Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

581–590 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#581

Earlier quoted context omitted.

Since your skepticism of regulation seems broad, it seems unfair to cabin examples to just the FCC. Why not look at the food quality changes between 1905 and today? Those have largely been won on the back of serious regulation through the FDA (and it's predecessor), as well as labeling requirements. Both of those regulations have had significant improvements in the lives of consumers. Honestly, I have a very hard tim…

Hmm I don't know the food quality area super well but I am sure it's hard to confirm improvements were caused by regulations and not technology, right? The idea of transparency is interesting to me. I used to agree with you that more is better but I no longer feel that way. Prop 65 in California is one example where there are stickers saying 'this might give you cancer' basically everywhere and we all ignore them so…

> but I am sure it's hard to confirm improvements were caused by regulations and not technology, right?

For a good summary of the history of food safety I'd recommend: https://www.ncbi.nlm.nih.gov/books/NBK221553/

Often the regulation _drives_ the technology. There is no inherent business need to create new technologies that improve the food safety, outside of demand from consumers or regulators.

> In 1909 the American Public Health Association appointed a committee to develop a “standard” bacteriological technique for screening oysters and other shellfish, which recommended use of a tube dilution method for the presence of Escherichia coli. In an effort to gain data on levels of contamination, USDA's Bureau of Chemistry conducted an extensive bacteriological study along the Atlantic and Gulf coasts between 1908 and 1910.

Again, though, consumers can only register there preferences with the existing market. So if they want _safer_ foods than are available on the market, there is no real way for them to register that desire.

> In the absence of government standards, companies willing to spend funds to assure protection of the public health are disadvantaged by the need to compete with companies unwilling to do so, because the latter could sell their products at a lower price. Some consumers might be willing to spend more on a “better” or “safer” product; poorer consumers, of course, would be unable to do so and would bear greater food safety risks than more affluent consumers. Price differentials for safer products would not be possible in many parts of the food marketplace, however, as most foodstuffs are sold as unbranded commodities at the beginning of the food chain, and often (as with most meat, poultry, and produce) at the retail level. Thus, even if society were willing to rely upon the market to encourage food safety, it is unlikely to be an effective producer of safety because of the commodity nature of most food transactions, as well as the difficulty of connecting foodborne illness with particular eating occasions or individual foods. For the same reasons, personal injury litigation provides only a weak incentive for food companies to improve their food safety efforts, because there is a low probability that they will be sued for foodborne illness, the damages they would pay are likely to be small, and there is a low probability that such litigation would have negative public relations consequences (Buzby and Frenzen, 1999).

> Imo existing laws regarding misleading marketing and accuracy are probably all that we need

Many of the food safety laws that exist are exactly to prevent this exact kind of misleading marketing and accuracy. Or, in other cases, to force them to make specific claims that can be later enforced rather than generic claims that can never be enforced.

In my mind, an analog to "put on the box how long security updates will be provided" are "nutrition facts", in that these don't just say: "everything on the box must be true", but also: "you must disclose some specific things about the product".

The introduction of nutrition labeling changed both consumer behavior, and the products being offered to consumers: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6340779/

> In pooled analyses (Table 2), food labeling reduced intakes of energy by 6.6% (95% CI= −8.8%, −4.4%. n=31 estimates; Appendix Figures 1 and 2), total fat by 10.6% (95% CI= −17.7%, −3.5%, n=13; Appendix Figures 3 and 4), and other unhealthy options by 13.0% (95% CI= −25.7%, −0.2%, n=16). Food labeling increased vegetable consumption by 13.5% (95% CI=2.4%, 24.6%, n=5; Appendix Figures 13 and 14).

> ...

> Reformulation outcomes were evaluated by six studies (Appendix Table 13, Appendix Figures 20–24). Food labeling significantly reduced the contents of trans fat (−64.3%, 95% CI= −91.1%, −37.5%, n=3) and sodium (−8.9%, 95% CI= −17.3%, −0.6%, n=4). Significant effects were not identified on product contents of total energy, saturated fat, dietary fiber, or other healthy (protein and unsaturated fat) or unhealthy (total fat, sugar, and dietary cholesterol) dietary components.

