Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

391–400 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#393
I think this is a bad idea which will lead to fewer and more expensive devices. I do not want the FCC regulating this.

It is much more reasonable to have the market impose some discipline on manufacturers and their level of support. Plenty of consumers would favor less costly, less-supported devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#394

Earlier quoted context omitted.

This sums up the situation that government regulations don't work. These regulations put us on the path of trusting religious-like in government. We could be working toward push-button simple network segmentation with some kind of default filtering for install by the average home user.

> These regulations put us on the path of trusting religious-like in government. We don't need to have religious-like faith in government because we can vote for people who will do what we want them to and we can vote out the people who refuse to do their job. It doesn't happen without the people getting involved and holding their government accountable though. You don't have to pray when you can vote. Without regula…

How well did that work for bank oversight in 2008, and again in 2023 with SVB? The accountability of "my one vote will remove government's failed regulators" fails on the scale of $billions.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#395
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

> There are also often practical issues related to security patching embedded devices: for example, a downstream supplier's driver can make it impossible to upgrade a kernel unless/until the supplier provides a fix. Of course, strong regulation here could help to drive bad practices like that out of the industry, but I'm not going to hold my breath on that one. The effect of regulation like this would make it harder…

As the support schedule for python is known ahead of time, this scenario seems pretty well covered by "disclosure of how long the product will receive security updates": just choose the EOL for the relevant python version in the date-picker.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#396
post #319

Earlier quoted context omitted.

Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…

So this feels like an amazing idea...but do we really want to give the federal government the keys to update your equipment remotely and to be able to pinpoint weaknesses of the source? This feels like Edward Snowden's grimmest nightmare.

As I understand that's not what's being proposed. The "keys" in this case would decrypt the encrypted source code that's available in a public repository, and there's some logical mechanism(and actual use for smart contracts) that would key the key in escrow until certain conditions are met(company doesn't renew, goes out of business, etc.) After which it will be publicly released so anyone can decrypt the already available encrypted source code

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#397
post #173

I think that IOT device manufacturers should be required to support their device for some minimum period of time AND be obligated to release the full source code for the device once they decide to end support. This also requires releasing the keys to any firmware signing mechanism or publishing a firmware update that removes such checks. The core problem is that without control of the firmware, consumers don't really…

There's also the problem that electronic devices last a long time -- often much longer than any manufacturer wants to admit. Vehicles, PCs, printers, and routers can easily last 10 years. Refrigerators and HVAC units can last 20 years or more. And now we're putting "smart" stuff into electric circuits that should last the lifetime of the house. The manufacturer will probably go out of business long before those devic…

Some sort of escrow with a dead man switch could solve this. They can reset the switch by releasing an update or affirming that they are still providing service. If no communication is received after a certain period of time, then it gets released publicly.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#398
post #319

Earlier quoted context omitted.

Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…

So this feels like an amazing idea...but do we really want to give the federal government the keys to update your equipment remotely and to be able to pinpoint weaknesses of the source? This feels like Edward Snowden's grimmest nightmare.

Framed like that, it sounds terrible. However, consider this:

[1] This discussion is about a federal agency providing certification of products essentially in the form of a stamp (on a device, website, etc.). Nothing is stopping a vendor from committing to and offering the same thing but without government involvement. This could easily be a selling point for the paranoid. Something something blockchain and smart contracts...

[2] Even though we're discussing IoT devices, it's not necessary that they be capable of updating over the air 24/7. Creative engineers could probably devise a method to prevent complete remote takeover by anyone holding the keys– physical switches, additional authentication required during the support period, etc.

[3] Personally, I think the federal government getting access to keys for any IoT device made/sold in the US is the only part of this idea that could already be happening. They can knock on doors or mail subpoenas, plant moles, etc. I would be much more comfortable with a technical solution on the physical device than any presumption of privacy in the current state.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#399
post #75

What about industrial IoT? Even if a manufacturer publishes updates, the clients would likely not want to change anything, often. If you have a plant with 1,000 units of gizmo-A and update them during a week-end and now 200 of them do not do the thing they used to do anymore... you have a big problem. There is a genuine fear to update anything in many industries and I am not sure how this can be overcome.

I'm not sure it should be overcome. Updating software is not a panacea and not always the best thing to do. In industrial hardware it's often better to have a known quantity. Especially with equipment that can cause damage or even kill people. Even if it isn't quite that high stakes, dealing with constant random updates is a cost factor with no clear commercial gain. This doesn't mean there can't be updates, but they…

Yeah, I don't operate software controlled heavy machineries, but it's not comforting when I update a physically moving machine and it makes different sounds than before due to altered algorithms and parameters.

Also, it's not considered a huge issue in smartphones and laptop computers, but updating firmware on Flash ROM degrades its performance such as data retention periods. Firmware updates are not always a rocket surgery, but like a surgery, not without risks. I think advocating frequent updates to all types of electronics is slightly irresponsible.

(Edited to add! I'm writing in good intentions but I'm not a US person, in case that matters)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#400
post #313
post #252

Maybe we need to approach it differently? There will always be an "End of Life" date. And there will always be a user using the product beyond it. So my question is: How do we make it safe? My first thought is a "deadman's switch". If a device doesn't get or see some form of a signal, it just stops updating and disables IOT features. If the user wishes it to come alive again, there's a button they can press to have i…

I am not a fan of this idea as it would only contribute to eWaste, but I think one aspect I can get onboard with is a clearly defined expiration for updates. I think we would be getting too far into the weeds to specify what "security updates" means as there will always be ways to work around the language, but the fact that a manufacturer will guarantee a certain expiration of updates would be better than where we ar…

I don't want my TV to "expire". I want to be able to use it with a gumstick if I still like it!

I think of IOT devices as a continuum:

One one end, Alexa and friends, which is a brick without Amazon. Good luck fixing that in a real way.

On the other, a washing machine. It'll wash clothes for 10-15 years, just fine. It may only get security updates for 5... but who cares. So it can't tell me by app when my clothes are done, it is still very useful.

TVs, Cars, etc... all fit on this line in a way.

And remember: People will use these devices past their expiry. They will get rooted, and turned into botnets and other crap. We have to choose our evils. I merely want a safe device at the end. Regardless of how long or short it lives.

Post reply on HN