Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

41–50 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#41

> Accordingly, incorporating our modifications, we propose, for purposes of the IoT labeling program, to define an IoT device as: (1) an Internet-connected device capable of intentionally emitting RF energy that has at least one transducer (sensor or actuator) for interacting directly with the physical world, coupled with (2) at least one network interface (e.g., Wi-Fi, Bluetooth) for interfacing with the digital wor…

I don't like the quoted wording. I would like it to be clearer that the RF part isn't part of the transducer, but part of the network interface.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#42

A mechanism requiring disclosure of how long security updates are available seems like a great step. Another great step would be a guarantee of making the firmware Open Source after no more than a certain amount of time, and having that guarantee known at compile time. Effectively, that means the device will always be supportable.

> A mechanism requiring disclosure of how long security updates are available seems like a great step.

So, as I work in this space, there needs to be realistic guidelines on this, does a security flaw need to have a CVE ? Do they need to fix every CVE ? What is the timeframe requirement ?

This kind of thing keeps me up at night.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#43
Thank so much for posting this here first of all! I agree with other comments that rather than, or in addition to, some direct required period for security updates I'd really like to see a dynamic setup along the lines of "Power Means Responsibility": manufacturers can stop supporting devices when they wish, but must at that time release all keys and IP licensing needed for hardware owners to take over. If a company wants to keep supporting something, and in turn keep their power over deciding how it works, for 10 years that's fine. If they want to drop it after 6 months and make the firmware fully source available and allow owners to add their own root keys to devices that'd be fine too. Or someone could offer something fully open source with no strings attached but also no responsibility attached. The market can fill with a range of decent options.

But manufacturers shouldn't be allowed to have it both ways, with control post-sale over their customers' hardware AND no responsibility to support it. It should be directly linked by law.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#44
Voluntary certification, please. Law is slower than technology. This is a good thing! EnergyStar is a great example of a voluntary program doing more good than DoE or FTC mandates. HIPAA is a good example of what happens when mandates can’t keep up with technology. When it comes to security, we can’t afford another HIPAA.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#45
Many of these devices are made in China, even if designed and sold by American companies. Nearly all contain Chinese made parts. These are network devices with sensors and various behaviors. Given the tension between USA and China, especially in the cybersecurity realm - what about making the case based on US national security (in addition to consumer protection)?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#46
There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches.

This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence.

Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many other spheres with your knowledge and time that are closer to home and probably affect you more immediately.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#47

Earlier quoted context omitted.

Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.

99% of users don't know their iot devices have firmware nor that it can be updated.

Maybe that figure would change if the firmware could indeed be updated.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#49

We’ve seen manufacturers abuse ongoing access to devices to turn off features the device came with at the time of purchase or convert one-time-fee features into subscriptions. One of my concerns is that security updates are strictly defined in a way that prevents this type of regulation from being used as cover for these shenanigans.

I just want to reaffirm the importance of this point. I've used an open source solution named Home Assistant[0] to manage my own network of IoT devices that I don't expose to the internet. I want to stay local because of the risks involved with the internet and with trusting companies to protect such private data.

As such, I look to purchase relativity open devices. But, companies want to keep trying to inject themselves as a middleman, sometimes after the fact. In that case I'm let with a device that becomes e-waste. I don't know what other actions are being taken in regards to subscriptions, but it's a problem here.

[0] https://www.home-assistant.io/

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#50
post #3

commitments on this label (including the support period) will be legally enforceable in contract and tort lawsuits and under other laws. When it comes to U.S. laws that touch technology, enforceability is a mess. Spyware, spam, fraud, misleading labels, etc. are already governed by various state and federal laws, yet enforcement efforts are whack-a-mole at best. For IoT devices, having the proposed requirements sound…

Your point about buyers at scale is really important. The current effort is focused on sellers, but we think that if sellers have to define their security commitments, buyers will pay attention and their risk management people will insist on high standards.

I fear it is practically unenforceable, particularly for consumer-grade devices manufactured overseas

Also a good point. The way we handle this for RF interference is to look at distributors and importers, not just manufacturers, but there will probably always be an untrustworthy product tier out there.

Post reply on HN