Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

71–80 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#71
post #8

Hurrah, more red tape! Please let customers opt out of your proposed protection, if they want to. (And it sounds like that's already the status quo. So perhaps you could use your time to figure out where you can cut obsolete and cumbersome regulations instead of adding more mandatory bureaucracy that customers evidently don't want enough to pay for voluntarily?) There might be an argument to be made about negative ex…

The free market hasn’t figured it out, as evidenced by the decade of half-working devices consumers are left with. There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up.

> There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up.

If customers want it, there is a way: use contract law to commit the manufacturer.

That's already the norm for enterprise grade equipment. Companies often pay more for their hardware to get guaranteed long term support.

So the market is willing and able to provide this kind of service, when people vote with their wallets.

> The free market hasn’t figured it out, as evidenced by the decade of half-working devices consumers are left with.

The free market hasn't provided me with a flying car either. But that doesn't mean the market has failed. And I don't think using bureaucracy to ban any company that doesn't want to sell me a flying car would be an improvement on the status quo.

(To be more explicit: many people, including me, think a flying car would be fun. But we don't want it badly enough to be willing to pay what it would take. And that's why suppliers only offer normal cars, not the flying kind.)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#72

There are too many IoT devices that want my email/phone just to perform what normal devices have been able to do for decades. No, I don’t want to download an app just so I can use my apartment stationary bike. I get enough spam already, and I don’t want to agree to a long terms and conditions just for that. In that case I couldn’t even use the bike at all without creating an account. I think a lot of places got duped…

This is a great point. What are your thoughts on requiring a switch on all IoT devices so the consumer can flip a switch and their "smart Widget" just becomes a "widget"? This would be a nice for both security perspective and a consumer perspective.

An insecure e-stationary bike should just become a stationary bike rather than a 100-pound pile of trash.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#73
post #29

> I’ve advocated for the FCC to require device manufacturers to support their devices with security updates for a reasonable amount of time [1]. No offense intended, but I would be worried about this more than I would be worried about the current state of the IoT world. A blanket requirement would punish hobbyists and small companies prototyping new technologies. But big players could spend relatively minor technical…

[deleted]

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#74

Voluntary certification, please. Law is slower than technology. This is a good thing! EnergyStar is a great example of a voluntary program doing more good than DoE or FTC mandates. HIPAA is a good example of what happens when mandates can’t keep up with technology. When it comes to security, we can’t afford another HIPAA.

100% agree! This is a totally voluntary program that is explicitly based on EnergyStar.

I also worry that check-the-box compliance is one possible outcome. I'd love to see professionals comment on the record about where a checklist would and wouldn't be helpful. I'd also love commentary on if and where liability for failure to meet stated commitments would be helpful.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#75
What about industrial IoT?

Even if a manufacturer publishes updates, the clients would likely not want to change anything, often.

If you have a plant with 1,000 units of gizmo-A and update them during a week-end and now 200 of them do not do the thing they used to do anymore... you have a big problem.

There is a genuine fear to update anything in many industries and I am not sure how this can be overcome.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#76
I can't file because I'm not based in the US, but I'd love to see smartphones, tablets and similar devices to be covered as part of IoT in general, as they share the most important of the characteristics - the manufacturer sells a device connected to the Internet.

There are multiple issues that I think need urgent regulatory attention, and the issue classes are valid for both "classic" IoT devices and phones:

1. Manufacturers often do not state anything about support: availability of spare parts, feature updates, security updates. Even those that do, like Google's Pixel lineup, have ridiculously short times, and "enterprise" devices like my Samsung Galaxy Tab Active 3 that's 2.5 years old don't have spare screens available any more. I bought an "enterprise" device in the hope that it would have a better supply chain than consumer devices, but I was mistaken.

2. Many devices with batteries are sold without the ability to easily replace them or without officially sanctioned spare parts, which causes a risk of people running devices with swollen or otherwise damaged batteries, or devices living way shorter than they could be because batteries can and do simply lose capacity.

3. Many devices are completely locked down. This is particularly relevant for SSL root certificates whose expiry leads to devices being bricked, or for people who simply would like to enjoy the freedoms of the GPL and other FOSS licenses but can't because custom firmware can't be installed at all (due to Secure Boot) or permanently bricks features out of DRM concerns (e.g. Samsung Knox, Netflix, banking and many other apps that refuse to run on rooted or otherwise modified devices).

4. Many devices' BSPs (board support packages) are littered with ridiculously old forks of stuff like bootloaders, the Linux kernel or other userland software, and the chip/BSP vendors and manufacturers don't give a fuck about upstreaming their changes or code quality is so bad it cannot be reasonably upstreamed.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#77
post #37

[flagged]

He's one of the Republican FCC Commissioners, so yes, you can safely assume he's using the role primarily to work against most Americans' interests in favor of corporate executives, just as Pai did. However, I don't see that obviously being the case in this particular discussion, so I think it's OK to stay on topic.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#79

Earlier quoted context omitted.

As far as I remember FCC about 8 years ago didn't liked OpenWRT, and even enforced on TP Link to lock it.

IIRC the main objection was that it could be used to do something with the radio (boost power?) that caused the device to exceed FCC limits for a consumer radio? Something along those lines?

It was about the radio and being able to modify the radio firmware.

As many modifications would void the FCC certifications of the device, due to changed parameters (more power, disabled anti-interface mitigations, out-of-band channels, etc.). This was avoided by making the radio firmware separate blobs, but there was a real danger of the whole device having to have signed firmware.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#80
post #10

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…

Sounds like you are making an argument based on externalities.

That's fine. But economic theory also gives you standard answers for externalities:

Don't ban the behaviour you dislike. Either let people sort it out themselves (like the Coase Theorem https://en.wikipedia.org/wiki/Coase_theorem describes), or at most tax the offending behaviour.

Post reply on HN