Earlier quoted context omitted.
The UL example is one where it would be hard for improved security to happen by itself. UL was founded to solve for fire risk when insuring buildings. It received funding from underwriters that would benefit from the label. I don't see any particular entity benefiting from security labels - it's a problem of the "commons" where you generally need government intervention of some sort of.
You can't see the consumer benefitting from a certification label? Interesting. Also, the vendor benefits by gaining more sales.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
491–500 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#492As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…
> Remote update mechanisms can themselves present security problems in some domains. Not really if done right to be fair. It's just a matter of implementing a signature verification of the firmware updates that are installed on the device. > IoT is making its way into defense and enterprise environments where reliability is a matter of national security. If it's a matter of national security surely you don't use IoT…
In principle: yes. In practice: signing keys seem to get leaked all the time.
It's not a mechanism I would blindly trust in security sensitive domains.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#493I care more about my privacy than I do about the security of my device, but an architecture that supports the second almost always supports the first (my neighbours hacking my zigbee isn’t a threat model almost anyone should be concerned about, unless there’s a pattern of hacking en masse).
I found out my smart lights literally have a microphone in them the other day, under the guise of ‘plays light to your music’ or something.
I architect my IOT by implementing a network without internet, fronted by home assistant - that way my devices can’t ‘phone home’ which who knows what privacy infringing crap.
I know that botnets driven by iot is a real and ongoing problem, but it’s a problem that is probably not going to get much vendor buyin without regulation, but what I’m pointing out is that it’s not the only threat facing these devices.
I want:
- clear guides on what data is collected, I don’t trust they’d only use it the way they say they will so I wouldn’t bother reading that part, if it existed
- the ability to opt out of any data collection aside from anything required to do technical updates. I want any data transfer to occur in a clear and auditable way (e.g the ability to inject a root CA and perform a mitm if I wish)
- enough protocol spec that at least basic functions can work offline via a system like home assistant
These won’t directly solve the ddos vectors, but they will solve the problems that come shortly after on the timeline.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#494Earlier quoted context omitted.
Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.
Indeed, this is awesome. Not sure if you're able to comment on this, but is there anything in place to mitigate the risk of automated astroturfed commentary e.g via LLMs in this and other cases? Edit: on the fcc docket specifically, not on HN
Look at HN account age, karma, and comment histories.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#495Earlier quoted context omitted.
I don't want my TV to "expire". I want to be able to use it with a gumstick if I still like it! I think of IOT devices as a continuum: One one end, Alexa and friends, which is a brick without Amazon. Good luck fixing that in a real way. On the other, a washing machine. It'll wash clothes for 10-15 years, just fine. It may only get security updates for 5... but who cares. So it can't tell me by app when my clothes are…
> On the other, a washing machine. It'll wash clothes for 10-15 years, just fine. It may only get security updates for 5... but who cares. So it can't tell me by app when my clothes are done, it is still very useful. > TVs, Cars, etc... all fit on this line in a way. Sure but you are missing an entire category of devices that revolve around home automation. Think light switches, dimmers, faders, plugs and door bells.…
Yes, we should. But alas, the incentives run the exact reverse today. Today they get to monitor your usage of the lights, resell the data, etc.
You are part of the product.
OTOH: If I look at this as a vendor, where else where the light switch go for updates?
I'd be VERY hesitant to direct wire any IOT device into my house, if I wasn't comfortable ripping it out in 6mo, when the company decides to desupport it and kill the app.
For me this is a the exact opposite problem: I won't adopt until I know that these issues are ironed out, or I accept that the device is 100% disposable.
There's cases where I can't avoid it, TVs, Cars, etc. It is pushed on me, like it or not. For those, I truly do want safe mode, so I can pick how it networks.
To me this generation is lost. I accept that. It is sad. I want to win the NEXT one, or the one after. And only by making the life cycle EXPLICIT will we do that.
