Earlier quoted context omitted.
I would like to add most of the IoT problem is no patches at all. The firmware they get is usually bog standard with some very minor tweaks out of china somewhere. It is a problem of vendor locked in products where you have to buy a hub to do an update. If there even is an update. If you want to get a good picture of how sideways updating can even be watch the linus tech tips on where he wanted (and has the tech abil…
> If you want to get a good picture of how sideways updating can even be watch the linus tech tips on where he wanted (and has the tech ability) to patch his light switches. But could not even get them to give him the correct firmware or even say if he could. It was a mess, but it may not be a good example because part of the confusion was that there was no newer firmware. Their firmware version was being reported in…
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
291–300 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#292Earlier quoted context omitted.
Openwrt is not the best example. Community sucks, some routers are full of bugs and the security is not great either. In general even if I like open devices and having the option to use my own software, this is not a solution for most of the consumers. It is not a solution even for the enthusiast that know how to flash their own firmware. Because even if they may do it a few times initially, eventually they stop doin…
openwrt is surely lacking in many aspects, but all the points you brought forward also apply to the manufacturer firmware but those are even less user friendly and cannot be modified. there are a lot of open and closed firmware projects building upon openwrt
That's more than a reach of a claim. All manufacturer firmware are buggy with poor security? That's very obviously false. With closed manufacturers the history is that it's a mixed bag, not a blanket. Some are excellent, some are very poor.
Openwrt has been mediocre and all the negatives about it do not equally apply to all closed manufacturer firmware.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#293Earlier quoted context omitted.
What do you mean by "no"? Are you denying the existence of my grandparents who trust me to manage their devices?
This approach may function effectively with your close family members. However, it can sometimes fail when your cousins won't let you near their IoT devices because they view you as the hacker or tech enthusiast who might tamper with their gadgets.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#294Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#295Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#296How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#297How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.
There's this level of management at the google/amazom/apple level, and in some cases google even lets me push firmware updates (sennheiser ambeo is an example), BUT there should be a requirement that security settings in firmware be exposed in a way that they can be manipulated in a rolled up dashboard. I shouldn't have to depend on a first party app to stay maintained to get to the settings for a device.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#298Earlier quoted context omitted.
> There is no such thing as computer security in 2023 This is absurd. Even the passive basics like relying on your free email provider's filtering and running Windows Defender is going to stop a huge number of attacks. If you're expecting perfect security, you'll be disappointed -- but we can't declare complete bankruptcy.
Scroll down: https://arstechnica.com/author/dan-goodin/ This is just a teeny tiny sampling of the security vulnerabilities disclosed every day. Our industry is just not built with security as a goal, and even if we started caring about it today, we have 50 years of not caring to patch up. Caring about security in a meaningful way (i.e. formal verification, engineer licensing & liability) is really, really expensive.…
For what it's worth, I'm not disagreeing with your points about needing drastic, systemic improvements in how we handle security.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#299Some updates deprecate code. If that code is needed for critical functionality the update renders the device useless for that application.
Updates require some level of connectivity. It is becoming increasingly more common to insulate an IoT device from the Internet. Either through a VPN, an internal firewalled network, or completely disconnected. This is at odds with an IoT "requirement" to update equipment.
Updates require downtime. When do updates occur? How often? Can they be scheduled? If I have several IoT devices from the same manufacturer can I aggregate updates with an intermediate software package which then controls deployment?
How are updates tested? Are the original requirements from the initial manufacturing process kept or does this change over time and result in a broken IoT device.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#300IoT devices need regulatory standardization w.r.t a few things: 1. software stack – big fat "firmware" should not exist. Entire stack should be upgradable safely, securely and frequently during its official supported lifetime and should be open-sourced for owner's own upgrades past end of life. For this, the hardware stack needs some amount of standards compliance. 2. Vendor should clearly declare/advertise the perio…
I dont want 30 semi/unmaintained apps to manage each manufacturers security settings.