Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

521–530 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#521
post #511

A required support period of some number of years is problematic for products developed by startups, because startups cannot guarantee that they will still exist to provide support in several years. They can have the best of intentions and excellent engineering, but still fail in the market and be unable to keep maintaining a device. So requiring security support for several years wouldn't have any effect on these de…

Totally valid point. Escrow then open sourced, or perhaps even some insurance policy so that the future patching and vulnerability remediation is guaranteed. There's a bunch of stuff consequential to EO 14028 which could allow for some automation of library vulnerability.

I was trying to think of ways to finance it, and "future patch insurance" is clever! There are other sorts of business insurance where the insurer is liable even if the business no longer exists, so it would be doable. Though a policy would require a level of technical competency that other insurance policies don't, since their providing a guarantee of service rather than a guarantee to pay out a certain amount in damages.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#522
post #369

Earlier quoted context omitted.

Thank you very much for reading. It was the first, and last time, I ever took place in the public process and political action. https://www.computerworld.com/article/2993112/vint-cerf-and-... We were within months of delivering a massive RFC8290-based fix for wifi performance and we´d been bricking routers left and right... and then got in a whole bunch that we could not modify... due to that proposed regulation... I…

Thanks again -- will review both links (especially the latter!) The FCC hasn't traditionally been a cybersecurity agency and will, most likely, never really be one; however, we can certainly do things through rules to empower experts, the public, and the agencies with cybersecurity expertise. If that one thing is all you ever did at the FCC, sounds like the public owes you a big debt of gratitude.

As communications increasingly overlaps with other elements of information --- data acquisition, storage, retrieval, processing, and transmission --- keeping the FCC out of the security space will become both more difficult and less tractable.

We've already seen instances where broadcast channels have been hacked or hijacked, where false reports have been injected into news streams (at times affecting global financial markets, or disrupting emergency / disaster responses), where communications providers have disabled public access to alerts (mobile providers and wildfires, Twitter's recent hostile takeover), and more.

There's also the overlap between communications and monopoly (generally the FTC's remit), which I realised a few years back: Censorship, surveillance, propaganda, and targeted manipulation (AdTech and similar tools) are all intrinsic properties of media monopolies:

https://web.archive.org/web/20201014011009/https://joindiasp...>

https://news.ycombinator.com/item?id=24771470>

There are other concerns where media are highly decentralised or fragmented, including spread of rumours and confusion (e.g., "fog of war", or the general uncertainty in natural disasters or after political and military upheavals such as Germany as the Third Reich fell). But the monopoly -> media concerns issues seem well established. Most though not all of these are addressed by people such as Tim Wu, Bruce Schneier, Cory Doctorow, and Shoshana Zuboff, though I'm not aware that all the components I've identified had been linked previously.

I'm aware that regulatory agencies are constrained by their legislative mandates, but communicating concerns over those limitations to Congress is also possible.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#523
As a developer and a consumer, what I'd really like to see is:

- Manufacturer voluntary guarantee of 1/3/5 years security updates with an expiration date.

- Separation of functionality and security updates.

- The ability to "turn off" connectivity and retain full local functionality.

- An industry security certification like UL.

- A single point way of identifying and validating devices.

As it is, I avoid using IoT mostly for security reasons. Having worked in security for many years I have seen the best and the worst. Having security isn't a panacea either - it needs an ongoing management & reporting infrastructure.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#524
post #3

commitments on this label (including the support period) will be legally enforceable in contract and tort lawsuits and under other laws. When it comes to U.S. laws that touch technology, enforceability is a mess. Spyware, spam, fraud, misleading labels, etc. are already governed by various state and federal laws, yet enforcement efforts are whack-a-mole at best. For IoT devices, having the proposed requirements sound…

If there’s a private right of action you can bet the class action lawyers will do the enforcing.

Fair enough, but against whom?

Fly-by-night foreign manufacturers or exporters would be difficult to prosecute. Unless the domestic importer, reseller, or transportation provider can be held liable, even class action lacks teeth.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#525
Thank you so much everyone for the interesting, high-quality discussion so far. My team and I are looking forward to continuing to engage with you for at least a few more hours.

Just a reminder: As fun as discussing this in here with you is, the best way to influence what the FCC ends up doing is to file an official comment by September 25th at https://www.fcc.gov/ecfs/search/docket-detail/23-239 . Click to file either an ‘express’ comment (type into a textbox) or a ‘standard’ comment (upload a PDF). The FCC is required to address your arguments when it issues its final rules. All options are on the table, so don’t hold back, but do make your arguments as clear as possible so even lawyers can understand them. If you have a qualification (line of work, special degree, years of experience, etc.) that would bolster the credibility of your official comment, be sure to mention that, but the only necessary qualification is being an interested member of the public.

Finally, I'd like to extend a special thanks to dang and the rest of the HN team for their help putting this together. They have been a pleasure to work with.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#526
post #319
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…

A challenge to this sort of suggestion is that the device OEM rarely controls all the software which goes into a device. There are third-party modules, hardware drivers, and more, which are also components. Then there are patents.

Either the escrow would have to apply to all software on the device, regardless of whether owned by the OEM or third parties, or OEMs would be required to vouch for all the included software.

I'd prefer the former myself: multiple software and patent assets can be combined, but on support EOL, all those become public domain.

Build / release / update toolchains must also be included.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#527
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

^^^ This right here ^^^

Additionally, this cannot be an excuse to charge subscriptions or force lease agreements into the fine print for items consumers buy outright.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#528
Maybe it is the price model. It should state what type of security updates are included and for how long these are for free and what the expected cost after that is. I think a problem is that you buy a thing and not a thing and a service.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#529

Earlier quoted context omitted.

Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn. Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen. This is literally a national security issue. We currently stifle security research on essential IoT device…

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

there needs to be consent from the company being probed for vulnerabilities

What is the type of scenario that you have in mind here? Do you mean probing a web service for vulnerabilities, performing security assessments as part of pre-sale publications (think Consumer Reports, Anandtech reviews etc), or performing pen-testing on a device I bought and is now running on my home network? Because you appear to be arguing that I shouldn't be allowed to examine a device I own without explicit manufacturer consent.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#530
post #517

Greetings from Ukraine, European country with real Great war just now. I must say, we see extreme grow of cyber-crime as part of modern war. I think, in nearest future, cold war will guaranteed have huge cyber-crime part. And, hacking of IoT devices has very significant share of cyber-crime now. For real war it is question of life and death, because hacked devices with radio emission, are used by hostile intelligence…

Hi and thanks for commenting. My concern with this topic is motivated in part by the AcidRain family of energy infrastructure attacks and the larger questions they raise about infrastructure security. Teardowns on Chinese-sourced equipment have been somewhat worrying as well -- one report I've read highlighted about two dozen versions of SSH in a single base station. Best wishes and good luck.
Post reply on HN