Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

301–310 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#301

Earlier quoted context omitted.

It would change, but again -- it wouldn't be appreciable. Security policy is needed that accounts for the behaviors of the vast majority of users.

Users update their phones, there's no reason they can't be educated to update their other devices

Most non-technical users that I know don't actively update their phones and push back when I tell them that they need to do so faster than the automatic process because of an actively exploited vulnerability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#302
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

> regulation like this would make it harder for manufacturers who don't have the market power to lean on their suppliers to provide security patches.

Thought question (I’m asking, I don’t know the “answer”):

Today, many of these devices are marketed and sold by a company that has little to no involvement in the creation of the firmware or software, besides maybe sending over an image of their logo to be rolled into some turnkey “app.” Would we actually be better off if companies couldn’t really afford to basically dropship some sketchy white-label Chinese product, and instead could only sell a product here if they were confident they (acting alone) would be fully capable of supporting and updating it for a reasonable lifetime? Yes, it would raise the barrier to entry above basically the floor where it is today, but I don’t imagine there is a way to have it both ways.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#303
This boils down the Right to Repair and Maintain.

I always advise my friends and relatives to NOT buy smart appliances. The doom scenario is buying a $20k furnace that becomes useless. Imagine a scenario where you need an app (that's never updated) to adjust your house temperature. Or requiring people run insecure wireless protocols to control it.

Appliances like this need to operate over an open control protocol, where the smart/internet bit is physically replaceable. Dropping $200 every 5-7 years for a new Furnace smart attachment is reasonable price, dropping $20k is not.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#304
post #176

Thank you for engaging with the community in this way. Many years ago, in a fight to preserve individuals ability to flash their own routers, Vint Cerf, and I, and a coalition of many others, filed this report: http://www.taht.net/~d/fcc_saner_software_practices.pdf (retaining the ability to reflash our own routers, allowed my research project to continue, and the resulting algorithm, fq_codel (rfc8290), now runs on…

High-quality comment. Thanks very much! I'll read your filing and think about it. But also, it's a great example of impactful public FCC commentary. I hope your work inspires others to make their mark in the record.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#305
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

Thank you for these thoughtful points. Some relevant responses from other threads: From https://news.ycombinator.com/item?id=37394188 : I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it mi…

You're the lawyer guy? What statutory authority are you drawing on that you believe allows you, the FCC, to regulate this stuff?

Thanks!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#306
post #173

I think that IOT device manufacturers should be required to support their device for some minimum period of time AND be obligated to release the full source code for the device once they decide to end support. This also requires releasing the keys to any firmware signing mechanism or publishing a firmware update that removes such checks. The core problem is that without control of the firmware, consumers don't really…

There's also the problem that electronic devices last a long time -- often much longer than any manufacturer wants to admit. Vehicles, PCs, printers, and routers can easily last 10 years. Refrigerators and HVAC units can last 20 years or more. And now we're putting "smart" stuff into electric circuits that should last the lifetime of the house. The manufacturer will probably go out of business long before those devic…

Seconding this thread. There is no reason why a device shouldn't be servicable in 30 years regardless of whether the vendor is still in business.

There might be a way to integrate these IoT regulations with e-waste regulations, where the liability for disposal, recycling, and cleanup is related to servicability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#307
Tbh, I think this will add unnnecessary regulatory burden for start-up companies.

Take for example general IoT cloud connected equipment: it will get security upgrades more often than one that is completely offline. That was a big selling point of the Meraki cloud offering that is now part of Cisco. There would be millions of unpatched networking equipment, but Meraki could force upgrades onto networks without them managing the patching. The result being they would have secure products, and the non-cloud providers would have to rely on their customers to update their phone. The meraki solution was by definition a better upgrade path than the standalone solution. Why would you burden them with regulatory hoops that non-cloud devices do not require?

When you buy an IoT device, you're taking on a risk on anything not open source, and betting that a product/company will succeed. For example, I bought some cube sensors to monitor my home air quality. These sensors are now garbage because they connect to a closed cloud that has been shut down. They don't even function let alone get security upgrades.

If anything, non-cloud connected IoT devices are more likely to cause problems.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#308
post #124

Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…

Liability. Make the manufacturer liable if a known vulnerability is exploited.

I would think that tort law already achieves this - unless some law was passed that shields manufacturers from lawsuits. If that's the case, then the easy fix is removal of such shields instead of trying to create new regulations. Same applies to nearly all aspects of product liability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#309

With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…

I like this approach, it doesn't necessarily need to be just the "market" performing the audits however. The FDA handles audits of medical software companies just fine. Focusing on the Quality Management System and their Risk Assessment/Security practices seems like a solid approach, and of course centralize this data and make it easily searchable as much as possible, and provide API access to it in case vendors like Amazon want to integrate it and display certifications/grades for products/manufacturers automatically.

All that being said, I have no idea how much manpower or money it would take to do audits at that scale, or even what the scale of IoT Devices vs. Medical Devices is.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#310

With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…

I can see it being useful for audiences who know what they're looking for. As an average retail consumer, if I saw such a label I would either have no idea what it means or have to do my own research about what UL is - not to mention the impossibility of them enforcing anything. I guess they could remove the label but how would I know a product I'm using has violated their commitment - routinely check a UL website?
Post reply on HN