I think FCC needs to step in on other things too. For one I think digital scalping has gotten out of hand. Something needs to be done to protect users and consumers. I think we need regulation on this matter. People use bots to buy up tickets or products and resell. The difficult part is how to enforce and prevent scalping.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
571–580 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#572The reasonable life of the equipment should be based on equipment type. It should also be clearly described and communicated to consumers how much support the manufacturer will provide the product over the life of the product and into future.
Manufactures should have to estimate how long a product can last and will receive updates based on their testing and in reasonable conditions of use. And what environment it was tested in.
Also, based on the Samsung recent leaks where many accounts were related to IOT devices we know the security risk is not just at the device level but in a broader sense the company itself.
How a company manages and deletes / archives data safely is a paramount issue that also flows into securing IOT devices better as well.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#573Earlier quoted context omitted.
Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.
The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.
HN when EU passes laws that have significant teeth in them and let them actually enforce them: This is ridiculous overreach! It will kill innovation and make it impossible to do business there!
Love it, never change <3
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#574How will the regulations keep up with evolving security best practices?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#575How can we define a security vulnerability meeting this "serious" requirement? There are a wide variety of vulnerabilities, so it seems difficult to define this strictly.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#576Does the FCC have any authority over IOT devices? and if so how? This seems like a massive overreach, how can a body designed to for managing shared spectrum have any authority on devices that use the internet?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#577As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…
> Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs. +1 for this at the consumer level. My oven may have a critical update, but - for right now - *nothing* is more critical than finishing dinner. I'll let the update apply the day after thanksgiving when I'm doing the dishes. There are a few connected appliances brands that do this well: updates…
Is finishing the dinner more important than applying a patch that fixes actively exploited bug that locks your oven into cleaning mode and burns everything inside into ash over the next three hours? Or something that disables the safety checks and lets the oven overheat and burn your house down?
(Granted, the latter shouldn't physically be possible because it should have physical temperature killswitches etc.)
People always (understandably so!) consider software updates to be annoyances; but especially when you give an example like _an oven_, the potential for _catastrophic_ failures is too great.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#578I have one cast-iron, non-negotiable relation with IoT objects:
No IoT device should ever hide what it is doing from me.
If it lives in my house, car or environment it is not acceptable for me to install something which then tries to hide its operations.
I don't care who it's made by or how much they think they are "helping me".
Whether by encrypted tunnelling, side channels, secure enclaves or whatever devious shitfuckery, if I can't put Wireshark on my network and put a name and purpose to every operation then I'll track down the origin and eliminate it.
Further, I am simply not interested in any "arguments" claiming this is "necessary". It is not. Profit, spying and control are always the ulterior motive, and they are unacceptable. Do not allow anyone to pretend they are "security" and hide behind that word. Security for whom, from whom and to what end....
Also there should be no "embedded function" which I cannot turn off with confidence, perhaps by a physical jumper or switch. No IoT device should ever reset itself to insecure defaults.
Thanks for enquiring and good luck in your difficult work.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#579Earlier quoted context omitted.
This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…
Do you believe that your proposal increases the cybersecurity of society as a whole? You focus a lot on the rights and conveniences of a company, but the rights of a company are not more important that the security of society as a whole. There are good guys and bad guys out there looking for vulnerabilities. What you propose reduces the number of good guys more than it reduces the number of bad guys (since bad guys a…
This benefits society as a whole because it clearly delineates actions with intent. If doing X is always not allowed, then all you need to do is find people doing X and you can hold them accountable.
If you allow or disallow the same activity based on merit of intent, then you increase the level of plausible deniability to everyone who gets caught.
I am not proposing security through ignorance. I am proposing security through consent. Nowhere did I say anything about not allowing research, I only said that if you do it unsolicited then it should be considered a threat.
So, we could systemically allow for a right to research that involves notice to the company and their consent for you to test. It would not hinder white hat at all. If businesses resist for selfish reasons we can expand the law to prevent them from denying requests without a legitimate reason. For example, maybe it is okay for them to deny a request from an ex-employee with a grudge who has sent the company aggressive emails. Idk, maybe there are no valid reasons to deny. The point is we can create a framework that promotes security development above the table with all parties involved. And my proposition is that if that is possible then it should be preffered.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#580Earlier quoted context omitted.
Why does everyone compare things to houses? If you want to be more consistent with your building analogy, IoT sold to the public or enterprises are more like bars, except that each user has their own privately owned bar that may or may not be stocked by a central liquor company. If a user wants to check it's not possible for someone to break into his bar, or slip poison into his booze shipments, or redirect the shipm…
I was speaking towards probing the business not the things you own. Using housing as a metaphor is common because it's an incredibly common thing people can relate to with personal experience, and is something people typically have relatively detailed intuitions built around what they are okay with and not okay with regarding it. It got the point I was making across, but I do think there was a misunderstanding about…