Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

261–270 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#261

Earlier quoted context omitted.

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

I would like to add most of the IoT problem is no patches at all. The firmware they get is usually bog standard with some very minor tweaks out of china somewhere. It is a problem of vendor locked in products where you have to buy a hub to do an update. If there even is an update. If you want to get a good picture of how sideways updating can even be watch the linus tech tips on where he wanted (and has the tech abil…

> If you want to get a good picture of how sideways updating can even be watch the linus tech tips on where he wanted (and has the tech ability) to patch his light switches. But could not even get them to give him the correct firmware or even say if he could.

It was a mess, but it may not be a good example because part of the confusion was that there was no newer firmware. Their firmware version was being reported in hexadecimal, but the latest firmware version was listed in decimal.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#262

Speaking as someone who has several cheap cameras gathering dust in a box because I no longer trust them with network access... ...manufacturers are simply never going to be incentivized to take security seriously. The best you can hope for with a regulatory approach is to incentivize them to pay more lip-service to the idea, while hiding their backdoors better. Their incentive to spy on users is simply too profitabl…

> The best you can hope for with a regulatory approach is to incentivize them to pay more lip-service to the idea

While I think this is true, there's also some benefit to getting the manufacturer's to pay lip-service to the idea.

In that, it becomes part of the marketing and the sales of the device. Later, consumers can _attempt_ to hold manufacturer's feet to the fire with false advertising and other fraud class action lawsuits.

It's really really not a good system, but even forcing a bit of lip-service is a marginal improvement over what we have now.

> Therefore, the most meaningful step would be to require support for open-source firmware.

I agree that it would absolutely be better, but it sounds like even this voluntary labeling program is the compromise that might be tolerated by the other members of the FCC. I'm guessing such a strong and effective program would be a non-starter with those members.

Which, honestly, tells me a lot about the other members of the FCC, and whose interests they are seeking to serve.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#263
post #207

Earlier quoted context omitted.

While I acknowledge that CVE scoring of risk can be inconsistent and sometimes wildly wrong, what would you suggest in its place?

That's the problem, there isn't a good objective measure. Some type of "reasonableness" standard is usually invoked in situations like this, but that kinda just takes us back to square one: what's currently considered reasonable in the industry is pretty terrible.

I'm not sure we will ever have a universally accepted objective measure of risk. Risk is, by its nature, somewhat subjective.

Most organisations will use CVEs and the CVSS system as a starting point, but will triage them and produce their own assessment of the actual risk to them and their products given how the software is used.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#264

Earlier quoted context omitted.

> either they must provide full (FLOSS) source code and documentation I like the spirit of this, but one problem with this is that the software stack is likely not FLOSS, and the manufacturers don't own all the software. A second problem is that lot of the software for production IoT-devices doesn't live in the device. Third, there are safety concerns with a lot of devices that you'd need legal productions for. Final…

I'm working on an IoT device for industrial use, and we're wrestling with this very problem. The answer we're probably going to go with is that the device is 'leased' to the customer. It's part of their subscription. This solves a ton of problems about FLOSS and support of the same. It's now a closed device, and you have no rights to the code inside. If we go out of business, you have a brick that you don't have to p…

I think it's always better for the customer to have access to the code inside. I'll actively recommend FLOSS solutions to customers even if they're not quite as good as the competition on paper right away. Simply because a large part of the cost of industrial hardware is actually supporting it for a long time. And support is SO MUCH EASIER if you have all the source code and schematics. Of course big customers get to demand this kind of arrangement (floss, escrow, or even just "give us all the paper") while small industrial operations end up paying a premium for inferior service.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#265
post #84
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

You as a customer can already give the manufacturer that choice, and simple refuse to buy from any manufacturer that doesn't comply.

Are there any that currently do comply?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#266
post #124

Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…

I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it might reasonably be expected to allow an attacker to take control of a device, or to do so when combined with other known or unknown vulne…

This sounds like a reasonable approach (sorry for the pun). One question - reasonable to whom? (who? - english is my first language sorry).

I ask because when I was doing security research, we'd often present issues and get responses like "but who is going to think of that?" or "No one could find that", only for someone to think of or find it later and take over a system. I still occasionally hear this from software developers (even though the industry as a whole has gotten much better over the years), but quite often from people who work in "cyberphysical" systems (e.g IOT).

Part of the tension seems to come from the fact that some infosec people can be equally unreasonable, declaring something utterly useless if there's a remote theoretical chance of a problem.

Unrelated to the above:

> Maybe here, a vulnerability needs to be patched if it might reasonably be expected to allow an attacker to take control of a device...

I suspect you know this and short-cutted for conversation, or maybe these are all the same legally, but "take control of a device" isn't the only win condition - DOS, info leaks, and so on also exist. I note this because I'm kind of curious if the law considers those the same or vastly different scenarios, and if any sort of FCC regulations would include them.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#267

I honestly don’t think we need a government solution to this issue. Consumers who want this security can buy from manufacturers with a reputation at stake such as Amazon or Apple. I don’t want your “help”. Let the market sort it out.

Consumers have no idea about security, the risks, the technology, how to evaluate it, or who to buy from. That is not a realistic solution.

Consider food or automobile security: Should consumers somehow evaluate them? Check the wiring? Find out, at every restaurant and grocery, how long the food has been stored and where?

IoT security has another issue: It can affect others more than the end user. If my IoT is DDoSing you, what will the market do about it?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#268
There’s a concept in the Linux ecosystem called Long Term Support (LTS) in which a Linux distro will label a new release as LTS which means they will support it with security updates for several years. IoT should probably have something similar.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#269
post #218

Earlier quoted context omitted.

Isn't that a bit overreaching? I can make you a device the spews garbage on any wavelength you fancy, so they're really only preventing accidental radio pollution. Even in that case it's pretty unusual to prevent a consumer device (other than a radio) from being used in an unlawful way, Part 15 notwithstanding.

I believe the regulation applies to such a device you make as well, not specifically consumer Wi-Fi products. I.e. if you make a transmitting SDR it's not supposed to allow certain things. The prevention all comes down to enforcement though, the law doesn't physically stop you from making a device it just means you could get in trouble for intentionally ignoring it and selling a lot of those devices.

You're totally right. I'm trying to make a moral argument, I think if it were unfeasible for an individual to make something (e.g. modern CPU) then you could make an argument for producers limiting them on the basis that it would effectively prevent anyone from doing the banned thing. The fact that it's roughly as easy to reflash an IoT device with custom firmware as it is to make an antenna that produces noise in a forbidden frequency means that you are adding a technical measure to prevent just some of that illegal action and not stopping a determined hacker.

I'm not claiming it wouldn't be an overall social good, but other areas of law and regulation don't seem to function like this (with notable exceptions like photocopying banknotes).

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#270
post #60

I'm generally skeptical of the efficacy of regulation to solve a problem. Can you please cite some examples of where FCC regulation has been successful in solving other problems, and explain why you believe iot security regulation is likely to help?

Since your skepticism of regulation seems broad, it seems unfair to cabin examples to just the FCC.

Why not look at the food quality changes between 1905 and today? Those have largely been won on the back of serious regulation through the FDA (and it's predecessor), as well as labeling requirements. Both of those regulations have had significant improvements in the lives of consumers.

Honestly, I have a very hard time seeing a downside to regulation that solely mandates a more transparent marketplace. The free market only actually works when an effective marketplace is possible, and that requires transparency. Without transparency, "free markets" are less likely to produce efficient outcomes.

Post reply on HN