Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

141–150 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#141
>> If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it. I fought hard for one of these criteria to be the disclosure of how long the product will receive security updates.

I think labeling may be a good idea. Requiring updates is probably not a great idea. For most of my things I prefer they not auto-update, as that invites another whole world of problems.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#142
post #10

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…

A big issue with botnets running on device owner equipment is the amount of bandwidth they "steal" from the device owner. Especially for device owners who are on constrained networks (such as a mobile/satellite network) this can be a really expensive issue for the device owner.

So while the device owner may not be the primary victim, they can definitely still be heavily affected.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#143
post #10

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…

Even if consumers don't necessarily care about security, required labelling gives brands an opportunity to stand out from one another. If I'm looking at two products on the shelf, where one claims to have greater security, and the other makes no such claim, I'm likely to buy the more secure one, even if I don't necessarily care much about security. If getting the secure label is relatively cheap (which it should be,…

oh man, you sound like the type of person that would fall for the intentionally misleading labels that makes it sound like one thing but is in fact absolutely not that thing. just yesterday, there was a link to an article about the lies on food packaging.

so, labeling requirements are one thing, but requiring that the information is straight forward and leaves no options for misleading would be great. I just don't think there's ever going to be a way from preventing someone from finding loopholes.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#144
post #10

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…

In order to make it a consumer problem, we'd have to make it a criminal violation to participate in a botnet. We could make it a punishable infraction I suppose, much like a speeding ticket for automobiles, but somehow I just don't see this happening in a coordinated fashion across the world.

I think it is already illegal to participate in DDOS. Even though enforcement is .. pretty much nonexistent? And how could you enforce it? It would create an outcry if done consequently. (But maybe a neccessary one)

But it also will be a consumer problem, if they cannot access important services anymore, because their IP has been blacklisted, because their toaster participated in too many DDOS or spam attacks.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#145
post #17

Earlier quoted context omitted.

I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.

Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.

replacing the firmware can allow knowledgeable users who want to secure their devices to improve the security. it can also allow malicious actors to replace the firmware (or trick users into replacing the firmware) with something less secure. allowing users to replace the software on the hardware they own is also a botnet waiting to happen.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#146
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

30 years of expected support is pretty unreasonable. Stating a requirement like this makes the discussion about competing dogmas. Rather, it's about the right way to keep devices operational as long as possible while also allowing companies to remain possible.

30 years of support expectations immediately makes the cost of any device go up to hedge against the risk of fines during the entire 30 years. It also makes it harder to disrupt an industry with hardware at its core.

I don't have a single computing device that has lasted longer than 10 years. Reasonably speaking, either performance or features start to make the device largely obsolete and unusable.

I think a better way to propose this would be the expectation that when a product is EOL, it should be supportable by the buyer for a certain period. This requires figuring out the right period of support. I'd propose something that scales period based on cost or device class. A $1200 phone should be usable for 10 years while a $10 disposable glucose sensor with a battery should not.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#147
post #19

FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…

> There is no such thing as computer security in 2023

This is absurd.

Even the passive basics like relying on your free email provider's filtering and running Windows Defender is going to stop a huge number of attacks.

If you're expecting perfect security, you'll be disappointed -- but we can't declare complete bankruptcy.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#148

Earlier quoted context omitted.

I don't think it has to be part of the network interface. You could have an ethernet-connected device that emits RF for some non-networking purpose and I think it would still qualify.

But if I have an ethernet-connected device that doesn't emit RF for some non-networking purpose, it should still qualify. It should just need the transducer and a network connection.

I don't think it would for this specific proposal. The FCC's justification for this rule is that insecure IoT devices "could be manipulated to generate and emit RF energy to cause harmful interference". That's why they have jurisdiction here, because they regulate radio frequency use.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#149
post #96
post #19

FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…

> It'd be like putting a "secure against bricks" sticker on a window. I lived in a house that had such secure windows. I even witnessed someone trying and failing to smash a window with a brick.

we installed a storm door not for protection against storms, but an intruder armed with a brick and/or hammer because our front door was 85% single pane of glass.

it seems like a bad analogy on the GP's part

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#150
>Many manufacturers oppose making any commitments about security updates, even voluntary ones. These manufacturers are heavily engaged at the FCC and represented by sophisticated regulatory lawyers.

Gee, I wonder if this has anything to do with the corrupt people like Ajit Pai?

Sincerely - after the Ajit Pai debacle and the fraudulent selling off bandwidth rights, I literally dont trust the FCC with anything...

So, prove to me the FCC actually understands IoT?

Basically youre attempting to regulate a swarm of GNATs and how they should behave, without understanding how they are born...

look at Moores Law as it pertains to surveillance and fraud tech ; The size of cameras, the power of IP enabled wireless talking devices (regardless of protocol/tech/mech) is so incredibly small and easily, cheaply replicated in any cheap-tech-state (china, and many other places we dont talk about) - makes it such that one can only assume that they are under 100% surveillance 100% of the time...

THAT is what you should be regulating - the scanning of an area for detection of IoT device transmissions

Think of Purple (brand) air quality monitors, a frequency field monitor for all RF transmissions in a given area (as can be heard) would be great, with sensors for adding to such monitoring that can RSSI triangulate the location of devices.

Think of Apple Air-Tags...

If you had cell phones all reporting RF triangulation signals - you could map out the IoT problem, frequencies, locations, targeted devices/tech etc...

Post reply on HN