Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

61–70 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#61
post #46

There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#62
post #8

Hurrah, more red tape! Please let customers opt out of your proposed protection, if they want to. (And it sounds like that's already the status quo. So perhaps you could use your time to figure out where you can cut obsolete and cumbersome regulations instead of adding more mandatory bureaucracy that customers evidently don't want enough to pay for voluntarily?) There might be an argument to be made about negative ex…

What's stopping hobby/micro-developers from saying 'Not FCC approved, use at own risk'? I hack on ESP32 devices, I certainly have different expectations as a hobbyist and as a consumer or consultant.

> What's stopping hobby/micro-developers from saying 'Not FCC approved, use at own risk'?

OP is. Or rather, he wants to make it impossible to opt out. At least that's how I interpret these two paragraphs:

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it. I fought hard for one of these criteria to be the disclosure of how long the product will receive security updates. I hope that, besides arming consumers with better information, the commitments on this label (including the support period) will be legally enforceable in contract and tort lawsuits and under other laws. You can see my full statement here [3].

> But it’s too early to declare victory. Many manufacturers oppose making any commitments about security updates, even voluntary ones. These manufacturers are heavily engaged at the FCC and represented by sophisticated regulatory lawyers. The FCC and White House are not likely to take a strong stand if they only hear the device manufacturer's side of the story.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#63
post #17
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.

It allows users to replace insecure software with secure software. And it allows updates long after the company drops official support of the device.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#64
Consumers consistently vote with their wallets on this, and based on their behavior, they don't care.

They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more.

If you want to make a difference, an FCC sticker won't do it. Consumers will go for the cheaper one without the sticker. You'll have to mandate whatever minimal level of support you want these companies to provide.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#65

We’ve seen manufacturers abuse ongoing access to devices to turn off features the device came with at the time of purchase or convert one-time-fee features into subscriptions. One of my concerns is that security updates are strictly defined in a way that prevents this type of regulation from being used as cover for these shenanigans.

I'm not a US citizen, but I too would cosign the idea of not using security updates as a vector for pushing monetization "features".

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#66
At the very least, manufacturers should have to notify all users or via press release when a product has been compromised or can be compromised via a known attack, with maybe some required details like the severity of the breach and possible outcomes.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#67
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

This is also a key point to fighting ewaste and making devices last longer. I have appliances from the 70s including a rotary telephone, that I still use regularly. If you combined mandatory OSS support with repair cafes, you would have a model for sustainable reuse and better security. You may even start a commercial aftermarket in reflashing older devices!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#68

Awesome! Thanks for engaging, where the rubber meets the road! Hopefully, you are also looking into other venues, as well. HN has a great group of folks that represent some of the most cutting-edge tech, but IT runs on Java 8[0]. [0] https://news.ycombinator.com/item?id=19877916

Thanks for participating! After this thread winds down, I and my team are going to comb through it for suggestions and take as many as we can. We're also looking into other venues to engage directly with cybersecurity professionals. But please feel free to comment on the record as well -- a robust and detailed record is worth a lot more than whatever I can do individually.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#69

What makes IoT devices special, and warrants carve outs for security / vulnerabilities? I guess I am not surprised there are security issues with these devices, because I think of most of them as coming from small companies, and wonder what the impact would be on the IoT space if only large players can work through more regulation. That said, I can't decide if I am more concerned about my Wyze camera sending data whe…

From the Cyber Trust Mark perspective, there's no inherent difference between a connected disposable gizmo and your example of the water heater. Personally, I would love to see a minimum cybersecurity commitment made by anyone who makes or sells anything with connectivity.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#70

Earlier quoted context omitted.

As far as I remember FCC about 8 years ago didn't liked OpenWRT, and even enforced on TP Link to lock it.

IIRC the main objection was that it could be used to do something with the radio (boost power?) that caused the device to exceed FCC limits for a consumer radio? Something along those lines?

For those out of the loop these documents have a good introduction to how free software interacts with radio regulations

https://wireless.wiki.kernel.org/en/developers/regulatory/st... https://wireless.wiki.kernel.org/en/developers/regulatory

TLDR manufacturers and "serious" companies won't touch anything that could potentially be configured to emit signals that your local government doesn't like. So Linux has to pretend it doesn't allow to do that (even though anyone with 2 braincells can patch it)

Post reply on HN