Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

321–330 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#321
To add to previous similar comments, I think that one of the best ways to ensure that security updates are provided is to ensure that manufacturers either commit to continuous security updates, or after a minimum sunset period during which they provide security updates (e.g. 5 years), they agree to provide source code as well as build and deployment instructions, so that the community can take over. It must be possible to build the source code using a freely available toolchain. Furthermore, they must agree to provide links to these communities through their support pages for these products, so that users can be made aware of new third party firmware.

A durable IoT device could last decades, but few companies building these products will survive as long as the devices, let alone support a device they are no longer profiting from. As long as they are supporting the device with security updates, it's fine for the firmware to be proprietary. But, when they decide to cut support for the device, they should be willing to ensure that consumers who have purchased this hardware and are still using it won't become victims, and that the overall Internet community won't end up harboring botnets made of living dead ewaste.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#322
Nathan -- thanks for your work on this issue. I'm the ceo/co-founder at Seam (YC S20). We're building an API for IoT devices. I have many, many thoughts for you.

For Seam, we purchase, set up, and test many individual devices and systems in our lab in San Francisco. During the course of this work, we discover quite a few interesting things. When possible, we work directly with manufacturers on addressing the more concerning problems we find. We maintain an internal device database (partially available here https://www.seam.co/supported-devices-and-systems) where we keep track of our findings on devices we test & integrate. One area that I haven't seen addressed here is data-storage jurisdiction. imho, that might be one of the more concerning aspect.

happy to have a chat; my seam email is in my hn profile.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#323

With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…

The UL example is one where it would be hard for improved security to happen by itself. UL was founded to solve for fire risk when insuring buildings. It received funding from underwriters that would benefit from the label.

I don't see any particular entity benefiting from security labels - it's a problem of the "commons" where you generally need government intervention of some sort of.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#324
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

As far as I remember FCC about 8 years ago didn't liked OpenWRT, and even enforced on TP Link to lock it.

Vint Cerf and I shot that proposed anti-dd-wrt regulation down thoroughly: filing here:

http://www.taht.net/~d/fcc_saner_software_practices.pdf

Substitute IoT for router in everything we wrote there on page 12-13 and that seems to be a starting point everyone around here has come to think is necessary. I would prefer not to summarize such a large filing here.

Also Dan Geer wrote extensively on these topics at the time.

Of late I have been strongly suggesting that software be at least "built in america": https://blog.cerowrt.org/post/an_upgrade_in_place/

I care most deeply first - that the front doors to our houses, the home gateways, are properly secured, kept up to date, and have ipv6 and bufferbloat fixes on them.

IoT devices belong on their own vlan...

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#325
Interesting turn of events to ask Hacker News for their opinion :)

Someone I know wrote an interesting opinion piece on this [1], which might be relevant to this discussion.

[1] https://bits-chips.nl/artikel/iot-we-need-to-get-a-grip-on-t...

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#326

Earlier quoted context omitted.

Liability. Make the manufacturer liable if a known vulnerability is exploited.

I would think that tort law already achieves this - unless some law was passed that shields manufacturers from lawsuits. If that's the case, then the easy fix is removal of such shields instead of trying to create new regulations. Same applies to nearly all aspects of product liability.

The general rule in tort is that you need physical injury or physical destruction of property to sustain a lawsuit. There's exceptions at the edges of that, but you basically can't sue a device manufacturer for crummy security that caused you to lose money or other non-physical damages like reputational harm. The same limitation does not apply to contract law. We think that a cybersecurity label could be enforceable under contract law, as well as help bolster claims that a duty was breached in tort (when there is physical injury/damage). It would also be subject to FCC enforcement, for failing to live up to the commitments made to get the label.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#327
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

> There are also often practical issues related to security patching embedded devices: for example, a downstream supplier's driver can make it impossible to upgrade a kernel unless/until the supplier provides a fix. Of course, strong regulation here could help to drive bad practices like that out of the industry, but I'm not going to hold my breath on that one. The effect of regulation like this would make it harder…

This is an honest question to these arguments, but as a consumer (and as an extension the FCC protecting them) why should I care? Would you accept the same arguments from your car manufacturer, "sorry we can't fix your broken brakes, our supplier uses a process that isn't supported by new brake standards so just don't brake"?

I suspect not, so why not because the car is more expensive?

I would argue that the purpose of regulation is exactly to root out this sort of practice. If it was cheap and effortless to do this we likely wouldn't need regulation.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#328

Earlier quoted context omitted.

IIRC the main objection was that it could be used to do something with the radio (boost power?) that caused the device to exceed FCC limits for a consumer radio? Something along those lines?

For those out of the loop these documents have a good introduction to how free software interacts with radio regulations https://wireless.wiki.kernel.org/en/developers/regulatory/st... https://wireless.wiki.kernel.org/en/developers/regulatory TLDR manufacturers and "serious" companies won't touch anything that could potentially be configured to emit signals that your local government doesn't like. So Linux has to pre…

As these regulations change frequently, I am glad that linux makes it possible to update this database and the devices in the field. For example a portion of the 5.9ghz spectrum became available.

https://www.computerworld.com/article/2993112/vint-cerf-and-...

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#329

Earlier quoted context omitted.

That's a great question. Devices that emit RF could be hijacked and turned into signal jammers. With smart jamming attacks, even low-power transmitters could potentially cause serious harmful interference to other devices. Botnets of compromised devices could be especially damaging. Since vulnerabilities are often chained by attackers, sometimes in very unexpected ways, to accomplish their final goal, we think that t…

Has there ever been an example of a consumer RF emitter being remotely hacked and turned into a jammer?

Of course not. But they don't operated based on evidence, they do based on fear. Like Apple, John Deere and pretty much any industry today.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#330

Tbh, I think this will add unnnecessary regulatory burden for start-up companies. Take for example general IoT cloud connected equipment: it will get security upgrades more often than one that is completely offline. That was a big selling point of the Meraki cloud offering that is now part of Cisco. There would be millions of unpatched networking equipment, but Meraki could force upgrades onto networks without them m…

Enforcing mandatory updates might not be a good idea, but creating standards that can inform the consumer in making decisions is helpful.
Post reply on HN