Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

51–60 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#51
post #8

Hurrah, more red tape! Please let customers opt out of your proposed protection, if they want to. (And it sounds like that's already the status quo. So perhaps you could use your time to figure out where you can cut obsolete and cumbersome regulations instead of adding more mandatory bureaucracy that customers evidently don't want enough to pay for voluntarily?) There might be an argument to be made about negative ex…

The free market hasn’t figured it out, as evidenced by the decade of half-working devices consumers are left with. There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#52
The best regulation is written as if it would be implemented and/or interpreted in the worst possible way. As if it would be used by your worn enemies against you.

Would manufacturers be required to brick devices that cannot be fixed in software? For example, if an MCU didn't have a hardware implementation of a particular crypto function.

Could a device be sold even if the end user had to take action in order to update the firmware? For example, would a manufacturer be encouraged to have every device "phone home" for "updates" without a method of operating in a network where outside Internet is unavailable?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#53
Could you summarize what these "security updates" would entail? There are 1000s of attack vectors, so it would be difficult to practically define.

It's awfully vague to the point of just being more regulation that allows selective enforcement, which reduces competition and leads to boilerplate allowing FCC department growth, without improving the situation.

It will serve as a barrier to entry to new entrants. What's worse, is that this will create the illusion that IoT is in any way secure. Some IoT is secure, but that standard is unrealistic to apply to consumer devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#54
Someone smarter than I and more versed in the legal matters should shape this concept: if you go bankrupt, your source code gets released. I can already see some small problems with this but the general thrust is, I think, not unreasonable.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#56
post #17

Earlier quoted context omitted.

I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.

Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.

Free software firmware would be great for free software lovers and tech experts, no doubt. But sophisticated users who'll take advantage of things like that are only 1% of the market.

But if the aim is to stop DDOSes from botnets of poorly secured IOT devices, we need something to help the other 99% of the market.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#57
post #17

Earlier quoted context omitted.

I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.

Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.

I'm sure the number of routers running OpenWRT is dwarfed by the number of OpenWRT-compatible routers running vulnerable, stock firmware.

Allowing people to install software on their hardware isn't a cure for vulnerabilities. It's a step in the right direction for sure, but it's a very small one from the perspective of something as huge as "IoT security".

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#58

Awesome! Thanks for engaging, where the rubber meets the road! Hopefully, you are also looking into other venues, as well. HN has a great group of folks that represent some of the most cutting-edge tech, but IT runs on Java 8[0]. [0] https://news.ycombinator.com/item?id=19877916

Pretty cool (or at least interesting) to see a government agency engage on HN like this. Never seen that before.

They're definitely making efforts to engage where practitioners and subject matter experts are. Substantial Federal gov showing at defcon this year for example.

https://www.dhs.gov/news/2023/08/11/secretary-mayorkas-deliv...

https://www.politico.com/news/2023/08/11/def-con-hackers-spa...

https://arstechnica.com/information-technology/2023/05/white...

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#59

If a device does not violate (e.g.) RF emissions regulations, what authority does the FCC have to regulate its internals? Thanks!

That's a great question. Devices that emit RF could be hijacked and turned into signal jammers. With smart jamming attacks, even low-power transmitters could potentially cause serious harmful interference to other devices. Botnets of compromised devices could be especially damaging. Since vulnerabilities are often chained by attackers, sometimes in very unexpected ways, to accomplish their final goal, we think that the FCC has a legitimate interest in just about any vulnerability on a wireless device. But the question of legal authority is itself open for public comment and we hope there's vigorous debate on the record to make sure we get it right.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#60
I'm generally skeptical of the efficacy of regulation to solve a problem. Can you please cite some examples of where FCC regulation has been successful in solving other problems, and explain why you believe iot security regulation is likely to help?
Post reply on HN