Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
331–340 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#332Earlier quoted context omitted.
Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.
I'm sure the number of routers running OpenWRT is dwarfed by the number of OpenWRT-compatible routers running vulnerable, stock firmware. Allowing people to install software on their hardware isn't a cure for vulnerabilities. It's a step in the right direction for sure, but it's a very small one from the perspective of something as huge as "IoT security".
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#333There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…
Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.
Instead of trying to compel manufacturers, who may no longer even exist, to support their old products; perhaps the government should focus on protecting consumers and aftermarket vendors who update / modify / reverse-engineer older revisions--especially after they're no longer meaningfully supported by the manufacturer.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#334For instance, can there be a remediation fund that manufacturers pay into to compensate/support users for privacy or security breaches involving their devices. The amount they pay would be based on the number of the devices involved and the severity of the issue (PII, loss of amenity, network nuisance, etc). The rate paid could also be reviewed periodically to ensure the amount is not too low or too high. This way, companies can put a literal price on security and factor it into their product strategy and planning.
The advantage of this approach is two-fold. It internalizes the cost of security so it is no longer an externality that is be foisted on consumers. It also allows companies to apply their innovation towards addressing the issue without hamstringing them into a regulation prescribed approach that may become outdated over time.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#335I'd be really happy with products having to be labeled with: 1. Final date the manufacturer will provide firmware updates & security updates 2. If the manufacturer will support open source alternative firmware & security updates. 3. If there are any subscription fees (and how much) to get firmware updates & security updates. Issue #1 is a big deal: I've purchased equipment, new in the box, after the mfg had discontin…
Exactly the kind of thing that sounds crazy but still happens.
>1. Final date the manufacturer will provide firmware updates & security updates 2. If the manufacturer will support open source alternative firmware & security updates. 3. If there are any subscription fees (and how much) to get firmware updates & security updates.
It would be great if you could file an official comment with your thoughts on exactly what disclosures are needed and why you think they're necessary. We want to get this right.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#336Earlier quoted context omitted.
The solution without free firmware (and I don’t like this) is that the device bricks itself at the end of its scheduled lifetime. Which is to say, you are buying a multi-year lease up front. And the manufacturer should send you a recycling return box. This is a more honest way to sell these devices. Consumers that would not care about length of security updates will suddenly very much care how long their “lease” is……
That just forces e-waste. Aftermarket firmware lets a device stay useful indefinitely.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#337I'm generally skeptical of the efficacy of regulation to solve a problem. Can you please cite some examples of where FCC regulation has been successful in solving other problems, and explain why you believe iot security regulation is likely to help?
Since your skepticism of regulation seems broad, it seems unfair to cabin examples to just the FCC. Why not look at the food quality changes between 1905 and today? Those have largely been won on the back of serious regulation through the FDA (and it's predecessor), as well as labeling requirements. Both of those regulations have had significant improvements in the lives of consumers. Honestly, I have a very hard tim…
The idea of transparency is interesting to me. I used to agree with you that more is better but I no longer feel that way. Prop 65 in California is one example where there are stickers saying 'this might give you cancer' basically everywhere and we all ignore them so often that we start worrying about cancer less. It's not a good thing.
Imo existing laws regarding misleading marketing and accuracy are probably all that we need (perhaps increased enforcement) for something like iot security updates.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#338I hope that all of the comments in this thread are fully discarded by all who hold actual power at the FCC; the opinions of the international community are not relevant.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#339I see the strong encouragement to post to the FCC's public comments, and you say it is highly influential - more influential than what you can do as a Commissioner. I'm a well-informed, active citizen, and I didn't realize that. It might help to explain how that works - how do public comments influence things? My concern would have been that it depends on the FCC, and that comments could be included or ignored as des…
The FCC conducts notice-and-comment rulemaking and is accountable to a public interest standard. Obviously the public interest can be hard to define, but at minimum, if reasonable comments on the record raise issues that we are clearly ignoring, this is likely to emerge in item debate, dissenting statements, and the press. In fact, the courts can go as far as overturning a rule if the FCC failed to adequately address arguments made on the record during the rulemaking process. A lot of our rulemaking is technical and not of general interest, but the public has the right to comment on all of it.
In this particular case, I think the much of the relevant experience and expertise resides with the public more than the federal government. A lot of tech workers are very upset with the current state of IoT security and with the US Government's actions or lack thereof, so if we get a lot of comments on the records about specifics, those will be hard to brush off.
Link for general reference: https://www.fcc.gov/about-fcc/rulemaking-process
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#340Maybe we need to approach it differently? There will always be an "End of Life" date. And there will always be a user using the product beyond it. So my question is: How do we make it safe? My first thought is a "deadman's switch". If a device doesn't get or see some form of a signal, it just stops updating and disables IOT features. If the user wishes it to come alive again, there's a button they can press to have i…
I don't think we need to kill the device. Ideally it would somehow be made clear to the user when it drops out of support. But I would rather have the consumer informed and capable of making a decision than taking away their control to keep using the device.