Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

571–580 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#571
I will need to read more about this over time. How does this effect Fedramp based stuff?

I think FCC needs to step in on other things too. For one I think digital scalping has gotten out of hand. Something needs to be done to protect users and consumers. I think we need regulation on this matter. People use bots to buy up tickets or products and resell. The difficult part is how to enforce and prevent scalping.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#572
What about requiring proactive exploit identification to be paid out and then patched by manufacturers for reasonable life of equipment?

The reasonable life of the equipment should be based on equipment type. It should also be clearly described and communicated to consumers how much support the manufacturer will provide the product over the life of the product and into future.

Manufactures should have to estimate how long a product can last and will receive updates based on their testing and in reasonable conditions of use. And what environment it was tested in.

Also, based on the Samsung recent leaks where many accounts were related to IOT devices we know the security risk is not just at the device level but in a broader sense the company itself.

How a company manages and deletes / archives data safely is a paramount issue that also flows into securing IOT devices better as well.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#573

Earlier quoted context omitted.

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.

HN when governments agencies have little leverage to enforce rules: The violations are a rounding error to profits! We need to make the laws more stringent.

HN when EU passes laws that have significant teeth in them and let them actually enforce them: This is ridiculous overreach! It will kill innovation and make it impossible to do business there!

Love it, never change <3

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#574

How will the regulations keep up with evolving security best practices?

It's a voluntary label, so it's open to competition from other standard-setting organizations. When it comes to mandatory regulations generally, our office thinks that broad standards that are used to hold people accountable for negligent conduct are better than detailed checkbox-compliance exercises that quickly become out-of-date red tape.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#575

How can we define a security vulnerability meeting this "serious" requirement? There are a wide variety of vulnerabilities, so it seems difficult to define this strictly.

I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually resolved by imposing a reasonableness standard. Maybe here, a vulnerability needs to be patched if it might reasonably be expected to allow an attacker to take control of a device, or to do so when combined with other known or unknown vulnerabilities. Or maybe a different standard. Then when enforcement/lawsuits come around, the judge/jury/regulator has to evaluate the reasonableness of the manufacturer's actions in light of that standard. We'd love to see commentary on the record as to what the right legal standard might be. (originally posted at https://news.ycombinator.com/item?id=37394188)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#576

Does the FCC have any authority over IOT devices? and if so how? This seems like a massive overreach, how can a body designed to for managing shared spectrum have any authority on devices that use the internet?

Good question. There's some discussion in this thread https://news.ycombinator.com/item?id=37395218

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#577

As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…

> Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs. +1 for this at the consumer level. My oven may have a critical update, but - for right now - *nothing* is more critical than finishing dinner. I'll let the update apply the day after thanksgiving when I'm doing the dishes. There are a few connected appliances brands that do this well: updates…

I think this is oversimplifying things.

Is finishing the dinner more important than applying a patch that fixes actively exploited bug that locks your oven into cleaning mode and burns everything inside into ash over the next three hours? Or something that disables the safety checks and lets the oven overheat and burn your house down?

(Granted, the latter shouldn't physically be possible because it should have physical temperature killswitches etc.)

People always (understandably so!) consider software updates to be annoyances; but especially when you give an example like _an oven_, the potential for _catastrophic_ failures is too great.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#578
Forgive my redundancy as I am surely saying what has already been said in other comments I've not yet read.

I have one cast-iron, non-negotiable relation with IoT objects:

No IoT device should ever hide what it is doing from me.

If it lives in my house, car or environment it is not acceptable for me to install something which then tries to hide its operations.

I don't care who it's made by or how much they think they are "helping me".

Whether by encrypted tunnelling, side channels, secure enclaves or whatever devious shitfuckery, if I can't put Wireshark on my network and put a name and purpose to every operation then I'll track down the origin and eliminate it.

Further, I am simply not interested in any "arguments" claiming this is "necessary". It is not. Profit, spying and control are always the ulterior motive, and they are unacceptable. Do not allow anyone to pretend they are "security" and hide behind that word. Security for whom, from whom and to what end....

Also there should be no "embedded function" which I cannot turn off with confidence, perhaps by a physical jumper or switch. No IoT device should ever reset itself to insecure defaults.

Thanks for enquiring and good luck in your difficult work.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#579

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

Do you believe that your proposal increases the cybersecurity of society as a whole? You focus a lot on the rights and conveniences of a company, but the rights of a company are not more important that the security of society as a whole. There are good guys and bad guys out there looking for vulnerabilities. What you propose reduces the number of good guys more than it reduces the number of bad guys (since bad guys a…

I proposed a preference for systemic solutions over building a soft dependence on white hat hackers.

This benefits society as a whole because it clearly delineates actions with intent. If doing X is always not allowed, then all you need to do is find people doing X and you can hold them accountable.

If you allow or disallow the same activity based on merit of intent, then you increase the level of plausible deniability to everyone who gets caught.

I am not proposing security through ignorance. I am proposing security through consent. Nowhere did I say anything about not allowing research, I only said that if you do it unsolicited then it should be considered a threat.

So, we could systemically allow for a right to research that involves notice to the company and their consent for you to test. It would not hinder white hat at all. If businesses resist for selfish reasons we can expand the law to prevent them from denying requests without a legitimate reason. For example, maybe it is okay for them to deny a request from an ex-employee with a grudge who has sent the company aggressive emails. Idk, maybe there are no valid reasons to deny. The point is we can create a framework that promotes security development above the table with all parties involved. And my proposition is that if that is possible then it should be preffered.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#580
post #561

Earlier quoted context omitted.

Why does everyone compare things to houses? If you want to be more consistent with your building analogy, IoT sold to the public or enterprises are more like bars, except that each user has their own privately owned bar that may or may not be stocked by a central liquor company. If a user wants to check it's not possible for someone to break into his bar, or slip poison into his booze shipments, or redirect the shipm…

I was speaking towards probing the business not the things you own. Using housing as a metaphor is common because it's an incredibly common thing people can relate to with personal experience, and is something people typically have relatively detailed intuitions built around what they are okay with and not okay with regarding it. It got the point I was making across, but I do think there was a misunderstanding about…

[deleted]
Post reply on HN