Bringing it back to this topic that would mean forcing them to make a statement like: "we will provide security updates for 3 months" in small print somewhere on the packaging, rather than _only_ having the phrase "WORLD-BEATING SECURITY" in 45pt font on the front. And, again, all of this is voluntary, and only required if they want to display a specific logo.

I honestly can't see _any_ argument for how this would be objectionable. I don't think existing laws are sufficient, because they don't require a company to make any specific claims. As such, no companies make any specific claims about security, which means as a consumer I have *no* ability to express a preference in the market for products that make stronger claims about security.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#582

Earlier quoted context omitted.

> Later, consumers can _attempt_ to hold manufacturer's feet to the fire with false advertising and other fraud class action lawsuits. I would hope that this becomes relatively simple at some point. 1. I have this box that says I get updates until 2025-01-01. 2. It is 2023-09-05. 3. I have applied all available security updates. 4. Vulnerability X is still exploitable and has been made public to the manufacturer for…

I think if the box says updates until the beginning of 2025, and they've stopped providing updates before then, you have a pretty good contract lawsuit against them. You'd have to show that their failure to issue a patch for four months constitutes a breach, but that is exactly the kind of thing that gets hashed out in lawsuits. You could even have a class action of all the owners suing the manufacturer. We think one…

Yep, the labeling would enable exactly the kind of class-action false advertising/fraud lawsuits against companies that simply lie on the packaging.

So companies would be forced to disclose their actual level of support, and risk consumers not wanting the product, lie on their disclosure and risk a significant class-action lawsuit, or improve their level of support.

I would hope the market would tip us towards the latter scenario, but...we won't know unless we actually force disclosure of these things.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#583

As a developer and a consumer, what I'd really like to see is: - Manufacturer voluntary guarantee of 1/3/5 years security updates with an expiration date. - Separation of functionality and security updates. - The ability to "turn off" connectivity and retain full local functionality. - An industry security certification like UL. - A single point way of identifying and validating devices. As it is, I avoid using IoT m…

> Manufacturer voluntary guarantee of 1/3/5 years security updates with an expiration date.

I just have to point out that these are all extraordinarily short numbers. There are industrial control systems that are still in operation despite being made out of mechanical relays from before the advent of microprocessors.

We got used to electronics getting replaced every 3-5 years because if it's a laptop by then it will be considered slow and have a questionable battery. But these devices are now being permanently affixed to real estate.

We need a way to update these devices that will outlive the manufacturers. Because many of the devices will.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#584
** THE REAL PROBLEM **

Is companies making shit that has not business connecting to the internet. _THAT_ needs to be regulated. Why does your car need an internet connection? Why does your fridge need an internet connection? What does your robovac need an internet connection? ALL of these items could work just fine with zero internet connect, or a simple LAN connection.

If we could regulate that, we'd solve 95% of the problem and the IOT Update problem goes away. Ounce of prevention worth a Terabit-Scale DDOS of cure.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#585
Thanks for advocating for these issues. They are important.

I'm the CTO of a small software studio who has worked almost exclusively in the IoT space for the last 8 years. We've worked on large, Fortune 500 companies, all the way down to startups. Half our projects have been for consumer IoT, the other half for B2B projects.

There are two core financial realities that regulators need to understand:

1. From a purely financial perspective, most manufacturers do not have financial models that make perpetual, ongoing updates possible. Without a recurring revenue stream tied directly to a device, any software update reduces the return on investment for a product. For example, say you make a consumer IoT device and sell it without a subscription. The BOM might be $50 and the NRE is $50. You might sell it for $200, and make $100 profit. However, without a revenue stream of some sort, that profit needs to somehow support all the software updates those devices will receive in the future. Say each update costs $5 to build and deploy, and you release once a year. After 4 years you've spent $20 in updates, likely more due to inflation. At some point this becomes a losing proposition. The fact that GAAP says non-recurring engineering can be capitalized, but the maintenance cannot, creates even more issues. And due to the maturity of security, it's difficult, if not possible, to guess upfront how many updates a device might require.

