Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

511–520 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#511

A required support period of some number of years is problematic for products developed by startups, because startups cannot guarantee that they will still exist to provide support in several years. They can have the best of intentions and excellent engineering, but still fail in the market and be unable to keep maintaining a device. So requiring security support for several years wouldn't have any effect on these de…

Totally valid point. Escrow then open sourced, or perhaps even some insurance policy so that the future patching and vulnerability remediation is guaranteed.

There's a bunch of stuff consequential to EO 14028 which could allow for some automation of library vulnerability.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#512
People need to admit one can't protect systems from the unknown. Thus, detection and incident handling is arguably more important.

If CISCO/Google/Amazon/Microsoft can't keep their systems clean, than you can be certain adversaries who feign ignorance will be much worse regardless of the paperwork.

A certification program similar to EMC testing in labs would however be favorable, as it does not consolidate the attack surfaces. Additionally, it allows the test to evolve with emerging threat vectors.

If you think companies will let people poke around their security policies for paperwork stamps, than you are fooling yourselves.

Good luck, =)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#513
post #492

Earlier quoted context omitted.

> Remote update mechanisms can themselves present security problems in some domains. Not really if done right to be fair. It's just a matter of implementing a signature verification of the firmware updates that are installed on the device. > IoT is making its way into defense and enterprise environments where reliability is a matter of national security. If it's a matter of national security surely you don't use IoT…

> It's just a matter of implementing a signature verification of the firmware updates that are installed on the device. In principle: yes. In practice: signing keys seem to get leaked all the time. It's not a mechanism I would blindly trust in security sensitive domains.

We could start by asking iot companies to be ISO 27002, stop saving passwords in excel files or in s3 bucket publicly accessible could help

Security is not an update, security is a cultural trait of an entity or an individual

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#514
post #440

Earlier quoted context omitted.

There is an overlap with the right to repair topic. It does not make sense to have the DMCA hanging over your head when you are reverse engineering a product that is abandoned by the manufacturer - be it end of life or bankruptcy to name two reasons among many.

Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn. Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen. This is literally a national security issue. We currently stifle security research on essential IoT device…

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent.

I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, even if it's for research purposes. There is an inherent risk of your vulnerabilities being broadcasted somewhere either on purpose or accidentally once that information is collected and organized by the researcher.

It isn't harmless and innocent to probe anything for weaknesses unsolicited. It is reasonable to respond to that as a threat. It is genuinely threatening behavior.

Now I do understand it gets complicated when it's a business being trusted with sensitive information / access to devices in your home. I am just saying as part of the solution we need to keep possibly threatening behavior in mind and try to avoid the promotion of it as part of the solution unless there is really no other way (imo)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#515
post #371

Earlier quoted context omitted.

If you buy from a supplier with a contract that stipulates security updates then you certainly would define the damages which failure to fix will cause you, wouldn't you?

One of the issues is that the upstream vendor goes out of business. What you really need is to have the source code for the firmware, ideally in the public mainline kernel tree so that new kernel versions continue to work on the hardware.

Certainly true. Source code escrow should be part of any kind of company selling internet connected devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#516
I am not an US citizen, so I cannot have a say here, but I have another idea.

What's the problem if an IoT device is vulnerable? In the worst case the user will have to buy a new one (or pay someone for fixing it). Is it a serious problem? I think, no. Eventually users will understand which manufacturers are reliable and which are not.

You probably want to argue, that infected devices can be used in DDoS attacks. But in this case, why don't you take measures against DDoS attacks directly and leave IoT devices alone?

Why, despite Internet existing for 50 years, there is no protocol, using which any host can demand all upstream providers to block traffic from specific IP addresses? This would make low-level (transport-level and below) DDoS attacks impossible.

Make such standard and make it required for all top-level ISPs. In this case the malicious traffic can be stopped at source network or at least at Tier-1 level. Middlemen like Cloudflare would become unnecessary, and you would be able to withstand a multigigabit DDoS attack even having just $5 VPS.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#517
Greetings from Ukraine, European country with real Great war just now.

I must say, we see extreme grow of cyber-crime as part of modern war. I think, in nearest future, cold war will guaranteed have huge cyber-crime part.

And, hacking of IoT devices has very significant share of cyber-crime now. For real war it is question of life and death, because hacked devices with radio emission, are used by hostile intelligence, to find targets for attacks of heavy weapon, but also, we seen cyber attacks on electric-energy infrastructure, indented to make blackout (fortunately for us, unsuccessful).

Chinese IoT devices are very special part of question, in many cases are connected to Chinese clouds, and this is also extremely dangerous, not only because potential unfriendly Chinese moves, but also because their security is not good enough, so in many cases, cyber-crime could intercept communications and interfere operation of device or even hijack control.

For example, exists smart door locks with camera and I hear hackers hacked them and used them to observe work of air defense, so enemy could tune their air attacks to make more harm.

In civilian life without war, videos from hacked door locks (or other IoT cameras) could be used for illegal surveillance, to coordinate riots, etc.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#519
Regulating here is necessary, but the challenge is steep! IoT devices may include a complex bill of materials (BoM) including software (SBoM). Vulnerabilities can appear in any of those components.

On the one hand, CVE and vulnerability databases are excellent, and with some automation of vulnerability and patch availability the's the possibility of automated re-build.

But the manifests can be huge. And some component could be vulnerable, but was never anticipated to be so, and perhaps doesn't even have the means to be patched. Update processes for sub-sub-components may not have been exercised, and could lead to bricked products.

So labelling and guarantees are welcomed. But the challenge is practically insurmountable, and until the entire industry steps up to meet it, labelling and guarantees are going to be 'best effort'.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#520
post #19

FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…

I think this might be useful if we kind of wargame prospective regulations to follow all the ways people might abuse it, then you might get something that works. Maybe lawmakers already do that? This thread feels in that spirit too…
Post reply on HN