Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

291–300 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#291

Earlier quoted context omitted.

I would like to add most of the IoT problem is no patches at all. The firmware they get is usually bog standard with some very minor tweaks out of china somewhere. It is a problem of vendor locked in products where you have to buy a hub to do an update. If there even is an update. If you want to get a good picture of how sideways updating can even be watch the linus tech tips on where he wanted (and has the tech abil…

> If you want to get a good picture of how sideways updating can even be watch the linus tech tips on where he wanted (and has the tech ability) to patch his light switches. But could not even get them to give him the correct firmware or even say if he could. It was a mess, but it may not be a good example because part of the confusion was that there was no newer firmware. Their firmware version was being reported in…

He had a mix of random ones. They were telling him to buy a hub and hope for the best or go thru one of their vendors (more cost). Even if it that was slightly wrong that exact example could very easily happen. You have a group of devices in random levels of firmware states with no real nice way to tell what is what.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#292
post #198

Earlier quoted context omitted.

Openwrt is not the best example. Community sucks, some routers are full of bugs and the security is not great either. In general even if I like open devices and having the option to use my own software, this is not a solution for most of the consumers. It is not a solution even for the enthusiast that know how to flash their own firmware. Because even if they may do it a few times initially, eventually they stop doin…

openwrt is surely lacking in many aspects, but all the points you brought forward also apply to the manufacturer firmware but those are even less user friendly and cannot be modified. there are a lot of open and closed firmware projects building upon openwrt

> but all the points you brought forward also apply to the manufacturer firmware but those are even less user friendly and cannot be modified.

That's more than a reach of a claim. All manufacturer firmware are buggy with poor security? That's very obviously false. With closed manufacturers the history is that it's a mixed bag, not a blanket. Some are excellent, some are very poor.

Openwrt has been mediocre and all the negatives about it do not equally apply to all closed manufacturer firmware.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#293

Earlier quoted context omitted.

What do you mean by "no"? Are you denying the existence of my grandparents who trust me to manage their devices?

This approach may function effectively with your close family members. However, it can sometimes fail when your cousins won't let you near their IoT devices because they view you as the hacker or tech enthusiast who might tamper with their gadgets.

So what? Just because there are some atypical people doesn't make it a "no".

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#296
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

Maybe the presence or absence of this capability could be something disclosed on the label? It's an idea worth thinking about. I encourage you to file a comment with your thoughts on the matter. You probably want to focus on how this information could help a security-concerned consumer/business make a better purchasing decision. Or if you're arguing that this be a hard-requirement for the label, why a device should not be considered secure without this capability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#297
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

Also, one of the single most important parts of security is human manageability. Having to go into a proprietary app for each manufacturer.

There's this level of management at the google/amazom/apple level, and in some cases google even lets me push firmware updates (sennheiser ambeo is an example), BUT there should be a requirement that security settings in firmware be exposed in a way that they can be manipulated in a rolled up dashboard. I shouldn't have to depend on a first party app to stay maintained to get to the settings for a device.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#298

Earlier quoted context omitted.

> There is no such thing as computer security in 2023 This is absurd. Even the passive basics like relying on your free email provider's filtering and running Windows Defender is going to stop a huge number of attacks. If you're expecting perfect security, you'll be disappointed -- but we can't declare complete bankruptcy.

Scroll down: https://arstechnica.com/author/dan-goodin/ This is just a teeny tiny sampling of the security vulnerabilities disclosed every day. Our industry is just not built with security as a goal, and even if we started caring about it today, we have 50 years of not caring to patch up. Caring about security in a meaningful way (i.e. formal verification, engineer licensing & liability) is really, really expensive.…

I'm sorry, I can't really debate with a reductionist claim that everything is 100% fucked when it's readily apparent that some threat actors are still being stopped.

For what it's worth, I'm not disagreeing with your points about needing drastic, systemic improvements in how we handle security.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#299
Updates and the updating process are fraught with problems. Adding a requirement for updates to occur can compound those problems.

Some updates deprecate code. If that code is needed for critical functionality the update renders the device useless for that application.

Updates require some level of connectivity. It is becoming increasingly more common to insulate an IoT device from the Internet. Either through a VPN, an internal firewalled network, or completely disconnected. This is at odds with an IoT "requirement" to update equipment.

Updates require downtime. When do updates occur? How often? Can they be scheduled? If I have several IoT devices from the same manufacturer can I aggregate updates with an intermediate software package which then controls deployment?

How are updates tested? Are the original requirements from the initial manufacturing process kept or does this change over time and result in a broken IoT device.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#300

IoT devices need regulatory standardization w.r.t a few things: 1. software stack – big fat "firmware" should not exist. Entire stack should be upgradable safely, securely and frequently during its official supported lifetime and should be open-sourced for owner's own upgrades past end of life. For this, the hardware stack needs some amount of standards compliance. 2. Vendor should clearly declare/advertise the perio…

I wrote elsewhere, but a standard/compatible requirement for a rolled up management dashboard. https://news.ycombinator.com/item?id=37395102

I dont want 30 semi/unmaintained apps to manage each manufacturers security settings.

Post reply on HN