Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

331–340 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#332
post #57

Earlier quoted context omitted.

Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.

I'm sure the number of routers running OpenWRT is dwarfed by the number of OpenWRT-compatible routers running vulnerable, stock firmware. Allowing people to install software on their hardware isn't a cure for vulnerabilities. It's a step in the right direction for sure, but it's a very small one from the perspective of something as huge as "IoT security".

We have worked very hard in the OpenWrt and Linux projects to make it easy to update them in the field. Linux distros, android, apple, openwrt, etc have this facility built in now. IoT should also.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#333
post #46

There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

This may be beyond the FCC's purview, but given some of the comments (e.g., https://news.ycombinator.com/item?id=37393644) perhaps an entirely different strategy is warranted.

Instead of trying to compel manufacturers, who may no longer even exist, to support their old products; perhaps the government should focus on protecting consumers and aftermarket vendors who update / modify / reverse-engineer older revisions--especially after they're no longer meaningfully supported by the manufacturer.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#334
It seems to me that a law based on technical specifications is going to be hard to define and harder still to enforce. Perhaps, it may be easier to employ market forces to incentivize the manufacturers to secure (and continue to secure) their devices.

For instance, can there be a remediation fund that manufacturers pay into to compensate/support users for privacy or security breaches involving their devices. The amount they pay would be based on the number of the devices involved and the severity of the issue (PII, loss of amenity, network nuisance, etc). The rate paid could also be reviewed periodically to ensure the amount is not too low or too high. This way, companies can put a literal price on security and factor it into their product strategy and planning.

The advantage of this approach is two-fold. It internalizes the cost of security so it is no longer an externality that is be foisted on consumers. It also allows companies to apply their innovation towards addressing the issue without hamstringing them into a regulation prescribed approach that may become outdated over time.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#335

I'd be really happy with products having to be labeled with: 1. Final date the manufacturer will provide firmware updates & security updates 2. If the manufacturer will support open source alternative firmware & security updates. 3. If there are any subscription fees (and how much) to get firmware updates & security updates. Issue #1 is a big deal: I've purchased equipment, new in the box, after the mfg had discontin…

>I've purchased equipment, new in the box, after the mfg had discontinued support.

Exactly the kind of thing that sounds crazy but still happens.

>1. Final date the manufacturer will provide firmware updates & security updates 2. If the manufacturer will support open source alternative firmware & security updates. 3. If there are any subscription fees (and how much) to get firmware updates & security updates.

It would be great if you could file an official comment with your thoughts on exactly what disclosures are needed and why you think they're necessary. We want to get this right.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#336

Earlier quoted context omitted.

The solution without free firmware (and I don’t like this) is that the device bricks itself at the end of its scheduled lifetime. Which is to say, you are buying a multi-year lease up front. And the manufacturer should send you a recycling return box. This is a more honest way to sell these devices. Consumers that would not care about length of security updates will suddenly very much care how long their “lease” is……

That just forces e-waste. Aftermarket firmware lets a device stay useful indefinitely.

Agreed. I fully expect to see the routers we used in the cerowrt project from 2008 still operational for 10-20 more years. Thereś one out there with 4+ years of uptime that I know of.

https://blog.cerowrt.org/post/an_upgrade_in_place/

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#337
post #60

I'm generally skeptical of the efficacy of regulation to solve a problem. Can you please cite some examples of where FCC regulation has been successful in solving other problems, and explain why you believe iot security regulation is likely to help?

Since your skepticism of regulation seems broad, it seems unfair to cabin examples to just the FCC. Why not look at the food quality changes between 1905 and today? Those have largely been won on the back of serious regulation through the FDA (and it's predecessor), as well as labeling requirements. Both of those regulations have had significant improvements in the lives of consumers. Honestly, I have a very hard tim…

Hmm I don't know the food quality area super well but I am sure it's hard to confirm improvements were caused by regulations and not technology, right?

The idea of transparency is interesting to me. I used to agree with you that more is better but I no longer feel that way. Prop 65 in California is one example where there are stickers saying 'this might give you cancer' basically everywhere and we all ignore them so often that we start worrying about cancer less. It's not a good thing.

Imo existing laws regarding misleading marketing and accuracy are probably all that we need (perhaps increased enforcement) for something like iot security updates.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#338
It is extremely disheartening to see one of our many bureaucrats come to an anoymous international forum for input on an American domestic policy issue. A domestic policy issue that should be exclusively taken care of by the elected legislature rather than an unelected bureaucracy.

I hope that all of the comments in this thread are fully discarded by all who hold actual power at the FCC; the opinions of the international community are not relevant.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#339

I see the strong encouragement to post to the FCC's public comments, and you say it is highly influential - more influential than what you can do as a Commissioner. I'm a well-informed, active citizen, and I didn't realize that. It might help to explain how that works - how do public comments influence things? My concern would have been that it depends on the FCC, and that comments could be included or ignored as des…

It might help to explain how that works - how do public comments influence things?

The FCC conducts notice-and-comment rulemaking and is accountable to a public interest standard. Obviously the public interest can be hard to define, but at minimum, if reasonable comments on the record raise issues that we are clearly ignoring, this is likely to emerge in item debate, dissenting statements, and the press. In fact, the courts can go as far as overturning a rule if the FCC failed to adequately address arguments made on the record during the rulemaking process. A lot of our rulemaking is technical and not of general interest, but the public has the right to comment on all of it.

In this particular case, I think the much of the relevant experience and expertise resides with the public more than the federal government. A lot of tech workers are very upset with the current state of IoT security and with the US Government's actions or lack thereof, so if we get a lot of comments on the records about specifics, those will be hard to brush off.

Link for general reference: https://www.fcc.gov/about-fcc/rulemaking-process

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#340
post #252

Maybe we need to approach it differently? There will always be an "End of Life" date. And there will always be a user using the product beyond it. So my question is: How do we make it safe? My first thought is a "deadman's switch". If a device doesn't get or see some form of a signal, it just stops updating and disables IOT features. If the user wishes it to come alive again, there's a button they can press to have i…

IMHO the biggest problem is that there is no end-of-life date made clear to the user. I think if the purchaser could clearly see the support lifetime on the box then they can make an informed decision. Maybe this model that costs 50% more but is supported for 10y rather than 2 is a better deal after all.

I don't think we need to kill the device. Ideally it would somehow be made clear to the user when it drops out of support. But I would rather have the consumer informed and capable of making a decision than taking away their control to keep using the device.

Post reply on HN