Hurrah, more red tape! Please let customers opt out of your proposed protection, if they want to. (And it sounds like that's already the status quo. So perhaps you could use your time to figure out where you can cut obsolete and cumbersome regulations instead of adding more mandatory bureaucracy that customers evidently don't want enough to pay for voluntarily?) There might be an argument to be made about negative ex…
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
51–60 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#52Would manufacturers be required to brick devices that cannot be fixed in software? For example, if an MCU didn't have a hardware implementation of a particular crypto function.
Could a device be sold even if the end user had to take action in order to update the firmware? For example, would a manufacturer be encouraged to have every device "phone home" for "updates" without a method of operating in a network where outside Internet is unavailable?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#53It's awfully vague to the point of just being more regulation that allows selective enforcement, which reduces competition and leads to boilerplate allowing FCC department growth, without improving the situation.
It will serve as a barrier to entry to new entrants. What's worse, is that this will create the illusion that IoT is in any way secure. Some IoT is secure, but that standard is unrealistic to apply to consumer devices.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#54Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#55Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#56Earlier quoted context omitted.
I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.
Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.
But if the aim is to stop DDOSes from botnets of poorly secured IOT devices, we need something to help the other 99% of the market.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#57Earlier quoted context omitted.
I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.
Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.
Allowing people to install software on their hardware isn't a cure for vulnerabilities. It's a step in the right direction for sure, but it's a very small one from the perspective of something as huge as "IoT security".
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#58Awesome! Thanks for engaging, where the rubber meets the road! Hopefully, you are also looking into other venues, as well. HN has a great group of folks that represent some of the most cutting-edge tech, but IT runs on Java 8[0]. [0] https://news.ycombinator.com/item?id=19877916
Pretty cool (or at least interesting) to see a government agency engage on HN like this. Never seen that before.
https://www.dhs.gov/news/2023/08/11/secretary-mayorkas-deliv...
https://www.politico.com/news/2023/08/11/def-con-hackers-spa...
https://arstechnica.com/information-technology/2023/05/white...
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#59If a device does not violate (e.g.) RF emissions regulations, what authority does the FCC have to regulate its internals? Thanks!