Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

191–200 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#191
post #126

Earlier quoted context omitted.

Consumer's power is not the same as FCC's

Indeed. And that's good.

It's good that consumers have much less power in context of forcing manufacturers to the described choice?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#192
post #19

FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…

I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glass, and get a sticker from the US Government saying so, it better be brick-proof.

Well, my comment is predicated on the, apparently erroneous :), assumption that no glass is brick-proof. It is impossible to build a secure software product with our current tooling & development practices. The number of security flaws in every software product is so high as to make the label meaningless. I don't think there's a meaningful distinction to end consumers between "this product has 1,000 holes, 100 of which are publicly disclosed" (i.e. no label) and "this product has 900 holes" (i.e. with label).

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#193

IoT devices need regulatory standardization w.r.t a few things: 1. software stack – big fat "firmware" should not exist. Entire stack should be upgradable safely, securely and frequently during its official supported lifetime and should be open-sourced for owner's own upgrades past end of life. For this, the hardware stack needs some amount of standards compliance. 2. Vendor should clearly declare/advertise the perio…

> 3.3 IoT should not accept inbound communication without authentication.

Ideally the user should have to specifically consent to inbound communication on an instance-by-instance basis, even from the manufacturer. There's many cases where forced updates are triggered that change/limit functionality unexpectedly. There's numerous anecdotes of people's devices being required to update to be used while they have some pressing need to use it.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#194
post #124

Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…

You could regulate they have to patch any outstanding CVEs for their device/firmware but enforceability might be difficult.

Not all CVE are real vulnerabilities.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#195

From the speech: > Wi-Fi deauthentication attacks, which can render useless every Wi-Fi network in an area, can be carried out by a single device with a Wi-Fi antenna. Is the prevention of such attacks within the mandate of the FCC (so long as all other relevant RF parameters are adhered to in the device)? I understood that unlicensed ISM users must not cause interference to licensed users, and they must be tolerant…

In the 2010s, the FCC began enforcement proceedings against more than one hotel chain for using Wi-Fi deauthentication attacks against guests using their own Wi-Fi hotspots instead of the official hotel Wi-Fi networks. The claims were settled, so there's no court ruling on the matter, but our office is inclined to believe that the FCC has legal authority over such attacks. But we definitely encourage you to share your views on the record.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#196
post #19

FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…

> There is no such thing as computer security in 2023 This is absurd. Even the passive basics like relying on your free email provider's filtering and running Windows Defender is going to stop a huge number of attacks. If you're expecting perfect security, you'll be disappointed -- but we can't declare complete bankruptcy.

Scroll down: https://arstechnica.com/author/dan-goodin/ This is just a teeny tiny sampling of the security vulnerabilities disclosed every day. Our industry is just not built with security as a goal, and even if we started caring about it today, we have 50 years of not caring to patch up. Caring about security in a meaningful way (i.e. formal verification, engineer licensing & liability) is really, really expensive. No one is going to carry that burden when their competitors don't have to. The end result is the situation we find ourselves in: there is no such thing as computer security, and any networked computer should be considered compromised by default.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#197

Has much consideration been given to labeling when a third party cloud or paid service is required to use the device? As somebody who uses IoT devices "locally" on my private network, I want to know my data will stay local and protected. The recent issues with Eufy doorbells claiming to be under local control [and encrypting data], but actually sending data to the cloud stands out to me as an example where labeling a…

Right now, the actual requirements for a label are totally up for grabs. This would make for a good public comment, in my opinion.

Thank you for your response, I'll consider submitting it.

For context, I've thought about commenting on issues in the past, but especially on the heels of the fake comments regarding net neutrality, for lack of a better way to put it I'm left feeling outgunned against such sophisticated lawyers and companies. This may be a little paranoid, but from a risk perspective I also worry about having my name attached to comments that go against the interests of large companies which dominate the marketplace. I also have hesitation about identity theft and uncertainty about the process.

Again, thank you for bring the conversation home, so to speak. I'll look at the process again.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#198
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

Openwrt is not the best example. Community sucks, some routers are full of bugs and the security is not great either. In general even if I like open devices and having the option to use my own software, this is not a solution for most of the consumers. It is not a solution even for the enthusiast that know how to flash their own firmware. Because even if they may do it a few times initially, eventually they stop doin…

openwrt is surely lacking in many aspects, but all the points you brought forward also apply to the manufacturer firmware but those are even less user friendly and cannot be modified.

there are a lot of open and closed firmware projects building upon openwrt

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#199
post #124

Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…

You could regulate they have to patch any outstanding CVEs for their device/firmware but enforceability might be difficult.

This would be an absolutely terrible standard. CVEs really, really suck. See, for example, this CVE for curl[1] that was assigned a 9.8. Or read sqlite's page on CVEs[2]. The sqlite issues alone would make this a non-starter, because you're not gonna convince everyone in every piece of software you use to update their version of sqlite.

[1] https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-eve... [2] https://www.sqlite.org/cves.html

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#200
All Internet supported devices should explicitly provide documentation about their functional behavior when there is no internet.

A few examples-

- internet enabled lights should say if they light up if no internet is available.

- internet enabled exercise equipment should say what is operational and what is not when there is no internet.

- automobiles should provide thorough documentation about what does not work and what does work when there is no internet

Post reply on HN