Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

231–240 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#231

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

> Please do not propose this regulation. If consumers actually cared about their IoT devices receiving security updates, companies would be doing it. The fact that companies are not already doing this is evidence it's not important to consumers. People may express frustration, but their purchasing behavior speaks louder than their words.

Or, maybe, companies are exploiting consumer ignorance and we're not dealing with an efficient market.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#235
Here are the concerns I care about at this time:

1. If Device Attestation/WEI takes off, and if it takes this new time-limited support lifetime into its attestation signature, then we'll see more physically healthy devices sent to the landfill. Devices that are reasonably fine for grandpa to play Mahjong on, but Google won't let her visit Facebook because WEI can't guarantee them their ad dollars, then it'll go to the landfill. I don't want to see this waste. I want the "support lifecycle" of a product to be the FULL lifecycle, including mandating a recycling program or something of the sort.

2. I want guarantees that I can keep using an old device after its support window closes. When Google decides to sunset the Nest Doorbell, I want to own it and be able to run it myself.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#236

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

If you ask an average consumer about their IoT devices' security updates their eyes will glaze over. I imagine the average car buyer in the 1950s would react the same way to talk of "crumple zones." Consumers absolutely need to be protected from corporate negligence here.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#237

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

The proposal in question is a voluntary labeling program. If a company did not want to participate they would not have to.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#238

Earlier quoted context omitted.

That's a great question. Devices that emit RF could be hijacked and turned into signal jammers. With smart jamming attacks, even low-power transmitters could potentially cause serious harmful interference to other devices. Botnets of compromised devices could be especially damaging. Since vulnerabilities are often chained by attackers, sometimes in very unexpected ways, to accomplish their final goal, we think that t…

Has there ever been an example of a consumer RF emitter being remotely hacked and turned into a jammer?

[deleted]

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#239
post #198

Earlier quoted context omitted.

Openwrt is not the best example. Community sucks, some routers are full of bugs and the security is not great either. In general even if I like open devices and having the option to use my own software, this is not a solution for most of the consumers. It is not a solution even for the enthusiast that know how to flash their own firmware. Because even if they may do it a few times initially, eventually they stop doin…

openwrt is surely lacking in many aspects, but all the points you brought forward also apply to the manufacturer firmware but those are even less user friendly and cannot be modified. there are a lot of open and closed firmware projects building upon openwrt

I am not clear how "all the points you brought forward also apply to the manufacturer firmware"

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#240
there are many parts of this problem, I have particular thoughts on two.

one concrete recommendation I would make is mandatory third party pen tests. software companies have to do this for soc2, etc. Companies putting live mics in living rooms across the country should deal with the same. This is all to raising the level of initial security on devices, including the update process.

the other consideration is about updates, and its much more nuanced against what's viable for a business. there is no security without updates, but the ability to produce those on any schedule is unclear. even more so when the originating company goes out of business. Ideally there would be a threat matrix here against a CVE list (remote access to hot mic/camera), would require a manufacturer to issue an update within x days.

Post reply on HN