However, that's been largely misinterpreted in every discussion I've seen recently.

For some context, check out https://wirednot.wordpress.com/2014/01/07/what-else-is-in-th...

You really don't want U-NII devices configured for Japan to be stomping on licensed spectrum in the US; you also need all that power negotiation, radar/interference avoidance algorithms in your radio so we don't get the same 2.4GHz mess happening in 5GHz.

Re: The FCC Might Ban Specific Operating Systems

#126
post #119

Earlier quoted context omitted.

The sub-ten dollar wideband SDR is a recent phenomenon.

Wideband radios are not all that new. My radio is a Kenwood TS-820S from the 70s and covers multiple bands from 160M to 10M. My cheapo Radio Shack walkie talkie from 15 years ago covers most (all?) of 6M to 2M (i.e. all kinds of serious bands that I'm not allowed to transmit on). My Yaesu VX-5R from 10 years ago can do full-on wideband receive, from 6M up to microwave. With the help of an auto-tuner to match the SWRs…

I made a short reply as to one reason why I thought that the fancy radios that monitor their own output might be cheaper now or in the not too distant future. I'm grateful for the reply, but I think you've read too much into my little one-line comment.

>Wideband radios are not all that new.

No, but super cheap ones are.

>It's not like tweaking a VFO is really a technical challenge

Well, it's a little bit of a challenge for most (especially non-hams), but sure, there's no magic involved.

>The FCC tracks you down and you get a pink slip telling you that they know what you're up to.

I've heard so many scary stories about the FCC, and yet their enforcement actions page is relatively empty; and hams are always heard complaining about both persistent abusive behavior that the FCC either does little, or is powerless to stop. My impression is that violators, both abusers and unintentional get a lot of chances to correct their behavior; and that FCC enforcement is mostly a paper tiger that can do a bit of damage to someone who wants to comply (for the most part), and can do very little or nothing to stop the worst abusers.

Enforcement actions: https://transition.fcc.gov/eb/AmateurActions/Welcome.html

Warning Letters: http://transition.fcc.gov/eb/AmateurActions/Legacy.html

>You both underestimate what older radios can do, and overstate what newer radios can do relative to them.

I don't think so. I know that these features, or reasonable substitutes for them exist/have existed for some time, but I also know that their widespread use was limited, primarily due to cost. Economies of scale in manufacturing mean that since a TV tuner chip which produced in the billions can be used as an SDR, now there are lots of very inexpensive SDR units available for purchase. For higher end equipment, there is also the fact that DSP tech has advanced at a pretty incredible pace enabling things like the ~$300 dollar 100MHz oscilloscopes in my lab and also the 500MHz scopes in my lab that didn't cost more than our minivan. Sure, many (maybe even most) of the things that can be done with an SDR can also be done with solder and wires, but an SDR can do any/all of them. A super cheap (as in >The reasons that you didn't see people transmitting off-band before was primarily social, not technological.

I think you've hit the nail on the head here. There simply isn't any/much of a problem, and where the problems do exist the FCC is largely toothless anyway (and that's arguably a good thing). The FCC sees the potential for cheap consumer equipment that can easily be made non-compliant; they know that they haven't the resources to enforce the rules against millions of people and want to simply prevent it from happening. There is a reason that the FCC has so little enforcement is because nobody who knows them, likes them.

>FCC was flipping out about people intercepting cellphone calls on omniband radios - 15 years ago.

Another reason to dislike the FCC, they made a rule which was almost totally ineffective, and today is completely moot; because the technology prevents the problem that the rule was supposed to prevent. The cost of scanners/radios went up, and some good products were taken off the market and replaced with junk, or simply not replaced. Yay FCC.

> Omni SDR was around 10 years ago too, with the same capabilities (see: GNU Radio), it just cost more than $10 for a rig.

A lot more than $10, and you had less "SD" for your SDR because your PC and the software was simply less capable. Now, a relative noob can start from practically nothing and point and click his/her way to receiving any number of things in an afternoon.

Re: The FCC Might Ban Specific Operating Systems

#127
post #102

Earlier quoted context omitted.

> as soon as I begin broadcasting, I'm not just living my life any more, I'm affecting yours, too Do you have a wifi router? If so, you are already broadcasting. Have your neighbors complained that they can't use their wifi because of your broadcasting? The huge missing piece in this whole discussion, to me, is: how much of a problem actually exists? How many people actually have problems using wifi because someone e…

My neighbors haven't complained because I'm not doing anything particularly radical with my router. But if I started swamping their signals I imagine they would be annoyed about it. I thought this context was obvious in my post above. The article suggests two: social norms, and aggressive enforcement against actual offenders--as in the Marriott case. And people who disagree with our perspective thought the Marriott c…

> My neighbors haven't complained because I'm not doing anything particularly radical with my router. But if I started swamping their signals I imagine they would be annoyed about it.

But you're not swamping their signals. Neither are the vast majority of people who have routers. So the vast majority of people are not hindering each other by broadcasting. That includes many people (like me) who have routers with third party open source firmware on them (I run OpenWRT). Just saying "well, someone could swamp others' signals" isn't enough to justify pre-emptive regulation; that should require showing that enough people are swamping others' signals to make ordinary enforcement insufficient.

> people who disagree with our perspective thought the Marriott case was a big government shakedown

How do you think those people would view pre-emptive regulation by the government?

> I am disinclined to rely on social norms, given that there are often substantial economic rewards for flouting them.

I see the economic incentive in the case of a large corporation like Marriott (and that's why I mentioned them in connection with enforcement, not social norms). But for ordinary users who just want to run routers in their homes? Social norms seems like a reasonable way to regulate in that case.

Re: The FCC Might Ban Specific Operating Systems

#128
post #100

Earlier quoted context omitted.

> they're only talking about modular radio systems or software defined radio systems Which, in practice, means any computer/electronic device that has a radio in it. > this is targeting consumer equipment Including "consumer" equipment that is being used for research, software coding, etc.

Which, in practice, means any computer/electronic device that has a radio in it. No. FCC approvals apply to the modular transmitter. Another approval may apply to the overall device.

> FCC approvals apply to the modular transmitter.

Including the software that controls it. Which, in practice, includes the OS of a laptop or the firmware of a router, as discussed in the article. Technically that might not be the "entire device", but it's the part that matters.

Re: The FCC Might Ban Specific Operating Systems

#129

Earlier quoted context omitted.

Do you have a link for that? I'd like to see it... The original wording from the FCC about DD-WRT was pretty awful, and I don't see how their intent can be interpreted otherwise (although they may be backpedalling now): "2. What prevents third parties from loading non US versions of the software/firmware on the device? Describe in detail how the device is protected from "flashing" and the installation of third party…

Do you have a link for that? I'd like to see it... It's the very same document - I'd encourage everyone to read it in full. There are only 3 pages of content after all: "Software Security Requirements for U-NII Devices" [1]. But keep in mind - this is not representative of the actual license conditions and regulations, it is a piece of bureaucratic administrivia that helps the FCC staff process and assess your applic…

Yes, I did mean the Ars article, my bad for not clarifying the context - and thanks for the additional commentary too!
Post reply on HN