This simultaneously enables innovation by small players while providing a pathway for bigger players to put a meaningful trust signal on their packaging and advertising.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
271–280 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#2721. Final date the manufacturer will provide firmware updates & security updates 2. If the manufacturer will support open source alternative firmware & security updates. 3. If there are any subscription fees (and how much) to get firmware updates & security updates.
Issue #1 is a big deal: I've purchased equipment, new in the box, after the mfg had discontinued support. I've also ran into issues with devices where updates required a subscription. I'd love a little disclosure.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#273As someone with a libertarian bent, meaningful labels appeal to me as a decent way to address problems without overriding the judgement of the market. An informed market avoids lemons. So this proposal sounds OK in principle but here are some questions. Please be aware that I'm not a US citizen so my views don't really matter here, I'm just looking over the garden fence and asking questions. 1. Your argument for why…
Has that been true in practice? I can think of plenty of horrible products, in IT, on the market. In terms of security (including privacy), the market has done nothing for IT consumers. And what about the people who already bought the lemons, before the market learned of it? Also, what if the lemon doesn't affect me but affects others (such as through DDoS)?
I prefer to keep it as simple as possible, but no simpler.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#274Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#275Earlier quoted context omitted.
But if I have an ethernet-connected device that doesn't emit RF for some non-networking purpose, it should still qualify. It should just need the transducer and a network connection.
I don't think it would for this specific proposal. The FCC's justification for this rule is that insecure IoT devices "could be manipulated to generate and emit RF energy to cause harmful interference". That's why they have jurisdiction here, because they regulate radio frequency use.
I think the broader definition would probably just fall back to the FTC, and as far as consumer protection goes I think they've been asleep at the switch for decades.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#276Earlier quoted context omitted.
The free market hasn’t figured it out, as evidenced by the decade of half-working devices consumers are left with. There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up.
> There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up. If customers want it, there is a way: use contract law to commit the manufacturer. That's already the norm for enterprise grade equipment. Companies often pay more for their hardware to get guaranteed long term support. So the market is willing and able to provide this kind of service, when people vo…
Give it a try and report back.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#277One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…
From https://news.ycombinator.com/item?id=37394188 :
I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it might reasonably be expected to allow an attacker to take control of a device, or to do so when combined with other known or unknown vulnerabilities. Or maybe a different standard. Then when enforcement/lawsuits come around, the judge/jury/regulator has to evaluate the reasonableness of the manufacturer's actions in light of that standard. We'd love to see commentary on the record as to what the right legal standard might be.
From https://news.ycombinator.com/item?id=37394793 :
Agreed. Building an automatic firmware update system from scratch would be burdensome for many IoT makers, but as it becomes necessary or encouraged, we would expect the market to provide a packaged solution/framework that manufacturers could fold into their products. It would be really helpful have to discussion of this on the record. How generalizable do you think such a solution could be? We are aware of the Uptane project, an OTA firmware update framework being jointly worked on by several car manufacturers, but would love to hear more about the feasibility of a solution for IoT devices generally, or particular classes of IoT devices.
From https://news.ycombinator.com/item?id=37393926 :
[...] companies wanting to put a label on their product would probably want to extract similar guarantees up their supply chain. Especially with a voluntary program like the one the FCC is proposing, good practices won't become the norm across the market overnight. But maybe, at the very least, the segment of product and component makers that take security seriously will begin to grow. I encourage you to share your thoughts in an official comment.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#278Earlier quoted context omitted.
No. As long as their iot device is still working consumers could care less about security updates.
What do you mean by "no"? Are you denying the existence of my grandparents who trust me to manage their devices?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#279Earlier quoted context omitted.
My two cents is that this would be an excellent comment on the record -- I'd love a discussion at the level of defining security risks to be part of the official federal commentary, because this is going to be a thorny implementation problem.
It would be great for people to post an update like "comment submitted" on threads like this one to make sure it was entered as a comment into the official record. I'm sure these comments in themselves are helpful to @SimingtonFCC individually, but having them be part of the official record gives the FCC legal grounds to consider them and incorporate them into rules.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#280[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…