Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

151–160 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#151

Speaking as someone who has several cheap cameras gathering dust in a box because I no longer trust them with network access... ...manufacturers are simply never going to be incentivized to take security seriously. The best you can hope for with a regulatory approach is to incentivize them to pay more lip-service to the idea, while hiding their backdoors better. Their incentive to spy on users is simply too profitabl…

manufacturers are simply never going to be incentivized to take security seriously

I worry about this too, and it's one thing when it's a camera but another when it's a car, or electrical grid equipment, or chemical process controls, etc. You make a great point re clickwrap, and clearly clickwrapping your rights away should be something that we don't readily allow for a manufacturer receiving the federal benefit of a marketing label.

It could be that even a top-tier label will turn out to be meaningless. That would mean that we'd need to have "harder" regulation or that people would start demanding dumb devices. I hope that industry will respond productively to this voluntary effort so that the public doesn't get harmed and we are able to benefit from the real advantages of connectivity that's also secure.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#152
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

I'm a big supporter of the idea of applying right to repair principles to software, but I don't think it should (or legally can) be implemented by fiat of unelected bureaucrats at the FCC. Labeling requirements like what the OP is proposing seem much more palatable to me.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#153

Has much consideration been given to labeling when a third party cloud or paid service is required to use the device? As somebody who uses IoT devices "locally" on my private network, I want to know my data will stay local and protected. The recent issues with Eufy doorbells claiming to be under local control [and encrypting data], but actually sending data to the cloud stands out to me as an example where labeling a…

Right now, the actual requirements for a label are totally up for grabs. This would make for a good public comment, in my opinion.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#154
Strange that in such a popular country this is so late.

> Defining the Internet of things as "simply the point in time when more 'things or objects' were connected to the Internet than people", Cisco Systems estimated that the IoT was "born" between 2008 and 2009, with the things/people ratio growing from 0.08 in 2003 to 1.84 in 2010.[29]

(https://en.wikipedia.org/wiki/Internet_of_things)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#155
post #19

FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…

This take is simply not based in reality. Compare what it took to gain root access to a computer 20 years ago to a modern iPhone and tell me again that there is absolutely no point in caring about security.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#156

Earlier quoted context omitted.

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

I would like to add most of the IoT problem is no patches at all. The firmware they get is usually bog standard with some very minor tweaks out of china somewhere. It is a problem of vendor locked in products where you have to buy a hub to do an update. If there even is an update. If you want to get a good picture of how sideways updating can even be watch the linus tech tips on where he wanted (and has the tech abil…

Re: the licensing issue, companies wanting to put a label on their product would probably want to extract similar guarantees up their supply chain. Especially with a voluntary program like the one the FCC is proposing, good practices won't become the norm across the market overnight. But maybe, at the very least, the segment of product and component makers that take security seriously will begin to grow. I encourage you to share your thoughts in an official comment.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#157
post #62

Earlier quoted context omitted.

> What's stopping hobby/micro-developers from saying 'Not FCC approved, use at own risk'? OP is. Or rather, he wants to make it impossible to opt out. At least that's how I interpret these two paragraphs: > The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. If they meet certain criteria for the security of their product, manufacturers can put an FCC…

Sorry for any confusion. The relevant language: If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it. So if they don't, they can't put the label. That's all.

Well, making a voluntary sticker to opt-in to certain legal obligations is fine.

But you are saying already that manufacturers don't really want to commit to anything? What makes you think the sticker would change that?

(In principle, I'm all for manufacturers offering more warranties. But when it comes to spending money, privately I almost never opt for the enterprise grad hardware that does come with warranties like long term guaranteed support.

Instead I rely on reputation, eg that Google will keep providing security updates for their Pixel phones for a few years as they have done in the past, even if there's no legal obligation for them.

And I wouldn't want any regulation to take that choice away from me. I'm glad to have escaped the EU where appliances are more expensive, partially because manufacturers are forced to include a two year warranty with each device.)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#158
The issue seems to be wider than just abandoning support on IoT. IoT device abandonment is a real problem, but you can aim higher. Software written for hardware is generally of poor quality.

There is an insightful HackNews thread from three days ago about the subject. I hope it will add some more insight into the scope of the issue: https://news.ycombinator.com/item?id=37352970

My 2 cents would be: treat software defects like hardware defects. Pass legislation to force manufacturers to provide a warranty for at least 2 years. Pass rules which favor the consumer ruthlessly. Button was not constrasty enough - refund. Text label caused the user to misinterpret the action - refund.

Perhaps the additional accountability during the early days of a device will have a positive impact on the longer-term longevity. If prices are forced to go up a bit in order to provide better support, there will be more money for higher-quality software.

Don't limit this to IoT devices. Manufacturers will find ways to skirt whatever way "IoT" gets defined. Make whatever rules you create apply very broadly to all devices with embedded software.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#159
post #84

Earlier quoted context omitted.

You as a customer can already give the manufacturer that choice, and simple refuse to buy from any manufacturer that doesn't comply.

A relatively small group of people won't have an effect, that's why regulation plays an important role.

Perhaps we should respect the wishes of the large rest of the people who are outside that relatively small group?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#160
post #88

Consumers consistently vote with their wallets on this, and based on their behavior, they don't care. They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more. If you want to make a difference, an FCC sticker…

> If you want to make a difference, an FCC sticker won't do it. Consumers will go for the cheaper one without the sticker. You'll have to mandate whatever minimal level of support you want these companies to provide. Or you could respect the customers' revealed preference?

For many products, I'd agree. For things that can affect public safety or shared, publicly owned or essential resources like network connections, use of radio spectrum, etc. we've long accepted that regulations are necessary so that the services can be available to everyone and provided safely.
Post reply on HN