Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

31–40 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#31
post #3

commitments on this label (including the support period) will be legally enforceable in contract and tort lawsuits and under other laws. When it comes to U.S. laws that touch technology, enforceability is a mess. Spyware, spam, fraud, misleading labels, etc. are already governed by various state and federal laws, yet enforcement efforts are whack-a-mole at best. For IoT devices, having the proposed requirements sound…

Hmm, yeah. Just as fraud telemarketers set up a new shell run by the same principals when the legal bills come due for their old one, so we're likely to see new labels for a new shell company slapped on the same old insecure IoT box.

So I'm not sure "escalating penalties" is going to cut it. It's still whack-a-mole. You need a way to kill the mole, not just drive it to pop up a new hole.

You need a way to get to the principals. They're the mole.

You need to either make them personally liable financially, or you need to jail them. Nothing else is going to stop serial fraud-behind-a-shell-company.

I'm not sure I have an answer. But whatever answer there is needs to be applied not only to fraud telemarketers (please), but also to fraud IoT manufacturers/resellers.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#32
Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so that they cannot get out of that liability by bankruptcy). Most will opt for FLOSS, and none will have the excuse that it would be more secure to make it proprietary. And then users will at least be able to fix issues -- and the security community will be way more effective at finding issues as it wouldn't have to do the slow reverse engineering.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#33
Planned or unplanned obsolescence is good for business. You are proposing regulations counter to that, so should expect counter-pressure, even for IoT makers that want to do the right thing.

By volume and impact, what devices have IoT vulnerabilities? If from large mfrs, you might expect some measure of support as that would be somewhat in their best interest, if only to preserve their brand image. My concern would be low quality, usually cheaper, whack-a-mole mfrs that come and go on Amazon, eBay, etc. Even if they release a product that would fall under these guidelines, how are you going to go after a ghost?

Also, what happens when an IoT mfr is acquired, does the acquirer assume all the IoT risks as well?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#34
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

As far as I remember FCC about 8 years ago didn't liked OpenWRT, and even enforced on TP Link to lock it.

IIRC the main objection was that it could be used to do something with the radio (boost power?) that caused the device to exceed FCC limits for a consumer radio? Something along those lines?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#35
While the IoT security situation is out of control I doubt that regulating security updates will have any other result than radically reducing competition and innovation in the space by making it impossible to operate as a small company. It will simply push more hardware innovation out to China.

Having worked in the space I came to the conclusion the only viable secure future is to adopt star topology local networks where local traffic for all devices goes into a single secure regularly updated broker device that then decides what to do with it. Any access out to the Internet or between devices needs to be mediated. The part that will annoy a lot of people is that broker device probably needs to be able to read all of it. Therefore rather than just regulation I would talk to the WiFi alliance in particular about possibly expanding the scope of what it means to be a WiFi router.

The problem is actors like Google really want such a thing to be just in the cloud "for convenience", by which they mean monitoring everything that ever happens.

The only corporate actors I encountered that understood this were the Taiwanese OEMs, who are remarkably on point and blunt behind closed doors, but they are basically powerless to do anything about it.

Edit to add: if there is one thing the FCC could do immediately it would be to ban the covert deployment of cellular modems in other devices and to force giant warning labels for such things and require they be user removable.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#36
post #3

commitments on this label (including the support period) will be legally enforceable in contract and tort lawsuits and under other laws. When it comes to U.S. laws that touch technology, enforceability is a mess. Spyware, spam, fraud, misleading labels, etc. are already governed by various state and federal laws, yet enforcement efforts are whack-a-mole at best. For IoT devices, having the proposed requirements sound…

If there’s a private right of action you can bet the class action lawyers will do the enforcing.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#38
post #10

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…

That’s only one aspect of the problem.

Lots of people have been bitten by suddenly unsupported devices.

I think it could do some good.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#39
post #17

Earlier quoted context omitted.

I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.

Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.

99% of users don't know their iot devices have firmware nor that it can be updated.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#40
post #10

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…

Exactly. I don't see the situation improving until either the owner or, preferably, the manufacturer of a device that participates in a DoS attack is held partially accountable for said attack.
Post reply on HN