Earlier quoted context omitted.
Then fire your shitty vendor or refund your customers. Nothing will change unless everybody changes.
You can't fire your SoC vendor especially once the product ships. And their are all PITA about security updates.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
371–380 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#372Earlier quoted context omitted.
I like this approach, it doesn't necessarily need to be just the "market" performing the audits however. The FDA handles audits of medical software companies just fine. Focusing on the Quality Management System and their Risk Assessment/Security practices seems like a solid approach, and of course centralize this data and make it easily searchable as much as possible, and provide API access to it in case vendors like…
FDA: $450K per product. And they aren't doing very much more than asking the vendor to describe their protocols, then ensure the vendor complies with their protocols and any agency guidance. Source: I work at an FDA-regulated company.
Still, many IoT companies that sell products don't even have protocols or a QMS at all, and need some kind of heat applied to them.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#373Earlier quoted context omitted.
Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.
The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.
That's a clear call to specific action as opposed to "We don't have rules that would have prevented this, and also many of the rules we do have across several agencies don't have enough funding to enforce rules designed to solve other problems."
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#374Hi thanks for the work here. I read through (some) of the linked materials including the statements. The proposal itself is enormous, and all of it is extremely well researched. (Reading the comments here it reads like few folks read your links as most of the comments are addressed in some way). That that end, and I realize part of these exercises is exhaustiveness, due to the legal and regulatory nature, it would be…
it would be really useful if there were a TLDR version
I agree; I'm hoping that the tech press takes up this topic, but an "official" one would make engagement much faster.
I think the labeling should be simple - like a small discrete set of classes for compliance that can be extended over time with further rules. So 20 years security updates is “platinum” 10 years is “gold” 5 is “silver” or something. Then the classes of label can accrete meaning over time as you enhance your proposals.
This is how I'm thinking about it too -- not just for support term, but for all kinds of things, FOSS firmware in escrow, bankruptcy transition plan, responsibility to publish and implement fixes from public databases -- there's so much that might go into each tier, and while I have my own ideas, it would be great to see the tech community take up these questions.
in some ways a way to work best is right here in the HN comments and then lifting material up into your direct work via the proposal and statement
Also true, and my team will be doing a detailed after-action on this thread once it winds down.
To that end maybe reaching out earlier in the process to get feedback would work
That's one to grow on for next time. The good news is that the final rule (I'd expect end of Q2 2024) will also be subject to notice-and-comment.
Seriously, a huge thank you for your close engagement. I'm really excited about what the tech world can bring to this high-level proposal.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#375How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.
Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#376Earlier quoted context omitted.
I would think that tort law already achieves this - unless some law was passed that shields manufacturers from lawsuits. If that's the case, then the easy fix is removal of such shields instead of trying to create new regulations. Same applies to nearly all aspects of product liability.
I would expect some sort of license "agreement" that shields the manufacturer and resellers from all liability.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#377Earlier quoted context omitted.
Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…
This is an amazing idea and I would only buy a product that has this stamp on them. I would put some additional triggers into the publication of source code as well, notably if the company goes out of business. I would also put some kind of timer and renewal process on it, like a company needs to recertify every 1-5 years (pros and cons to different time lengths) and that they have indeed been providing actual update…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#378How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing?
Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the owner has physical access to the device. Will the manufacturer be liable for damages caused by attacks on vulnerable devices that were not sufficiently updated by their owners?
IoT is making its way into defense and enterprise environments where reliability is a matter of national security. An update nearly always results in some downtime for the device, even if it's just a couple seconds. Sometimes, it may be in the best interest of a device's owner to defer an update indefinitely, until that device's continuous operation is no longer mission-critical. Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#379With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…
The UL example is one where it would be hard for improved security to happen by itself. UL was founded to solve for fire risk when insuring buildings. It received funding from underwriters that would benefit from the label. I don't see any particular entity benefiting from security labels - it's a problem of the "commons" where you generally need government intervention of some sort of.
IFF companies have financial liability, then the market can be expected to find a cost-effective solution.
Without any selection pressure though, there is no reason tho think the market will spend resources to solve this. Users empirically don’t understand security, don’t price it appropriately in advance, and aren’t able to evaluate the security qualities even if they do want to pay more for a “secure” product.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#380Earlier quoted context omitted.
The UL example is one where it would be hard for improved security to happen by itself. UL was founded to solve for fire risk when insuring buildings. It received funding from underwriters that would benefit from the label. I don't see any particular entity benefiting from security labels - it's a problem of the "commons" where you generally need government intervention of some sort of.
You can't see the consumer benefitting from a certification label? Interesting. Also, the vendor benefits by gaining more sales.