Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

251–260 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#251

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

> If consumers actually cared about their IoT devices receiving security updates, companies would be doing it.

I don't think this is true. Security issues don't matter until they do, and consumers -- by which I mean "people" -- are notoriously bad at estimating risk for sufficiently rare outcomes.

To take a common example, insecure internet-connected baby monitors can literally give strangers video access to your home (not to mention your child, although we don't need to resort to "think of the children"). I think most consumers make purchases with the reasonable expectation that the product isn't going to violate their personal security without them knowing.

As a concrete example to the contrary, even many laypeople I know consider home assistants like Alexa to be too risky -- they don't like the idea of being overheard and monitored by some unknown "other". And that's almost literally part of the product description! When consumers are aware of these issues, they do care. The idea that they currently purchase as though they don't is confounded by a lack of awareness on the one hand, and a reasonable expectation to the contrary on the other hand.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#252
Maybe we need to approach it differently?

There will always be an "End of Life" date. And there will always be a user using the product beyond it.

So my question is: How do we make it safe?

My first thought is a "deadman's switch". If a device doesn't get or see some form of a signal, it just stops updating and disables IOT features. If the user wishes it to come alive again, there's a button they can press to have it "Check for updates" if there are none, it tells the user it is at "End of Software Updates" and "Certain services will be disabled." etc.

We can't stop the issue. We can decide what to do once a vendor decides to stop updating... and make sure that final revision is as safe as it can be. Preferably non-networked (including bluetooth etc).

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#253

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

And here's the political angle. Letting a bunch of insecure iot devices into your home actually harms other people by allowing your devices to enable subsequent exploits of your neighbors, both on the next block over as well as the next country over.

Therefore iot devices most certainly should be regulated as this is a critical issue for the public good as well as national security.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#254

Consumers consistently vote with their wallets on this, and based on their behavior, they don't care. They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more. If you want to make a difference, an FCC sticker…

I just don't agree with this at all. I specifically avoid all smart plugs that don't have a UL mark (or European equivalent mark).

It's impossible to say that consumers don't care about a specific certification before it exists based on their existing behavior. Consumers _do not have any ability_ to distinguish on this axis at the moment. So, we can't say: "based on their behavior they don't care". They very well might, and just don't have the information necessary to tell.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#255
IOT security is funny. Secure ways of deploying things exists today, but retrofitting existing systems would be impossible if the devices don’t support it ? Also, updating a running system… seems like a very costly and time consuming exercise.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#256
post #29

> I’ve advocated for the FCC to require device manufacturers to support their devices with security updates for a reasonable amount of time [1]. No offense intended, but I would be worried about this more than I would be worried about the current state of the IoT world. A blanket requirement would punish hobbyists and small companies prototyping new technologies. But big players could spend relatively minor technical…

> I would prefer that FCC works to inform: maintain an up-to-date database of issues (reported by both the manufacturers and by third-parties), impacts and recommended fixes for those that have a fix. My 2c.

How would that help 99.99% of consumers? They are not going to look in databases, understand the issue, and apply fixes.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#257
post #46

There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…

[deleted]

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#258
post #218
post #100

Earlier quoted context omitted.

There was no requirement that firmware be locked down. The requirement was that consumer radio transmitters could be too easily made to use frequencies and power levels that violate FCC regulations. If a device had a transmitter where firmware could control those things, and the firmware for the device was one blob that contained everything so letting the user replace firmware meant letting the user control those res…

Isn't that a bit overreaching? I can make you a device the spews garbage on any wavelength you fancy, so they're really only preventing accidental radio pollution. Even in that case it's pretty unusual to prevent a consumer device (other than a radio) from being used in an unlawful way, Part 15 notwithstanding.

I believe the regulation applies to such a device you make as well, not specifically consumer Wi-Fi products. I.e. if you make a transmitting SDR it's not supposed to allow certain things.

The prevention all comes down to enforcement though, the law doesn't physically stop you from making a device it just means you could get in trouble for intentionally ignoring it and selling a lot of those devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#259
post #225

For those of you unfamiliar with the specific challenges IoT patching brings, here is a blog post from just last week on one aspect of the topic: http://tomalrichblog.blogspot.com/2023/08/british-cuisine-de... FTA: > I assumed that device manufacturers update the software in their device about every month...he said they do it annually. Those devices are at least _getting_ updates - there is a long tail of devices who…

>And since this is HN - there is a startup hidden in the midst of all of this: an enterprise-grade IoT OS that "does security right." Sell to the device manufacturers, allow them to market it as "enterprise-ready" or some such. If the FCC guidelines here are approved, there will be a suddenly increased demand!

Agreed. Building an automatic firmware update system from scratch would be burdensome for many IoT makers, but as it becomes necessary or encouraged, we would expect the market to provide a packaged solution/framework that manufacturers could fold into their products. It would be really helpful have to discussion of this on the record. How generalizable do you think such a solution could be? We are aware of the Uptane project, an OTA firmware update framework being jointly worked on by several car manufacturers, but would love to hear more about the feasibility of a solution for IoT devices generally, or particular classes of IoT devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#260
post #3

commitments on this label (including the support period) will be legally enforceable in contract and tort lawsuits and under other laws. When it comes to U.S. laws that touch technology, enforceability is a mess. Spyware, spam, fraud, misleading labels, etc. are already governed by various state and federal laws, yet enforcement efforts are whack-a-mole at best. For IoT devices, having the proposed requirements sound…

They're proposing an opt-in labeling program that essentially amounts for to the FCC underwriting certain attestations that vendors are choosing to make about their products.

This means that someone applying the label without meeting the standards the label indicates would be guilty of exactly the sort of fraudulent advertising you're describing, and contract and tort law are the relevant mechanisms of enforcement for this.

I'm not sure what you mean by enforcement efforts being "whack-a-mole at best", but if you're expecting some sort of preemptive regulatory barrier to be enforced by a bureaucratic agency in advance, that's just not the way this sort of thing works or is intended to work, and the FCC certainly wouldn't have the legal authority to implement such a regime.

Legal actions for fraud, false advertising, trademark infringement (in the case of trademarked standards certification badges, e.g. UL) are frequently used mechanisms for this sort of thing, and seem to work well enough to ensure that vendors are deterred from fraudulently applying certification labels to their products.

Post reply on HN