I think labeling may be a good idea. Requiring updates is probably not a great idea. For most of my things I prefer they not auto-update, as that invites another whole world of problems.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
141–150 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#142> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…
So while the device owner may not be the primary victim, they can definitely still be heavily affected.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#143> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…
Even if consumers don't necessarily care about security, required labelling gives brands an opportunity to stand out from one another. If I'm looking at two products on the shelf, where one claims to have greater security, and the other makes no such claim, I'm likely to buy the more secure one, even if I don't necessarily care much about security. If getting the secure label is relatively cheap (which it should be,…
so, labeling requirements are one thing, but requiring that the information is straight forward and leaves no options for misleading would be great. I just don't think there's ever going to be a way from preventing someone from finding loopholes.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#144> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…
In order to make it a consumer problem, we'd have to make it a criminal violation to participate in a botnet. We could make it a punishable infraction I suppose, much like a speeding ticket for automobiles, but somehow I just don't see this happening in a coordinated fashion across the world.
But it also will be a consumer problem, if they cannot access important services anymore, because their IP has been blacklisted, because their toaster participated in too many DDOS or spam attacks.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#145Earlier quoted context omitted.
I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.
Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#146Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…
30 years of support expectations immediately makes the cost of any device go up to hedge against the risk of fines during the entire 30 years. It also makes it harder to disrupt an industry with hardware at its core.
I don't have a single computing device that has lasted longer than 10 years. Reasonably speaking, either performance or features start to make the device largely obsolete and unusable.
I think a better way to propose this would be the expectation that when a product is EOL, it should be supportable by the buyer for a certain period. This requires figuring out the right period of support. I'd propose something that scales period based on cost or device class. A $1200 phone should be usable for 10 years while a $10 disposable glucose sensor with a battery should not.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#147FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…
This is absurd.
Even the passive basics like relying on your free email provider's filtering and running Windows Defender is going to stop a huge number of attacks.
If you're expecting perfect security, you'll be disappointed -- but we can't declare complete bankruptcy.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#148Earlier quoted context omitted.
I don't think it has to be part of the network interface. You could have an ethernet-connected device that emits RF for some non-networking purpose and I think it would still qualify.
But if I have an ethernet-connected device that doesn't emit RF for some non-networking purpose, it should still qualify. It should just need the transducer and a network connection.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#149FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…
> It'd be like putting a "secure against bricks" sticker on a window. I lived in a house that had such secure windows. I even witnessed someone trying and failing to smash a window with a brick.
it seems like a bad analogy on the GP's part
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#150Gee, I wonder if this has anything to do with the corrupt people like Ajit Pai?
Sincerely - after the Ajit Pai debacle and the fraudulent selling off bandwidth rights, I literally dont trust the FCC with anything...
So, prove to me the FCC actually understands IoT?
Basically youre attempting to regulate a swarm of GNATs and how they should behave, without understanding how they are born...
look at Moores Law as it pertains to surveillance and fraud tech ; The size of cameras, the power of IP enabled wireless talking devices (regardless of protocol/tech/mech) is so incredibly small and easily, cheaply replicated in any cheap-tech-state (china, and many other places we dont talk about) - makes it such that one can only assume that they are under 100% surveillance 100% of the time...
THAT is what you should be regulating - the scanning of an area for detection of IoT device transmissions
Think of Purple (brand) air quality monitors, a frequency field monitor for all RF transmissions in a given area (as can be heard) would be great, with sensors for adding to such monitoring that can RSSI triangulate the location of devices.
Think of Apple Air-Tags...
If you had cell phones all reporting RF triangulation signals - you could map out the IoT problem, frequencies, locations, targeted devices/tech etc...