Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

271–280 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#271
With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security. The highest grades indicate regular audits of vendor practices. And a website where approval status (and possible revocation) can be looked up.

This simultaneously enables innovation by small players while providing a pathway for bigger players to put a meaningful trust signal on their packaging and advertising.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#272
I'd be really happy with products having to be labeled with:

1. Final date the manufacturer will provide firmware updates & security updates 2. If the manufacturer will support open source alternative firmware & security updates. 3. If there are any subscription fees (and how much) to get firmware updates & security updates.

Issue #1 is a big deal: I've purchased equipment, new in the box, after the mfg had discontinued support. I've also ran into issues with devices where updates required a subscription. I'd love a little disclosure.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#273

As someone with a libertarian bent, meaningful labels appeal to me as a decent way to address problems without overriding the judgement of the market. An informed market avoids lemons. So this proposal sounds OK in principle but here are some questions. Please be aware that I'm not a US citizen so my views don't really matter here, I'm just looking over the garden fence and asking questions. 1. Your argument for why…

> An informed market avoids lemons.

Has that been true in practice? I can think of plenty of horrible products, in IT, on the market. In terms of security (including privacy), the market has done nothing for IT consumers. And what about the people who already bought the lemons, before the market learned of it? Also, what if the lemon doesn't affect me but affects others (such as through DDoS)?

I prefer to keep it as simple as possible, but no simpler.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#275

Earlier quoted context omitted.

But if I have an ethernet-connected device that doesn't emit RF for some non-networking purpose, it should still qualify. It should just need the transducer and a network connection.

I don't think it would for this specific proposal. The FCC's justification for this rule is that insecure IoT devices "could be manipulated to generate and emit RF energy to cause harmful interference". That's why they have jurisdiction here, because they regulate radio frequency use.

This makes sense to me. The definition is slightly awkward, but awkward in a way that preserves the FCC's ability to regulate the issue at all. If you clean up the definition, you can get to a more coherent definition of IoT device, but without the FCC's ability to regulate the devices.

I think the broader definition would probably just fall back to the FTC, and as far as consumer protection goes I think they've been asleep at the switch for decades.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#276
post #71

Earlier quoted context omitted.

The free market hasn’t figured it out, as evidenced by the decade of half-working devices consumers are left with. There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up.

> There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up. If customers want it, there is a way: use contract law to commit the manufacturer. That's already the norm for enterprise grade equipment. Companies often pay more for their hardware to get guaranteed long term support. So the market is willing and able to provide this kind of service, when people vo…

Have you ever used contract law in that manner? Did you call up Apple and negotiate a contract for your new iPhone, imposing requirements on them?

Give it a try and report back.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#277
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

Thank you for these thoughtful points. Some relevant responses from other threads:

From https://news.ycombinator.com/item?id=37394188 :

I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it might reasonably be expected to allow an attacker to take control of a device, or to do so when combined with other known or unknown vulnerabilities. Or maybe a different standard. Then when enforcement/lawsuits come around, the judge/jury/regulator has to evaluate the reasonableness of the manufacturer's actions in light of that standard. We'd love to see commentary on the record as to what the right legal standard might be.

From https://news.ycombinator.com/item?id=37394793 :

Agreed. Building an automatic firmware update system from scratch would be burdensome for many IoT makers, but as it becomes necessary or encouraged, we would expect the market to provide a packaged solution/framework that manufacturers could fold into their products. It would be really helpful have to discussion of this on the record. How generalizable do you think such a solution could be? We are aware of the Uptane project, an OTA firmware update framework being jointly worked on by several car manufacturers, but would love to hear more about the feasibility of a solution for IoT devices generally, or particular classes of IoT devices.

From https://news.ycombinator.com/item?id=37393926 :

[...] companies wanting to put a label on their product would probably want to extract similar guarantees up their supply chain. Especially with a voluntary program like the one the FCC is proposing, good practices won't become the norm across the market overnight. But maybe, at the very least, the segment of product and component makers that take security seriously will begin to grow. I encourage you to share your thoughts in an official comment.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#278

Earlier quoted context omitted.

No. As long as their iot device is still working consumers could care less about security updates.

What do you mean by "no"? Are you denying the existence of my grandparents who trust me to manage their devices?

This approach may function effectively with your close family members. However, it can sometimes fail when your cousins won't let you near their IoT devices because they view you as the hacker or tech enthusiast who might tamper with their gadgets.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#279

Earlier quoted context omitted.

My two cents is that this would be an excellent comment on the record -- I'd love a discussion at the level of defining security risks to be part of the official federal commentary, because this is going to be a thorny implementation problem.

It would be great for people to post an update like "comment submitted" on threads like this one to make sure it was entered as a comment into the official record. I'm sure these comments in themselves are helpful to @SimingtonFCC individually, but having them be part of the official record gives the FCC legal grounds to consider them and incorporate them into rules.

Completely agree! The public record in this case is going to be what agencies and industry looks to, far more than whatever I might happen to personally believe. I'm going to get as much information from this discussion as I can, but every participant should feel free to comment on the record, or to get their employers, companies, trade associations, ad-hoc working groups, concerned citizens congregating on Discord to complain, etc. to do so as well.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#280

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

Consumer don't have time, knowledge, or resources to demand all these things they use. When I buy a car, I want it to be safe. I spend zero time evaluating its technology and demanding labels. I already have a job.
Post reply on HN