Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

461–470 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#461
I have personally found several IoT vulns in everything from Zoom devices to Japanese robot hotels, and I run a security consulting firm. Swooping in with my 2c.

Most of the time the engineers making these things -think- they are reasonably secure, but they tend to have little to no infosec experience and are moving too fast with no accountability.

Worse, even when there is some accountability such as code review, the release engineer creates the security problems at release time either as a supply chain attack or stupidity.

If I were making the rules, I would ramp up common sense supply chain accountability which would cause some of the most prevalent problems to be spotted early.

My wish list:

1. Require all source code be signed (git signatures or similar)

2. Require all source code reviews by peers be signed (minimum 1)

3. Require source code to compile deterministically

4. Require at least two individuals or entities verify code signatures, compile code, and compare identical hashes

5. Require proprietary firmware products have an external security firm on retainer incrementally reviewing code (including dependencies!), as well as reproducing, and co-signing releases.

6. Require proprietary products use a source code escrow service that will make their code public the day support and security updates stop so the consumer community can patch for themselves

7. Require open source firmware products have a bug bounty program (potentially with government funding like the EU does)

Happy to chat about this sort of thing with anyone interested. Contact info in my bio.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#462
post #319

Earlier quoted context omitted.

Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…

This is an amazing idea and I would only buy a product that has this stamp on them. I would put some additional triggers into the publication of source code as well, notably if the company goes out of business. I would also put some kind of timer and renewal process on it, like a company needs to recertify every 1-5 years (pros and cons to different time lengths) and that they have indeed been providing actual update…

Classic tech to think of technical solutions to a regulatory problem, but I like it.

Could have the code run in a sandbox where people can apply “external” network traffic trying to hack it (or apply vulnerabilities), inspired by how you can run ML models on kaggle.org on Kaggle servers to validate models.

Have end-points as honney-pots, so if you can access these endpoint you prove you have compromised the code.

If there is no new code with patches the keys are released.

This way FCC/gov don’t need to maintain a technical system. Just build this once.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#463
This is likely outside of the scope of this proposal, but my red team brain sees IoT devices from China as a distributed Trojan Horse.

In a time of conflict with China, firmware updates will be sent which will create the largest DDOS botnet in history.

Our cheap IoT lightbulbs will take down major internet infrastructure.

I don’t know the solution to that problem, but it’s a problem. Isn’t it?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#464
post #440

Earlier quoted context omitted.

This may be beyond the FCC's purview, but given some of the comments (e.g., https://news.ycombinator.com/item?id=37393644 ) perhaps an entirely different strategy is warranted. Instead of trying to compel manufacturers, who may no longer even exist, to support their old products; perhaps the government should focus on protecting consumers and aftermarket vendors who update / modify / reverse-engineer older revisions-…

There is an overlap with the right to repair topic. It does not make sense to have the DMCA hanging over your head when you are reverse engineering a product that is abandoned by the manufacturer - be it end of life or bankruptcy to name two reasons among many.

Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn.

Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen.

This is literally a national security issue. We currently stifle security research on essential IoT devices primarily so companies can avoid being embarrassed by their own poor security.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#465
This is not really relevant to the proposed rulemaking but it is something that bugs me deeply, and would like to get off my chest. I would like to see a mandate that red LED be wired inband to every camera and microphone, on every device, so if it is powered up, the LED is also. This is what John Gilmore proposed in 2004, and we adopted in the OLPC project, as the first step towards not being ubiquitously surveilled. It is low cost, low power, and easy to implement.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#466

This is likely outside of the scope of this proposal, but my red team brain sees IoT devices from China as a distributed Trojan Horse. In a time of conflict with China, firmware updates will be sent which will create the largest DDOS botnet in history. Our cheap IoT lightbulbs will take down major internet infrastructure. I don’t know the solution to that problem, but it’s a problem. Isn’t it?

Not just on the firmware level. Many cheap IoT products are based on the Chinese ESP32 SoC.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#467
post #183

Earlier quoted context omitted.

Yeah if companies that make IoT hardware complain about the costs to keep old devices updated then they should be required to make them more user-modifiable and release source code / signing keys when they're abandoned by their manufacturer so that they can be picked up by the communities and development can be continued (also requires some policing to determine when hardware is functionally abandoned, as releasing a…

Releasing Signing keys seems a potentially dangerous one. Someone could produce malicious firmware, sign it, and convince your device to auto-update with it. I think (and I'm a security know-nothing, so could very well be off in the weeds), the firmware should accept updates signed with two keys. The manufacturer key, which can allow automatic updates, and a post-service key that cannot be automatic. Either a user ha…

Presumably they'd remove the auto-update functionality before releasing signing keys and require that it be physically loaded by a user at that point.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#468
You might be interested in this (in French, but you may try with google translate or other alternatives :) https://www.bortzmeyer.org/8240.html

It is a very interesting explanation of debates around https://www.rfc-editor.org/rfc/rfc8240.txt

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#469

Earlier quoted context omitted.

> These regulations put us on the path of trusting religious-like in government. We don't need to have religious-like faith in government because we can vote for people who will do what we want them to and we can vote out the people who refuse to do their job. It doesn't happen without the people getting involved and holding their government accountable though. You don't have to pray when you can vote. Without regula…

How well did that work for bank oversight in 2008, and again in 2023 with SVB? The accountability of "my one vote will remove government's failed regulators" fails on the scale of $billions.

>How well did that work for bank oversight in 2008, and again in 2023 with SVB

Hilarious own goal on this one.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#470

Earlier quoted context omitted.

This is an honest question to these arguments, but as a consumer (and as an extension the FCC protecting them) why should I care? Would you accept the same arguments from your car manufacturer, "sorry we can't fix your broken brakes, our supplier uses a process that isn't supported by new brake standards so just don't brake"? I suspect not, so why not because the car is more expensive? I would argue that the purpose…

The issue is that it's currently not a regulatory requirement. So when you go to the chip maker and demand that their chip have drivers in the Linux kernel tree so it will continue to support newer kernel versions, they turn you down. Most of their customers don't care about this and they would have to pay a developer to produce drivers of the quality that would be accepted by the Linux kernel maintainers. Then you'r…

I don't understand your argument, are you agreeing with me that regulation will cause this to happen? So why is that an argument against regulation?
Post reply on HN