Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

411–420 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#411
post #124

Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…

The irony is that botnets often function as an automatic update: they break in through a vulnerability, often include a patch for said vulnerability, and then stay somewhat updated via their C&C server. Of course, this is all to prevent other botnets from coming in and stealing their devices away.

We had a WiFi camera get compromised. We put it on the internet - so it could get an update - and it got pwned before the update even finished downloading. The malware blocked the admin interface, but kept the camera feed running, presumably to minimize suspicion. As far as we can tell, the actual vuln was patched (some sort of dumb command injection in one of the many exposed endpoints), so there was also no way for us to get back in.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#412
Here's a thought. Your proposal is really to create an FCC Cybersecurity label, but why does it matter?

For a long time in the US since the 1960s, we had the private industry UL and their trademarked seal they enforced. The standards were quite rigorous and in response to many residential and commercial accidents, fires, and more. The problem is over time, the industry created ETL/Intertek to compete because of cost. They claim to be another standards testing body like UL but their actual standards are quite loose and verification looser. Now in 2023? Nobody cares anymore.

You have Amazon selling literal fire hazards for electrical equipment that no brick and mortar retailer in their right mind will sell without UL or ETL certification. The CPSC barely is able to make Amazon take down products, and the flood is immense.

I just don't see how a voluntary label will solve anything.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#413
The single biggest problem with IoT devices is the black box, vendor-specific cloud platform nature. This causes privacy issues galore as well as requiring every manufacturer to reinvent the wheel to secure their devices, while also making huge quantities of ewaste when Random Manufacturer #484 goes out of business, taking their cloud with them.

How about instead, mandating that all IoT devices need to comply with an open standard? Customers would be free to connect their device to Siri or Alexa if they wanted, but by default the device just works with an open standard that you can control fully, hosted at home if desired.

It would also remove the cloud security onus from the manufacturer—they would fund the standards org, which would be responsible for the security of the interface.

We already have this concept for electricity, phones, networking. You don’t buy a “MA Bell” phone anymore or an “Edison-compatible” fan.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#415
I strongly suspect that regulation at the IoT product level will have a very small practical impact because I think its largely targeting the wrong issue. The vast majority of the vulnerabilities aren't coming from the manufacturer, many of them are making relatively small changes to a reference design provided by a company like Broadcom (which is notorious for exactly the behavior I'm about to describe).

The reference design problem is an issue where a manufacturer like Broadcom creates a specialized chip. To use this chip they create a "reference driver" for it, package it in a custom firmware, then will never update that reference software. I've worked building internet routers for homes and small business and there are pieces of software we couldn't touch because they had been modified and only the fully compiled version is provided.

Broadcom passes the buck by calling it a reference design and washing their hands of it. Some upstreams do provide the source, but it's the complete source, not just the changes they made and usually without any specific reference to what the specific version they based their changes on was. Trying to tease specific changes from the Linux kernel's raw source code is quite the needle in the haystack problem.

I'm not sure how a lot of device manufacturers _could_ handle this. They tend to have very small development teams that are more electrical engineers than software engineers and usually their only directive is to make it work under an extraordinarily tight deadlines. Maybe part of the answer is they need to hire more to be more responsible... But even with experienced developers _every single hardware manufacturer_ is going to have to repeat the security fixes that companies like Broadcom refuse to fix.

I don't even know where to begin proposing a legal foundation for reference design software. I do think if the penalties and pain were strict enough at this level it would lead to a different shortcut that would be much more beneficial to the world... If Broadcom and other companies doing this kind of malicious apathy were forced to keep their reference designs up to date, my money would be that they stop doing it entirely and instead get those driver merged into the Linux kernel proper where it can be properly maintained and updated by the legion of developers that care.

The act of getting that code into the kernel would force them to improve the code and not take the shortcuts that cause so many headaches because the kernel developers gate the quality of code they produce.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#416

Earlier quoted context omitted.

But if I have an ethernet-connected device that doesn't emit RF for some non-networking purpose, it should still qualify. It should just need the transducer and a network connection.

I don't think it would for this specific proposal. The FCC's justification for this rule is that insecure IoT devices "could be manipulated to generate and emit RF energy to cause harmful interference". That's why they have jurisdiction here, because they regulate radio frequency use.

