Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

121–130 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#121
post #55

How about requiring devices to implement key security-relevant features in an immutable way, such as via FPGA, so that attackers have no way of circumventing those features even post EoS.

Good luck patching security problems then?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#122

Earlier quoted context omitted.

99% of users don't know their iot devices have firmware nor that it can be updated.

Maybe that figure would change if the firmware could indeed be updated.

It would change, but again -- it wouldn't be appreciable.

Security policy is needed that accounts for the behaviors of the vast majority of users.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#123
Speaking as someone who has several cheap cameras gathering dust in a box because I no longer trust them with network access...

...manufacturers are simply never going to be incentivized to take security seriously. The best you can hope for with a regulatory approach is to incentivize them to pay more lip-service to the idea, while hiding their backdoors better. Their incentive to spy on users is simply too profitable.

(And, the legal environment is such that users can simply click-wrap away literally anything. If the terms say you agree to let the manufacturer monitor your conversations, guess what, it's no longer spying. Perhaps any such language, in the built-in firmware OR IN ASSOCIATED APPS, should immediately make a device ineligible for a favorable label.)

Only users ourselves, actually have users' interests at heart. The only meaningful improvements in security that I've ever seen in the wild, have been with open-source firmware that completely replaces the device's own. Not a shim on top that adds functionality while preserving the OEM's backdoors, but a complete ground-up replacement.

Therefore, the most meaningful step would be to require support for open-source firmware. Providing all the data such that open-source drivers can be written, providing a working build-environment, and making it easy to install user-provided firmware, would go a long way.

Then once the device is fully supported in the mainline distro of a mainstream FOSS project, its label could indicate that support may extend beyond the manufacturer's whims or even existence. And since the label wants to be affixed at time of sale, the incentive is on the manufacturer to get this support work done before they even ship.

Also, require a meaningful cybersecurity response. That is, they have a disclosure contact, they work with researchers to fix vulnerabilities under standard timelines, they pay bounties that make it worth researchers' time rather than incentivizing them to sell their vulns, and they check related products for similar vulns rather than playing perpetual whack-a-mole.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#124
Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing material.

A bigger issue than the available of updates is whether security updates are automatic and mandatory, or optional for the user. If a security update requires some action on the user's part, most users won't want it.

The overall problem is that the main IoT security problem is botnets, not insecure devices per se. A botnet does not affect the owner of a device very much. Thus, the owner of a device usually prefers an insecure device, rather than taking some risk of the security update breaking the device.

I'm not sure what the FCC should do here. It seems reasonable to hold the manufacturers of devices responsible in some way when those devices are used in a botnet, but I'm not sure if that's within the FCC's scope.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#125
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

> either they must provide full (FLOSS) source code and documentation

I like the spirit of this, but one problem with this is that the software stack is likely not FLOSS, and the manufacturers don't own all the software.

A second problem is that lot of the software for production IoT-devices doesn't live in the device.

Third, there are safety concerns with a lot of devices that you'd need legal productions for.

Finally, the best IoT devices use a zero-trust architecture. You'd need to support a variation of this pattern to allow users to modify the devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#126
post #84

Earlier quoted context omitted.

You as a customer can already give the manufacturer that choice, and simple refuse to buy from any manufacturer that doesn't comply.

Consumer's power is not the same as FCC's

Indeed. And that's good.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#127

Consumers consistently vote with their wallets on this, and based on their behavior, they don't care. They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more. If you want to make a difference, an FCC sticker…

> based on their behavior, they don't care. Personally I see it as "based on their behavior, they don't understand " We also need far more computer/tech literacy in the education system and populace.

In a healthy person, caring should pretty surely imply efforts to research the topic and eventual understanding.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#128

There are too many IoT devices that want my email/phone just to perform what normal devices have been able to do for decades. No, I don’t want to download an app just so I can use my apartment stationary bike. I get enough spam already, and I don’t want to agree to a long terms and conditions just for that. In that case I couldn’t even use the bike at all without creating an account. I think a lot of places got duped…

This is a great point. What are your thoughts on requiring a switch on all IoT devices so the consumer can flip a switch and their "smart Widget" just becomes a "widget"? This would be a nice for both security perspective and a consumer perspective. An insecure e-stationary bike should just become a stationary bike rather than a 100-pound pile of trash.

My opinion is that a stationary e-bike should be a stationary bike whether or not the wifi is connected, and then I can choose whether I want to connect it online. I don’t think a switch is necessary, just don’t connect the thing.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#129
post #116
post #10

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…

I think you are underestimating how a well known „secure“ label (or lack thereof) could influence customer behavior. It’s not that they don’t care - they (understandably) lack deeper knowledge and therefore don’t base their purchasing decisions on how long they will get updates. „If sticker X is not on the package I will get hacked“ is much easier to grasp.

> „If sticker X is not on the package I will get hacked“ is much easier to grasp.

Hmm. In the grocery store, where this idea comes from and has the most persuasive history in govt. regulation, where manufacturers own the front of the package and regulators own the back, what is the healthiest food?

The produce and meat. Which has no nutritional label.

There's no such thing as a secure IoT device. There's absolutely no such thing as a secure connected device that is also cheap.

If you build your computer from commodity parts, it tends to be the longest lasting and most secure. It is usually the most expensive.

Anyway, what would the label for a PlayStation 5 and an iPhone 15 look like? Miles long.

Then, for the consumer buying the cheapest smart plugs off Amazon? Like one paragraph the vendor copied and pasted from the Internet, along with all the other legal shit they deal with.

Whom should be regulated? I guess Amazon and Walmart, the retailers, they are the real gatekeepers. That's what the EU does! Which doesn't fly here. The Waltons live here, not in the EU.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#130
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

My two cents is that this would be an excellent comment on the record -- I'd love a discussion at the level of defining security risks to be part of the official federal commentary, because this is going to be a thorny implementation problem.
Post reply on HN