This problem is compounded by the poor software practices at most manufacturers. It is non trivial to set up a software practice that keeps the cost of ongoing development in check. More model numbers and large fleets increase the development and QA costs. The per unit costs go down, but the absolute dollars go up.

2. The second issue is that IoT devices have a symbiotic relationship with other systems, and the financials for the overall product are tightly coupled. For example, consider cold chain monitoring systems. These devices are simple: measure the temperature, and send the data to a cloud-based pipeline. Alerts are forwarded to another. The value is in the outcome: alerting users to problems. However, to be competitive, the manufacturer might sell the hardware at a loss. If the _system_ is unprofitable, the vendor might turn off the system. In this case, it's hard to demand that the vendor provide updates for a defunct system. In the worst case, companies will go out of business and all the regulation in the world won't really help the consumer. Or the large companies will simply set up shell corporations to shield themselves.

Some in this thread suggested that all the software be open sourced. This is a fool's errand, IMHO. Forcing manufacturers to do this isn't viable because they often don't own the entire software stack: they have suppliers who own the IP, who in turn have their own suppliers. And it's really hard to draw the line in embedded systems. The BSP, RTOS/kernel and applications are all tightly coupled.

"But I bought the software!" you say. Yes, you did. You bought a binary snapshot in time of a software system. Unless you're paying for perpetual updates, you didn't buy unlimited free updates into perpetuity. And you definitely didn't buy source code.

So, what's the solution? I don't have any silver bullets, but here are some thoughts:

1. For many devices, allowing the user to replace the microcontroller outright is the ultimate consumer safeguard, while protecting IP. If the vendor doesn't provide updates, or goes out of business, the owner can replace the MCU or SOC. And it protects the IP of the manufacturer's supply chain. This requires a clean separation of concerns, and it also would allow competitors into the market. But this is the best actual safeguard to consumer protections and respecting IP. There are a lot of ramifications to this. The user instantly voids the warranty, and would need to take responsibility for the security and safety of the system. But for a lot of use cases, this is fine.

2. Incentivizing a secondary market to encourage third-parties to take over failed systems. For example, if a vendor winds down a failed IoT project, give them a tax break to sell the system to a third-party, or open source it. This would give vendors a lot more reasons to try and own/license all the IP to make it open source-able. There _are_ knock on effects: the third-party might charge for updates, or raise prices.

3. Incentivizing common hardware/software platforms. Here's the reality: most manufacturers don't really want to write their own software. They want to sell hardware: it's what they're good at. Encourage more generalized software architectures for IoT devices. This will reduce the costs and enable parts of the system to be updated, without requiring access to the entire system.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#586
post #577

Earlier quoted context omitted.

> Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs. +1 for this at the consumer level. My oven may have a critical update, but - for right now - *nothing* is more critical than finishing dinner. I'll let the update apply the day after thanksgiving when I'm doing the dishes. There are a few connected appliances brands that do this well: updates…

I think this is oversimplifying things. Is finishing the dinner more important than applying a patch that fixes actively exploited bug that locks your oven into cleaning mode and burns everything inside into ash over the next three hours? Or something that disables the safety checks and lets the oven overheat and burn your house down? (Granted, the latter shouldn't physically be possible because it should have physic…

One my favorite IoT botnet scenarios is an attacker taking control of thousands of ovens/air conditions/other high-wattage devices and using them to cause power outages. https://www.usenix.org/system/files/conference/usenixsecurit...

I wonder how the impulse to connect everything to the internet will be remembered.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#587
post #573

Earlier quoted context omitted.

The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.

HN when governments agencies have little leverage to enforce rules: The violations are a rounding error to profits! We need to make the laws more stringent. HN when EU passes laws that have significant teeth in them and let them actually enforce them: This is ridiculous overreach! It will kill innovation and make it impossible to do business there! Love it, never change <3

Almost like it's different people :)

The bigger issue is that simplistic takes expressed strongly with no room for disagreement tend to get the most upvotes from other people. The people who agree will upvote, the people who disagree will just move on, and the people who don't have an opinion will think the person sounds like they know what they're talking about and will upvote anyway. That's how you end up with back to back threads where completely opposite takes are highly upvoted, and both of them happen to be awful takes.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#588
post #218
post #100

Earlier quoted context omitted.

