Earlier quoted context omitted.
Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn. Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen. This is literally a national security issue. We currently stifle security research on essential IoT device…
This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
561–570 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#562I've dealt with this multiple times, so let me give my perspective. - It is hard for manufacturers to do this with small teams. Mostly because they do not always have good CI/CD or platforms available to keep being on top of vulnerabilities and so on and so forth. - Not all manufacturers write their own software and often contract it out to other experts in the field. This includes firmware and app developers. - If a…
> If a producer goes out of business they should be forced to give out a signed firmware that disables the key checking, then they must put up their source code for any users who wish to build and flash it themselves. Requiring an organization to do even a small amount of engineering as it is going under is simply not going to work in practice. IMHO the only possible way for something like this to work is to require…
The only way to know that it works is to let people install custom firmware from day one, so they can discover if they can't and raise their objections before the company is defunct.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#563Abandoned IoT devices if there are few of them are an issue for the consumer and they should be enabled to at least help themselves or hire help.
Abandoned IoT devices if they are in larger numbers can pose a threat to the network and one may consider what could be done about those.
Abandoned IoT devices also are an economic burden as they cause a premature loss of value of investments of consumers and investors. Worse are way too many horror stories out there of critical infrastructure running on outdated platforms. These devices were bought at a time where computers were rare. If we extrapolate 15 years from now based on the experience we have today - we will not see accumulated economic loss but disasters too.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#564Voluntary certification, please. Law is slower than technology. This is a good thing! EnergyStar is a great example of a voluntary program doing more good than DoE or FTC mandates. HIPAA is a good example of what happens when mandates can’t keep up with technology. When it comes to security, we can’t afford another HIPAA.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#565Earlier quoted context omitted.
I'm working on an IoT device for industrial use, and we're wrestling with this very problem. The answer we're probably going to go with is that the device is 'leased' to the customer. It's part of their subscription. This solves a ton of problems about FLOSS and support of the same. It's now a closed device, and you have no rights to the code inside. If we go out of business, you have a brick that you don't have to p…
>> The answer we're probably going to go with is that the device is 'leased' to the customer. It's part of their subscription. 1000% wrong answer, unless you straight up front sell a service with an installer making a site visit to deploy chattels of service. such as satellite television, or DSL internet. when you swap handfulls over the counter before any contractual agreements i.e. clickthrough TOS , you are sellin…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#566How is a small business going to be able to pay for this? This will be something that big tech can do but not startups that are bootstrapped.
This is being proposed as a completely voluntary program. No need to participate in it if you don't want an FCC cybersecurity label on your product.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#567How is a small business going to be able to pay for this? This will be something that big tech can do but not startups that are bootstrapped.
Valid point. Customers would then need to prepare for a new reality where their options are limited and potentially more expensive.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#568Earlier quoted context omitted.
Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn. Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen. This is literally a national security issue. We currently stifle security research on essential IoT device…
This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#569Earlier quoted context omitted.
That's great for the 0,1% of users who will do that. As said: I'm all for it. But the problem is the other 99,9%.
Seriously. I'm a SWE and I would throw out a TV and get a new one before spending hours minimum figuring out how to switch the firmware to a open source version.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#570Earlier quoted context omitted.
This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…
Why does everyone compare things to houses? If you want to be more consistent with your building analogy, IoT sold to the public or enterprises are more like bars, except that each user has their own privately owned bar that may or may not be stocked by a central liquor company. If a user wants to check it's not possible for someone to break into his bar, or slip poison into his booze shipments, or redirect the shipm…
Using housing as a metaphor is common because it's an incredibly common thing people can relate to with personal experience, and is something people typically have relatively detailed intuitions built around what they are okay with and not okay with regarding it.
It got the point I was making across, but I do think there was a misunderstanding about what I was applying it to. I was referring to people who probe businesses security vulnerabilities on the internet side of IoT, not people who check for vulnerabilities in things they own on the T side of IoT.
As for the bar analogy, I agree that there is a lot of room for reasonable due diligence to test the security if there is potential for you to be at risk of its failings. This is more in line of my last paragraph, and I do still assert that solutions that avoid the need for people to verify security themselves should be preferable to one's that do.
If you've got 2 legally independent entities messing with the same device, and then abuse of the device does happen and it leads to damages - can you understand how much more difficult this becomes to sort out than if the company was solely responsible for the device?