Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

161–170 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#161
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

Openwrt is not the best example. Community sucks, some routers are full of bugs and the security is not great either.

In general even if I like open devices and having the option to use my own software, this is not a solution for most of the consumers.

It is not a solution even for the enthusiast that know how to flash their own firmware. Because even if they may do it a few times initially, eventually they stop doing it.

You need a system that can update automatically even when you are busy in another project.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#162
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

> either they must provide full (FLOSS) source code and documentation I like the spirit of this, but one problem with this is that the software stack is likely not FLOSS, and the manufacturers don't own all the software. A second problem is that lot of the software for production IoT-devices doesn't live in the device. Third, there are safety concerns with a lot of devices that you'd need legal productions for. Final…

I'm working on an IoT device for industrial use, and we're wrestling with this very problem.

The answer we're probably going to go with is that the device is 'leased' to the customer. It's part of their subscription.

This solves a ton of problems about FLOSS and support of the same. It's now a closed device, and you have no rights to the code inside. If we go out of business, you have a brick that you don't have to pay for anymore.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#163
This economy seems to consist largely of cheaply made products with high profit margins. You're attacking profit margins, so good luck with that. Sorry for the pessimism but this country just derailed the FTC attempt to abolish non-competes because it would cost law firms business.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#164

Earlier quoted context omitted.

Even if consumers don't necessarily care about security, required labelling gives brands an opportunity to stand out from one another. If I'm looking at two products on the shelf, where one claims to have greater security, and the other makes no such claim, I'm likely to buy the more secure one, even if I don't necessarily care much about security. If getting the secure label is relatively cheap (which it should be,…

oh man, you sound like the type of person that would fall for the intentionally misleading labels that makes it sound like one thing but is in fact absolutely not that thing. just yesterday, there was a link to an article about the lies on food packaging. so, labeling requirements are one thing, but requiring that the information is straight forward and leaves no options for misleading would be great. I just don't th…

There are a couple of NIST papers on specifics for labels:

https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.02042022-2.... https://www.nist.gov/itl/executive-order-14028-improving-nat...

They're in FN 20 of the linked proposal for rulemaking (which is 48 dense pages and which I don't expect anyone here to have had a chance to read yet.)

If you find yourself skeptical about the NIST proposals, please feel free to comment on the record!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#165
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

I favor something like this, if less strong. It should be required that a product that reaches end-of-life as defined by the manufacturer should have all documentation and source code released and open sourced; prior to end-of-life (and perhaps for one year after), they're required to provide security updates. The manufacturer is then free to decide the point at which closed source is no longer worth the maintenance cost.

A few additional thoughts:

- Perhaps hardware design/specs should be released as well?

- A government body should probably host this information after EOL.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#166
post #140

Earlier quoted context omitted.

I've been not-buying IOT trash as hard as I can for decades. But nothing's changing... please tell me how to do this correctly!

Well, lots of people have been not-buying liquorice their whole life, but nothing's changing. The market for liquorice candy is alive and well. Less snarky: if other people still want to buy certain products, manufacturers will provide. But that's not a bad thing. Different folks have different preferences.

Why did you suggest not-buying as a better action than regulation if you acknowledge that it doesn't work? Are you a manufacturer of low-quality IoT devices? People don't prefer insecure devices, they just want convenience and manufacturers are not being upfront about how dangerous these "convenient" devices are. Ergo, regulation.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#167
post #19

FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…

I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glass, and get a sticker from the US Government saying so, it better be brick-proof.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#168
post #124

Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…

You could regulate they have to patch any outstanding CVEs for their device/firmware but enforceability might be difficult.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#170
post #71

Earlier quoted context omitted.

The free market hasn’t figured it out, as evidenced by the decade of half-working devices consumers are left with. There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up.

> There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up. If customers want it, there is a way: use contract law to commit the manufacturer. That's already the norm for enterprise grade equipment. Companies often pay more for their hardware to get guaranteed long term support. So the market is willing and able to provide this kind of service, when people vo…

Contract law actually is pretty universally used the other way around, to prevent you from updating. I have several old Android phones with locked bootloaders that I couldn't legally update even if the manufacturer hadn't locked the bootloader. I don't have access to the source code or the signing keys. I'm not sure the signing keys even exist anymore.

And I can't buy a phone with the contract terms I want, they simply don't exist and can't exist unless the government forces companies to offer such terms. (They exist if you're buying thousands, maybe, but I just want one for personal use.)

Post reply on HN