There was no requirement that firmware be locked down. The requirement was that consumer radio transmitters could be too easily made to use frequencies and power levels that violate FCC regulations. If a device had a transmitter where firmware could control those things, and the firmware for the device was one blob that contained everything so letting the user replace firmware meant letting the user control those res…

Isn't that a bit overreaching? I can make you a device the spews garbage on any wavelength you fancy, so they're really only preventing accidental radio pollution. Even in that case it's pretty unusual to prevent a consumer device (other than a radio) from being used in an unlawful way, Part 15 notwithstanding.

People were asking online for help dealing with WiFi interference, and were getting answers telling them how to install open source firmware on their WiFi routers, and giving them exact commands and configuration changes that would set the power higher than was legally allowed or stop them from avoiding channels that were being used by active weather radar (5 GHz WiFi shares channels with weather radar and is supposed to monitor and only use those channels when the radar is not in use).

I suppose you could call that accidental radio pollution, because most of the people doing it probably didn't realize that they were causing interference, but regardless it was becoming a problem.

Hence regulations to address it.

That's the world we're in now. You have a problem, you do a search online for help, and among the answers you often will find some that really should only be used by people with more experience or expertise than you but do not make that clear.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#589
post #534

Earlier quoted context omitted.

I just don't agree with this at all. I specifically avoid all smart plugs that don't have a UL mark (or European equivalent mark). It's impossible to say that consumers don't care about a specific certification before it exists based on their existing behavior. Consumers _do not have any ability_ to distinguish on this axis at the moment. So, we can't say: "based on their behavior they don't care". They very well mig…

FWIW, I want to claim that I personally care deeply about a lot of this stuff; but, if I go to Home Depot and buy a piece of dumb equipment (such as a run of the mill light bulb or an outlet), it never occurred to me that I might have to check that there is a UL mark on it... I somehow assumed that Home Depot wasn't allowed to sell something that wasn't certified for at least basic electricity safety in the US.

I haven't checked everything at Home Depot, but many reputable retailers won't sell things in their store unless they have such a mark.

It's "online marketplaces" like Amazon (or AliExpress) where you're actually purchasing from a random third party seller, and the marketplaces attempts to disclaim as much liability as possible that I'm more wary.

I actually don't know the specific laws or regulations on this. It's very possible that it's illegal for Home Depot to sell a non-UL or other nationally recognized laboratory mark. It's probably that it's illegal for third-party sellers on other sites to do it as well, but my faith in Amazon and other "online marketplaces" for policing their third party sellers on this kind of stuff is...not high.

I'm just trying to be a lot more careful about the stuff that goes into real circuitry, because I'm more used to playing with low-voltage DC stuff where I'm just not too fussed about it, so I feel OK ordering anything cheap that probably works.

---

Finally, I think it's actually a regulatory and consumer information _success_ that you feel safe buying something from Home Depot and wiring/plugging it into your house without thinking about the product safety risks. The reason for that is _those risks have largely been eliminated_. There was a time when you _did_ have to be super careful as a consumer of electrical products. Over the years, we've drastically improved the safety of these kinds of products to the point where we for the most part don't have to think about it anymore, because it's not a problem anymore. That's effective government regulation at work.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#590
post #529

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

there needs to be consent from the company being probed for vulnerabilities What is the type of scenario that you have in mind here? Do you mean probing a web service for vulnerabilities, performing security assessments as part of pre-sale publications (think Consumer Reports, Anandtech reviews etc), or performing pen-testing on a device I bought and is now running on my home network? Because you appear to be arguing…

I was speaking towards internet side of things where you do not own the infrastructure.

As a related note, I do firmly believe in right to repair, and if you own something you can do whatever you want with it.

Partial ownership seems to be a thing now. So I think there is a lot of missing framework around managing that properly.

Long story short - I think there is room for manufacturer consent / acknowledgement / notice to be part of the solution and if it can be part of the solution then it should be. We may need regulation around that, it likely cannot be left solely to the companies discretion and may even need an aggressive "receipt but no reply by X days is considered consent" clause - but I would like to promote solutions that come with communication between the effected parties

Post reply on HN