Earlier quoted context omitted.
Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.
The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
351–360 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#352How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.
Furthermore, if the concern is national security, then I think some of the onus should be on the corporate consumers of such devices. Holding them responsible for doing due diligence on their vendors seems easier to regulate and enforce than trying to regulate supply side.
Of course, this leaves the general population without a clear solution to updates if the process of updating using alternate channels has any amount of friction whatsoever. I'm clueless as to what to do about that. Regulating it entrenches established companies. Not regulating it maintains the status quo.
Anecdotally, it feels like software has gotten far more secure in the past decade without regulation but security theater and concerns around national security have grown considerably faster. This isn't easy to measure of course, but that's how I see it.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#353Earlier quoted context omitted.
Liability. Make the manufacturer liable if a known vulnerability is exploited.
I would think that tort law already achieves this - unless some law was passed that shields manufacturers from lawsuits. If that's the case, then the easy fix is removal of such shields instead of trying to create new regulations. Same applies to nearly all aspects of product liability.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#354Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…
I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it might reasonably be expected to allow an attacker to take control of a device, or to do so when combined with other known or unknown vulne…
It seems pretty simple. The standard should be the same as used in other industries where vendors need to recall, repair, or refund products in case of defects.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#355Doubly so if their products are still in use after the company goes under. Now who is liable? What protections can one create for this scenario?
Most consumers will never file a lawsuit against such behavior because it is an incredibly uphill battle.
I get the sense that regulation like this will just create a new goalpost that won't ultimately help consumers, we've seen it happen time and time again, but I don't have a better idea. I suspect if you tried to enact real change you'd get too much opposition.
Tricky situation.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#356With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…
I can see it being useful for audiences who know what they're looking for. As an average retail consumer, if I saw such a label I would either have no idea what it means or have to do my own research about what UL is - not to mention the impossibility of them enforcing anything. I guess they could remove the label but how would I know a product I'm using has violated their commitment - routinely check a UL website?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#357This is off-topic but while you're here, the amateur radio regulations regarding baud / symbol rate really need to be removed and replaced with a 2.8kHz bandwidth limit. See Section 97.307(f).
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#358A standard and an org for keeping those things in escrow, please!
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#359Earlier quoted context omitted.
You're the lawyer guy? What statutory authority are you drawing on that you believe allows you, the FCC, to regulate this stuff? Thanks!
Good question. The Notice of Proposed Rulemaking has a Legal Authority section that discusses this issue https://www.fcc.gov/document/fcc-proposes-cybersecurity-labe... . I also touch on it here https://news.ycombinator.com/item?id=37393316
I read your linked HN comment too, but: "legitimate interest in" [1] a thing and actual "authority" to do a thing are not the same thing.
I feel like I'm being bamboozled here. The fcc.gov "Notice", and this HN post, seem like they're talking about substantially different proposals.
[0] "I’ve advocated for the FCC to require device manufacturers to support their devices with security updates for a reasonable amount of time"
[1] "...we think that the FCC has a legitimate interest in just about any vulnerability on a wireless device"
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#360With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…
This would make for a fine comment on the record. It would be great to have suggestions about pros and cons of government, court, third-party and other audit means.