Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

441–450 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#441
post #140

Earlier quoted context omitted.

I've been not-buying IOT trash as hard as I can for decades. But nothing's changing... please tell me how to do this correctly!

Well, lots of people have been not-buying liquorice their whole life, but nothing's changing. The market for liquorice candy is alive and well. Less snarky: if other people still want to buy certain products, manufacturers will provide. But that's not a bad thing. Different folks have different preferences.

Insecure IOT has the huge externality of providing muscle to criminal botnets, though.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#442
Been in the IoT space for over 10 years and this is much needed. In my experience, Cellular based IoT devices are inherently more secure than non cellular devices due to the network security and the certifications they go through. Of course, there are exceptions to this rule. Would be interested to learn more about the proposed regulations while not impacting the pace of innovation.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#443
post #46

There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…

Going to echo my thanks here as well.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#444
One solution not being discussed much: formal verification. Any given "critical" IoT software component ideally should be subject to rigorous mathematical inspection in order to verify its logical integrity. Upon passing, it could then be signed with an FCC-issued key (along with the understanding that no unsigned software be installed during updates). While there are indeed plenty of theorem provers to be found in the wild, most are likely too domain-specific to solve the problem right out of the box. So the solution is hardly trivial, but it would nonetheless be a worthy (if daunting) undertaking.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#445
post #388

How is a small business going to be able to pay for this? This will be something that big tech can do but not startups that are bootstrapped.

Valid point. Customers would then need to prepare for a new reality where their options are limited and potentially more expensive.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#446
post #365
post #320

Earlier quoted context omitted.

This is great for hackers but doesn't it make IoT devices incredibly insecure for normal users who wouldn't even know their device has reached end of support?

> doesn't it make IoT devices incredibly insecure for normal users How secure or insecure a device is is unrelated to whether its source code is public. Disclosure: I might be biased on this, as I'm a reverse engineer.

I think the parent comment is implying that if the source code is released at the end of the device's supported life, it will be much easier for hackers to find vulnerabilities. Then users who aren't paying attention will continue running that last version, and hackers will attack them using those now-public vulnerabilities.

So you'd still need some mechanism to force-update devices in response to vulnerabilities found in open-source end-of-support firmware.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#447
post #388

How is a small business going to be able to pay for this? This will be something that big tech can do but not startups that are bootstrapped.

This is being proposed as a completely voluntary program. No need to participate in it if you don't want an FCC cybersecurity label on your product.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#448
Please consider requiring making source code available instead of "updates". If the vendor will no longer "support" a product, then the vendor should let the buyer support it themselves and release the source code. In practice, what we know can happen is that buyers may share their support solutions and actually support each other. The story of Cisco's WRT54G router is an example of what's possible.

If security is truly a concern, then all IoT devices connecting to the internet should be routed through a computer that the owner fully controls, which is likely to be running OpenWRT. Any tactics used by IoT vendors to evade traffic monitoring by the computer owner, e.g., discouraging self-signed TLS certificates, should be prohibited.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#449

Earlier quoted context omitted.

Thanks, but, that FCC document clearly says it's about a "voluntary labeling program", and, the title of this HN post has the word "regulation" and the text has language like "require" [0]. And the phrase "oppose[...] even voluntary ones", which clearly sounds like someone's proposing non-voluntary stuff. I read your linked HN comment too, but: "legitimate interest in" [1] a thing and actual "authority" to do a thing…

Nathan's post and the proposed rulemaking are both quite explicit that the proposal under comment is a voluntary labeling scheme. Perhaps the intro could be better written to be clearer, but I don't really understand your complaint. There's no bamboozle. From above: "I’ve advocated for the FCC to require device manufacturers to support their devices with security updates for a reasonable amount of time [1]. I can't b…

Thanks! Sorry for any lack of clarity. My initial draft was way over the character limit and I had to cut a lot prior to posting. Thanks for highlighting the relevant language and clearing things up.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#450
post #176

Thank you for engaging with the community in this way. Many years ago, in a fight to preserve individuals ability to flash their own routers, Vint Cerf, and I, and a coalition of many others, filed this report: http://www.taht.net/~d/fcc_saner_software_practices.pdf (retaining the ability to reflash our own routers, allowed my research project to continue, and the resulting algorithm, fq_codel (rfc8290), now runs on…

There's no small amount of irony in the fact that attempting to open your .PDF without the comforting assurance of SSL gives me a "security warning" that I have to go out of my way to circumvent. I'm sure that it won't be long before it will simply become impossible for me to open the file "for my protection."

The push to mandate certificates and other gatekeeping mechanisms that enforce obsolescence for the sake of digital security theatre is ultimately going to benefit corporate bottom lines (especially those of landfill operators), but it will indisputably harm consumers.

I guess I should turn that into a comment and submit it...

Post reply on HN