Live data from Hacker News

FCC Bans Authorizations for Devices That Pose National Security Threat

fcc.gov

21–30 of 242 posts

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#21

In reality, Chinese manufactures will just ignore FCC licensing requirements. A good amount of cheap Chinese electronics on Amazon are already unlicensed, so I doubt any new changes will affect them. Online marketplaces like Amazon really need to crack down on products and make sure they are properly licensed.

and that's fine in the scheme of things. Random one-off imports by researchers or hobbyists via AliExpress? NBD.

Deployments at-scale where vendor support engineers could theoretically use cellular gear for passive collection? Major concern.

Hytera being used for commercial 2-way radio? Similar concerns on the repeater side, not to mention questions about encryption quality if they are used by governments.

You have to name the vendor for commercial 2-way radio licenses, for USDA RUS funding, etc. Lying on those forms brings far worse penalties than what a random individual buying a Hytera DMR for ham use off Amazon would face.

Hikvision is the odd name here. AFAIK they do not make cellular handsets or base stations and were already prohibited from being used on government contracts.

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#22

In reality, Chinese manufactures will just ignore FCC licensing requirements. A good amount of cheap Chinese electronics on Amazon are already unlicensed, so I doubt any new changes will affect them. Online marketplaces like Amazon really need to crack down on products and make sure they are properly licensed.

I would rather Amazon focus on elimination of Counterfeits and Fraud, not enforcement of FCC protectionism

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#24

Earlier quoted context omitted.

Source?

See CVE: https://www.cvedetails.com/vulnerability-list.php?vendor_id=... At some point you have to think these are deliberate.

Extraordinary claims require extraordinary evidence. All I see are a lot of CVEs.

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#25
post #19

the video surveillance bans all seem to target billion dollar companies, so its safe to say this is just your friendly lobbyists at ring, nest, and amazon getting an early christmas gift. the security argument is pretty flimsy considering how many american companies are just as bad (looking at you nest) the usual suspect, huawei, has been on americas shitlist ever since they beat US telcos to market with 5g. their ce…

>lobbyists at ring, nest, and amazon getting an early christmas gift

This has no impact on sales to the consumer market for Video, the covered list [1] limits the ban to "the extent it is used for the purpose of public safety, security of government facilities"

Ring, Nest etc are used for personal home and small business not likely covered under that ban, and the people buying Hikvision as an example most likely are not the target consumer of Ring devices. Hikvision is / was popular is commercial segment of professionally installed products, I know of zero professional installers doing commercial deployments of Ring. Companies like Axis however do get a boost as Axis is often many times more expensive than Hikvision

[1]https://www.fcc.gov/supplychain/coveredlist

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#26

Earlier quoted context omitted.

That's not how this will be applied. Instead, I think, they will go after devices that don't contain government backdoors.

Which devices have government backdoors?

Almost all of them?

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#27

Based on the actual news release[1], this is the FCC's formal statement of rules for compliance with the Secure Equipment Act of 2021[2]. [1]: https://docs.fcc.gov/public/attachments/DOC-389524A1.pdf [2]: https://www.congress.gov/bill/117th-congress/house-bill/3919

Thanks for connecting the dots, I was doing this research before I found your comment. I knew I had searched for covered telecom equipment last year.

Also, I didn't know the covered list was being updated. Does anyone know what AO Kaspersky is? Is that the official corporate name for the anti-virus Kaspersky?

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#28

About time. We need open and verifiable firmware, at the very least, to be able to trust anything. Now if only they'd turn this lens on American-made devices which are likewise opaque, insecure, and likely to be weaponized against us as soon as security updates stop....

[deleted]

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#29
post #11

About time. We need open and verifiable firmware, at the very least, to be able to trust anything. Now if only they'd turn this lens on American-made devices which are likewise opaque, insecure, and likely to be weaponized against us as soon as security updates stop....

> We need open and verifiable firmware, at the very least, to be able to trust anything. How? Even ignoring ASICs, I just don't see how it's possible. Even if you had no binary blobs anywhere (we are already in the wonderland), with process for turning source to binary, you need to trust compiler, cpu, flashing hardware and software and the whole lot of other things. And that's all ignoring the fact that hiding bad s…

> with process for turning source to binary, you need to trust compiler, cpu, flashing hardware and software and the whole lot of other things.

"We should not solve this solvable problem because other problems exist" is false.

Meanwhile the other problems have solutions, like reproducible builds, so that the attacker not only has to compromise your compiler/CPU/hardware, they also have to compromise any others the output result gets compared by, or one of them will differ and the attack will be detected.

Post reply on HN