Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

111–120 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#111
post #40

Earlier quoted context omitted.

Exactly. I don't see the situation improving until either the owner or, preferably, the manufacturer of a device that participates in a DoS attack is held partially accountable for said attack.

Well, you can't hold somebody accountable if there isn't even a label or information somewhere saying that what they are doing is dangerous.

Sure you can. For example, we have vehicle codes that hold people accountable for dangerous driving.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#112

While the IoT security situation is out of control I doubt that regulating security updates will have any other result than radically reducing competition and innovation in the space by making it impossible to operate as a small company. It will simply push more hardware innovation out to China. Having worked in the space I came to the conclusion the only viable secure future is to adopt star topology local networks…

> The only corporate actors I encountered that understood this were the Taiwanese OEMs, who are remarkably on point and blunt behind closed doors, but they are basically powerless to do anything about it.

Fascinating! Could you elaborate?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#113

Consumers consistently vote with their wallets on this, and based on their behavior, they don't care. They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more. If you want to make a difference, an FCC sticker…

> based on their behavior, they don't care.

Personally I see it as "based on their behavior, they don't understand"

We also need far more computer/tech literacy in the education system and populace.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#114
post #62

Earlier quoted context omitted.

What's stopping hobby/micro-developers from saying 'Not FCC approved, use at own risk'? I hack on ESP32 devices, I certainly have different expectations as a hobbyist and as a consumer or consultant.

> What's stopping hobby/micro-developers from saying 'Not FCC approved, use at own risk'? OP is. Or rather, he wants to make it impossible to opt out. At least that's how I interpret these two paragraphs: > The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. If they meet certain criteria for the security of their product, manufacturers can put an FCC…

Sorry for any confusion. The relevant language:

If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it.

So if they don't, they can't put the label. That's all.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#115

These rules sound like reasonable steps, upon first reading. Not sure what the downstream effects might be. Is there any thought given to cloud based devices becoming paperweight when companies behind them just stop supporting it or turn off the API? I'd like some "assurances" in place that if the company either goes out of business or decides to sunset the service, it would be required to open source (or at least ma…

[deleted]

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#116
post #10

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…

I think you are underestimating how a well known „secure“ label (or lack thereof) could influence customer behavior. It’s not that they don’t care - they (understandably) lack deeper knowledge and therefore don’t base their purchasing decisions on how long they will get updates. „If sticker X is not on the package I will get hacked“ is much easier to grasp.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#117

Earlier quoted context omitted.

I don't like the quoted wording. I would like it to be clearer that the RF part isn't part of the transducer, but part of the network interface.

I don't think it has to be part of the network interface. You could have an ethernet-connected device that emits RF for some non-networking purpose and I think it would still qualify.

But if I have an ethernet-connected device that doesn't emit RF for some non-networking purpose, it should still qualify. It should just need the transducer and a network connection.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#118
I added a comment voicing support. I also added concerns about only being able to update devices through specific ecosystems. I use Home Assistant at home, and many devices will only update through the likes of Google Nest or Alexa - rendering them unsupported on day 1. I was lucky enough to know not to purchase devices that have this issue, but many home owners could find this out the hard way. Firmware should be available from a publicly accessible location.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#119
post #45

Many of these devices are made in China, even if designed and sold by American companies. Nearly all contain Chinese made parts. These are network devices with sensors and various behaviors. Given the tension between USA and China, especially in the cybersecurity realm - what about making the case based on US national security (in addition to consumer protection)?

Sounds like a case of protectionism?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#120

I can't file because I'm not based in the US, but I'd love to see smartphones, tablets and similar devices to be covered as part of IoT in general, as they share the most important of the characteristics - the manufacturer sells a device connected to the Internet. There are multiple issues that I think need urgent regulatory attention, and the issue classes are valid for both "classic" IoT devices and phones: 1. Manu…

Re your point 4 in particular, I feel your pain -- I said "exposed public keys, expired certs" in the OP for a reason. The current item doesn't contemplate a requirement to tie these off as such, but I'd be interested to see if commenters ask for this as part of getting a stronger label.

Thanks for your response!

To add on the "label" point: I don't think labels are enough, not in a world where consumers (private, commercial and governments) primarily look at the price in purchase decisions. At least a base set of legally binding requirements must be established.

ETA: I'd also love to see an exception for small scale / startups. Like < 1000 units sold per model and year. That allows quick iterations while the large offenders still have to comply.

Post reply on HN