Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

481–490 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#481
1. The platform doesn't exist to do basic things like authentication or push notifications, so people hack together expensive cloud services or do insecure things instead. There is no rulemaking that will help this, we just need a better and universal platform.

2. "Keeping things patched" works in a world with Apple-like margins and it simply does not in a low-volume, startup-oriented, competitive market. No rules pay for a company to spend $500k a year on a dev team when a product didn't make enough profit - developers cost a ton and make the prices much higher, so these products are not the ones that win in the market.

3. If open standards cannot satisfy #1, then we have to look for other corporate structures, like a "Microsoft + Intel" marriage where hardware can be sold for cheap but the software remains supported by third parties. We see some of this with cloud companies like Alexa, Apple, and Google Home, but it's not really healthy yet, because there are no incentives to do things on the LAN in a secure way, so we are just hiding the costs of servers in other ways.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#482

Earlier quoted context omitted.

This sums up the situation that government regulations don't work. These regulations put us on the path of trusting religious-like in government. We could be working toward push-button simple network segmentation with some kind of default filtering for install by the average home user.

> These regulations put us on the path of trusting religious-like in government. We don't need to have religious-like faith in government because we can vote for people who will do what we want them to and we can vote out the people who refuse to do their job. It doesn't happen without the people getting involved and holding their government accountable though. You don't have to pray when you can vote. Without regula…

Maybe I could have some faith if regulatory bureaucrats were fired when there are major regulatory failures e.g. 737 max. Maybe I could have some faith if police state agency employees were jailed for FISA abuse.

Voting isn't enough because even elected officials aren't allowed to fire these people.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#483

Earlier quoted context omitted.

What do you mean by "no"? Are you denying the existence of my grandparents who trust me to manage their devices?

I am saying that people like you are not enough to help the 99% of people who have an iot product.

Apart from Smart TVs, most people don't have an IoT device to begin with.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#484

Earlier quoted context omitted.

While I acknowledge that CVE scoring of risk can be inconsistent and sometimes wildly wrong, what would you suggest in its place?

just go by past incidents. Quite often it is not software vuln that enables hacker's attack - it is insecure default config that user never changes and manufacturer supplies same default user/pw with each device. also insecure backdoors left by developers for debug purposes (or is it really debug or maybe espionage?)

> also insecure backdoors left by developers for debug purposes (or is it really debug or maybe espionage?)

It should be made clear that any "backdoor" is a criminal offense under the "unauthorized access" provision of the Computer Fraud and Abuse act, unless the device is covered by an explicit remote maintenance agreement which imposes duties upon the maintainer.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#485

Awesome! Thanks for engaging, where the rubber meets the road! Hopefully, you are also looking into other venues, as well. HN has a great group of folks that represent some of the most cutting-edge tech, but IT runs on Java 8[0]. [0] https://news.ycombinator.com/item?id=19877916

Thanks for participating! After this thread winds down, I and my team are going to comb through it for suggestions and take as many as we can. We're also looking into other venues to engage directly with cybersecurity professionals. But please feel free to comment on the record as well -- a robust and detailed record is worth a lot more than whatever I can do individually.

An even better venue for informed cybersec professionals is the info-sec community on Twitter and Mastodon, https://infosec.exchange/about .

People like Michal Zalewski, https://twitter.com/lcamtuf, could point you to the best of that.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#486
post #312

Earlier quoted context omitted.

> There are also often practical issues related to security patching embedded devices: for example, a downstream supplier's driver can make it impossible to upgrade a kernel unless/until the supplier provides a fix. Of course, strong regulation here could help to drive bad practices like that out of the industry, but I'm not going to hold my breath on that one. The effect of regulation like this would make it harder…

> I would love it if the lawmakers considered this scenario. You're building on quicksand, and you're asking for us to give you leeway when the building collapses. Either do the work of making all of those security fixes yourself, or pick a better platform to build on top of.

> pick a better platform

Unfortunately there isn't all that much competition in this space. The choice was try building on quicksand, or let the idea die. I'm glad we tried it.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#487

As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…

> Remote update mechanisms can themselves present security problems in some domains.

Not really if done right to be fair. It's just a matter of implementing a signature verification of the firmware updates that are installed on the device.

> IoT is making its way into defense and enterprise environments where reliability is a matter of national security.

If it's a matter of national security surely you don't use IoT devices connected to the public internet. At least the devices are in some private network, where the traffic is under your control. So if you don't do security updates it may be acceptable under that circumstances.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#488
Is there any way to tie an expectation of long term security support with legal protection of the product against competitors/reverse engineers/other parties that manufacturers may not want looking too closely?

I’m not suggesting granting additional protections to manufacturers, but codify an expectation of “if you abandon it, other people can come in and potentially salvage it”

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#489

As someone with a libertarian bent, meaningful labels appeal to me as a decent way to address problems without overriding the judgement of the market. An informed market avoids lemons. So this proposal sounds OK in principle but here are some questions. Please be aware that I'm not a US citizen so my views don't really matter here, I'm just looking over the garden fence and asking questions. 1. Your argument for why…

> An informed market avoids lemons. Has that been true in practice? I can think of plenty of horrible products, in IT, on the market. In terms of security (including privacy), the market has done nothing for IT consumers. And what about the people who already bought the lemons, before the market learned of it? Also, what if the lemon doesn't affect me but affects others (such as through DDoS)? I prefer to keep it as…

Nothing? Hasn't Apple built a part of their brand upon security and privacy?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#490

Earlier quoted context omitted.

Which the manufacturers of IoT devices will give us willingly out of the goodness of their hearts?

Yet government is made of people so it does not have God-like powers, even though it is often worshipped. I would prefer to plug in a box that does this segment/filter. I will pay if it can be rebuilt from available source code. Make it easy to install and setup. If nobody purchases then nobody cares and why would government get involved? Seems like FCC scope creep. Forcing every IoT vendor to do it overlooks the pro…

> Yet government is made of people so it does not have God-like powers, even though it is often worshipped.

A slightly bizarre aside.

Post reply on HN