Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

351–360 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#351

Earlier quoted context omitted.

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.

This sums up the situation that government regulations don't work. These regulations put us on the path of trusting religious-like in government. We could be working toward push-button simple network segmentation with some kind of default filtering for install by the average home user.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#352
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

I like this angle. Require device manufacturers to actually comply with OSS licenses and extend it to require providing the means for consumers to build upon the software as you mention.

Furthermore, if the concern is national security, then I think some of the onus should be on the corporate consumers of such devices. Holding them responsible for doing due diligence on their vendors seems easier to regulate and enforce than trying to regulate supply side.

Of course, this leaves the general population without a clear solution to updates if the process of updating using alternate channels has any amount of friction whatsoever. I'm clueless as to what to do about that. Regulating it entrenches established companies. Not regulating it maintains the status quo.

Anecdotally, it feels like software has gotten far more secure in the past decade without regulation but security theater and concerns around national security have grown considerably faster. This isn't easy to measure of course, but that's how I see it.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#353

Earlier quoted context omitted.

Liability. Make the manufacturer liable if a known vulnerability is exploited.

I would think that tort law already achieves this - unless some law was passed that shields manufacturers from lawsuits. If that's the case, then the easy fix is removal of such shields instead of trying to create new regulations. Same applies to nearly all aspects of product liability.

I would expect some sort of license "agreement" that shields the manufacturer and resellers from all liability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#354
post #124

Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…

I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it might reasonably be expected to allow an attacker to take control of a device, or to do so when combined with other known or unknown vulne…

A cyber vuln is a defect in a product expected to function well. In other domains (cars, apartments, pharmaceuticals), if there is a defect, the manufacturer is responsible to ensure it is fixed.

It seems pretty simple. The standard should be the same as used in other industries where vendors need to recall, repair, or refund products in case of defects.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#355
I can't see this changing much if they water it down to a point where liability isn't an issue. If a company is weighing whether to put resources into a security update vs. roll the dice on whether they are used as an attack vector, where they will be sued and just declare bankruptcy, I don't think it would be effective.

Doubly so if their products are still in use after the company goes under. Now who is liable? What protections can one create for this scenario?

Most consumers will never file a lawsuit against such behavior because it is an incredibly uphill battle.

I get the sense that regulation like this will just create a new goalpost that won't ultimately help consumers, we've seen it happen time and time again, but I don't have a better idea. I suspect if you tried to enact real change you'd get too much opposition.

Tricky situation.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#356
post #310

With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…

I can see it being useful for audiences who know what they're looking for. As an average retail consumer, if I saw such a label I would either have no idea what it means or have to do my own research about what UL is - not to mention the impossibility of them enforcing anything. I guess they could remove the label but how would I know a product I'm using has violated their commitment - routinely check a UL website?

It would be up to the certification organization to market their seal of approval to increase awareness.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#357

This is off-topic but while you're here, the amateur radio regulations regarding baud / symbol rate really need to be removed and replaced with a 2.8kHz bandwidth limit. See Section 97.307(f).

Thanks for raising this. I support the law addressing this issue and would also support Commission action on this.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#358
The most important thing is what happens after vendors fail and disappear - the code and keys and reproducible build system must be released so people can fix their things.

A standard and an org for keeping those things in escrow, please!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#359

Earlier quoted context omitted.

You're the lawyer guy? What statutory authority are you drawing on that you believe allows you, the FCC, to regulate this stuff? Thanks!

Good question. The Notice of Proposed Rulemaking has a Legal Authority section that discusses this issue https://www.fcc.gov/document/fcc-proposes-cybersecurity-labe... . I also touch on it here https://news.ycombinator.com/item?id=37393316

Thanks, but, that FCC document clearly says it's about a "voluntary labeling program", and, the title of this HN post has the word "regulation" and the text has language like "require" [0]. And the phrase "oppose[...] even voluntary ones", which clearly sounds like someone's proposing non-voluntary stuff.

I read your linked HN comment too, but: "legitimate interest in" [1] a thing and actual "authority" to do a thing are not the same thing.

I feel like I'm being bamboozled here. The fcc.gov "Notice", and this HN post, seem like they're talking about substantially different proposals.

[0] "I’ve advocated for the FCC to require device manufacturers to support their devices with security updates for a reasonable amount of time"

[1] "...we think that the FCC has a legitimate interest in just about any vulnerability on a wireless device"

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#360

With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…

This would make for a fine comment on the record. It would be great to have suggestions about pros and cons of government, court, third-party and other audit means.

I'll work on it some more based on feedback I'm receiving and submit it. Thank you.
Post reply on HN