Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

381–390 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#381

Earlier quoted context omitted.

The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.

This sums up the situation that government regulations don't work. These regulations put us on the path of trusting religious-like in government. We could be working toward push-button simple network segmentation with some kind of default filtering for install by the average home user.

> These regulations put us on the path of trusting religious-like in government.

We don't need to have religious-like faith in government because we can vote for people who will do what we want them to and we can vote out the people who refuse to do their job. It doesn't happen without the people getting involved and holding their government accountable though. You don't have to pray when you can vote.

Without regulation you could only ever have religious-like faith in private corporations because they have zero incentive to act benevolently and you have zero power to replace a CEO who is acting against the interests of the public. You have no vote, so prayer is all you have left.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#382

Earlier quoted context omitted.

I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glass, and get a sticker from the US Government saying so, it better be brick-proof.

Well, my comment is predicated on the, apparently erroneous :), assumption that no glass is brick-proof. It is impossible to build a secure software product with our current tooling & development practices. The number of security flaws in every software product is so high as to make the label meaningless. I don't think there's a meaningful distinction to end consumers between "this product has 1,000 holes, 100 of whi…

> the, apparently erroneous :), assumption that no glass is brick-proof

That reminds me of:

> With sufficient thrust, pigs fly just fine.

https://www.rfc-editor.org/rfc/rfc1925

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#383
I think the most valuable security feature for IoT devices is being able to work without contact with a central service.

If the value of a device is tied to opening a connection to and occasionally retrieving code from a third party it is inherently insecure. All I have to do is buy the company that owns the central server (or compromise it in some other less visible way) and I now have the ability to introduce malicious code to all devices that are receiving 'security updates.' You won't be able to make a rule to prevent asset transfer (correct me if I'm wrong) so you won't be able to close this hole. And this assumes the manufacturer isn't malicious in the first place.

For people to be able to protect themselves and to protect the value of the property they have purchased (e.g. the company tanks and the central service is lost) a rule should exist mandating minimum useful functionality in a disconnected and/or self-managed environment.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#384
Although I don’t have much to add on the specific topic here, I wanted to applaud you for coming to this community for consultation. If we want to see better regulation of our industry, this is exactly the sort of thing we need to see more of. (As opposed to dusty formal public comment processes easily gamed by rent-seekers.)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#385

Earlier quoted context omitted.

> There are also often practical issues related to security patching embedded devices: for example, a downstream supplier's driver can make it impossible to upgrade a kernel unless/until the supplier provides a fix. Of course, strong regulation here could help to drive bad practices like that out of the industry, but I'm not going to hold my breath on that one. The effect of regulation like this would make it harder…

This is an honest question to these arguments, but as a consumer (and as an extension the FCC protecting them) why should I care? Would you accept the same arguments from your car manufacturer, "sorry we can't fix your broken brakes, our supplier uses a process that isn't supported by new brake standards so just don't brake"? I suspect not, so why not because the car is more expensive? I would argue that the purpose…

The same thing happened to my car — they discontinued support for the cellular module it shipped with. I had to bring it in (and I believe pay something) to have the module updated. I did not and now it no longer has the online functionality.

Brakes are not internet-connected, but where the line is between features or functions that might be lost and those that represent the core of the product is an interesting question.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#386

Earlier quoted context omitted.

Good question. The Notice of Proposed Rulemaking has a Legal Authority section that discusses this issue https://www.fcc.gov/document/fcc-proposes-cybersecurity-labe... . I also touch on it here https://news.ycombinator.com/item?id=37393316

Thanks, but, that FCC document clearly says it's about a "voluntary labeling program", and, the title of this HN post has the word "regulation" and the text has language like "require" [0]. And the phrase "oppose[...] even voluntary ones", which clearly sounds like someone's proposing non-voluntary stuff. I read your linked HN comment too, but: "legitimate interest in" [1] a thing and actual "authority" to do a thing…

Maybe, reach out to the FTC over the fraud that's being perpetuated with this cloud-locked (other peoples' servers) *rental* being sold as a *sale* ?

If these companies are selling defective goods and preventing individuals to fix it themselves (in other words, the selling company holds material control of the device), that's a *rental* .

Properly reclassifying consumer garbage with company-locked electronics as a rental would be the big kick-in-the-pants that nearly every company is playing now. And that includes the cellphone-on-wheels (Tesla), the stunts being played by most other car manufacturers ($$$ for heated seats, etc), Apple holding control over what approved software a general purpose computer can process, and loads more.

I don't think the FCC can require firmware updates other than in radio based units, to require regulatory requirements for specific frequencies (2.4GHz no channel 12/13 in USA, 10 minute wait on a part of 5.8GHz for ground radar). But the FTC could force it by clarifying cloud-crap is a rental, and not a sale.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#387

Earlier quoted context omitted.

This sums up the situation that government regulations don't work. These regulations put us on the path of trusting religious-like in government. We could be working toward push-button simple network segmentation with some kind of default filtering for install by the average home user.

Which the manufacturers of IoT devices will give us willingly out of the goodness of their hearts?

Yet government is made of people so it does not have God-like powers, even though it is often worshipped.

I would prefer to plug in a box that does this segment/filter. I will pay if it can be rebuilt from available source code. Make it easy to install and setup. If nobody purchases then nobody cares and why would government get involved? Seems like FCC scope creep.

Forcing every IoT vendor to do it overlooks the problem of each vendor having and maintaining the skillsets.

How about something like UL to create a slim standard and test against that standard. The aforementioned box idea could apply to be tested against the standard.

https://www.ul.com

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#389
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

Thank you for these thoughtful points. Some relevant responses from other threads: From https://news.ycombinator.com/item?id=37394188 : I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it mi…

> How generalizable do you think such a solution could be? We are aware of the Uptane project, an OTA firmware update framework being jointly worked on by several car manufacturers, but would love to hear more about the feasibility of a solution for IoT devices generally, or particular classes of IoT devices.

One thing to be aware of: a decent number of connected devices are white label devices or "lightly" tweaked forks of a reference design. The consumer-facing company may have no power to actually update anything. If the originating company only provides proprietary versions of some critical component and can't/won't ship updates, the consumer-facing company can only patch issues with _their_ portion of the final software running on the device.

A _requirement_ that the consumer-facing company be able to update any/all portions of the software stack for $someTimeFrameAfterSale might start to change this but expect a fight from every link in the software-supply-chain on this front.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#390
post #252

Maybe we need to approach it differently? There will always be an "End of Life" date. And there will always be a user using the product beyond it. So my question is: How do we make it safe? My first thought is a "deadman's switch". If a device doesn't get or see some form of a signal, it just stops updating and disables IOT features. If the user wishes it to come alive again, there's a button they can press to have i…

IMHO the biggest problem is that there is no end-of-life date made clear to the user. I think if the purchaser could clearly see the support lifetime on the box then they can make an informed decision. Maybe this model that costs 50% more but is supported for 10y rather than 2 is a better deal after all. I don't think we need to kill the device. Ideally it would somehow be made clear to the user when it drops out of…

I never said to kill it. I said to kill it's IOT functionality. There is a very big difference.

Think of a washing machine. It'll still wash clothes... it may not ping the internet portal anymore, it isn't "safe".

Post reply on HN