Ah, I see.

Well, I stand by my position that the other is also a problem, but maybe this rulemaking isn't an approach that can cover that.

Don't get me wrong, this is still worth doing...

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#417

Earlier quoted context omitted.

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

This may be beyond the FCC's purview, but given some of the comments (e.g., https://news.ycombinator.com/item?id=37393644 ) perhaps an entirely different strategy is warranted. Instead of trying to compel manufacturers, who may no longer even exist, to support their old products; perhaps the government should focus on protecting consumers and aftermarket vendors who update / modify / reverse-engineer older revisions-…

Fully agree. If some company vanishes, consumers are left holding the shit end of a broken stick. It would sure help if there were protections for those that effectively volunteer their time and effort to keep things running for others.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#418
post #400
post #313

Earlier quoted context omitted.

I am not a fan of this idea as it would only contribute to eWaste, but I think one aspect I can get onboard with is a clearly defined expiration for updates. I think we would be getting too far into the weeds to specify what "security updates" means as there will always be ways to work around the language, but the fact that a manufacturer will guarantee a certain expiration of updates would be better than where we ar…

I don't want my TV to "expire". I want to be able to use it with a gumstick if I still like it! I think of IOT devices as a continuum: One one end, Alexa and friends, which is a brick without Amazon. Good luck fixing that in a real way. On the other, a washing machine. It'll wash clothes for 10-15 years, just fine. It may only get security updates for 5... but who cares. So it can't tell me by app when my clothes are…

> On the other, a washing machine. It'll wash clothes for 10-15 years, just fine. It may only get security updates for 5... but who cares. So it can't tell me by app when my clothes are done, it is still very useful.

> TVs, Cars, etc... all fit on this line in a way.

Sure but you are missing an entire category of devices that revolve around home automation. Think light switches, dimmers, faders, plugs and door bells. These types of devices have an interface but also need IoT to be useful but not necessarily the cloud. If I install something like this in a light panel, it seems a little odd to me to "kill the IoT" of the device. It loses tremendous value. Again think of the incentives. Should we be incentivizing manufacturers to create devices that can so easily be created that lose value that I may have invested in as a part of a renovation?

Can we create/incentivize an ecosystem of IoT devices that can live without the manufacturer tying these devices to a cloud service or the Internet in general?

Let's find ways to incentivize second lives vs another renovation 5 years from now when my light switches and outlets no longer get updates.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#419
post #385

Earlier quoted context omitted.

This is an honest question to these arguments, but as a consumer (and as an extension the FCC protecting them) why should I care? Would you accept the same arguments from your car manufacturer, "sorry we can't fix your broken brakes, our supplier uses a process that isn't supported by new brake standards so just don't brake"? I suspect not, so why not because the car is more expensive? I would argue that the purpose…

The same thing happened to my car — they discontinued support for the cellular module it shipped with. I had to bring it in (and I believe pay something) to have the module updated. I did not and now it no longer has the online functionality. Brakes are not internet-connected, but where the line is between features or functions that might be lost and those that represent the core of the product is an interesting ques…

That's the thing though: most IoT devices shouldn't be Internet-connected, and most definitely should not depend on a vendor cloud (or increasingly, a cloud of a different vendor that sold white-label IoT solution to the "vendor" you you bought the device from). It's an unnecessary limitation, a combination of laziness (going over cloud is easier than figuring out local-first and standardizing on some VPN solution) and abusive business (the cloud on the other side of the world is holding your Internet-connected air conditioner hostage, better play nice).

If brakes are not Internet-connected, that's mostly because they were established before Internet - and given the trends in car manufacturing in general, it's only a matter of time.

(In some sense, we're already there - if you have cloud-connected self-driving, and that self-driving can override your command to apply brakes, then your brakes are de-facto Internet-connected, even if connectivity isn't a hard dependency in all cases just yet.)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#420
This is a wonderful thread, and I am so glad to see so many sharing my nightmares and some of my conclusions. I encourage folk to work together on actually filing proposals with the FCC in their format. I would gladly join on such an effort, but am too busy to lead such an effort.
Post reply on HN