When a customer goes into Home Depot and says "My lightswitch stopped working in 2 years, you got something that will live longer this time?" The problem is self solving.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#496I think the most valuable security feature for IoT devices is being able to work without contact with a central service. If the value of a device is tied to opening a connection to and occasionally retrieving code from a third party it is inherently insecure . All I have to do is buy the company that owns the central server (or compromise it in some other less visible way) and I now have the ability to introduce mali…
> "All I have to do is buy the company that owns the central server (or compromise it in some other less visible way) and I now have the ability to introduce malicious code to all devices that are receiving 'security updates.' You won't be able to make a rule to prevent asset transfer (correct me if I'm wrong) so you won't be able to close this hole." Has this actually been a problem in the past? I do not know of any…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#497For a labelling program for this type of company, you could require additional disclosure to consumers at the time of sale, along the lines of "We can't guarantee that we'll provide security updates." Or you could require open-sourcing of firmware if a company goes defunct. Or perhaps device manufacturers could be required to hand the technology of to some third party maintainer if they go under.
Any regulation at end-of-support-life has the "company disappears" problem, so probably disclosure at time of sale is the only thing that could be reliably enforced.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#498I think that IOT device manufacturers should be required to support their device for some minimum period of time AND be obligated to release the full source code for the device once they decide to end support. This also requires releasing the keys to any firmware signing mechanism or publishing a firmware update that removes such checks. The core problem is that without control of the firmware, consumers don't really…
This is great for hackers but doesn't it make IoT devices incredibly insecure for normal users who wouldn't even know their device has reached end of support?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#499Earlier quoted context omitted.
This is an honest question to these arguments, but as a consumer (and as an extension the FCC protecting them) why should I care? Would you accept the same arguments from your car manufacturer, "sorry we can't fix your broken brakes, our supplier uses a process that isn't supported by new brake standards so just don't brake"? I suspect not, so why not because the car is more expensive? I would argue that the purpose…
The same thing happened to my car — they discontinued support for the cellular module it shipped with. I had to bring it in (and I believe pay something) to have the module updated. I did not and now it no longer has the online functionality. Brakes are not internet-connected, but where the line is between features or functions that might be lost and those that represent the core of the product is an interesting ques…
The issue with software OTOH, is that a security hole in one trivial component (e.g. resize images to make thumbnails) can often lead to a full system compromise. Even if you don't get full root, you can still use a compromised system to your advantage: steal personal data, use it in a botnet, serve malware, mine proof of waste, etc.
On top of that, adding a dependency is often made very easy by modern package managers, and as the number goes up it gets rather difficult even to vet your direct dependencies, let alone transitive. Installing brakes in a vehicle doesn't automatically pull in a kitchen sink, but in the software world it's widely accepted, almost inevitable. You can spend your time removing the 90% of that library that you don't need, and rewriting the remaining 10%, or you do the "reasonable" thing and just ship.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#500Earlier quoted context omitted.
Are you in favor of seat belt and airbag requirements? What about the bans on asbestos and lead paint?
Are you in favor of seat belt and airbag requirements? No. The presence of these features is easy to document, and the harms are limited to the person making the $/risk tradeoff. What about the bans on asbestos and lead paint? This is more justifiable. The harm is very far removed from the manufacture (time, place) and it is hard to evaluate whether a given space has these features when e.g renting.
and the harms are limited to the person making the $/risk tradeoff
That's not really true. Certainly the harm is concentrated there, but it leaks onto their passengers, whoever has to face vehicular manslaughter charges that should've been more minor, etc. and it is hard to evaluate whether a given space has these features when e.g renting.
But it's hard to evaluate every aspect of any product, let alone all of them. Do you research the manufacturer of the capacitors in your phone chargers to prepare for the next capacitor plague? Do you perform supply chain analysis on the local sandwich shop to make sure their current veggie supplier isn't one associated with unusually high rates of salmonella? Or do you, at some point, assume that the things around you are generally safe?