Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

591–600 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#592

Thanks for advocating for these issues. They are important. I'm the CTO of a small software studio who has worked almost exclusively in the IoT space for the last 8 years. We've worked on large, Fortune 500 companies, all the way down to startups. Half our projects have been for consumer IoT, the other half for B2B projects. There are two core financial realities that regulators need to understand: 1. From a purely f…

Thank you for this detailed feedback. In the long-run, it's worth asking whether a business that doesn't make money once externalities have been internalized is a business worth having. But this is a voluntary program, and we're just hoping to spur growth of a segment of the device market where these issues are properly accounted for. Hopefully as more and more purchasers begin insisting on higher-standards, maybe by insisting on this label being present, economies of scale and componentization of secure IoT platforms will drive the costs of good IoT security down to the point where your concerns aren't as salient. Please consider sharing your thoughts through official comments.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#593

Earlier quoted context omitted.

> These regulations put us on the path of trusting religious-like in government. We don't need to have religious-like faith in government because we can vote for people who will do what we want them to and we can vote out the people who refuse to do their job. It doesn't happen without the people getting involved and holding their government accountable though. You don't have to pray when you can vote. Without regula…

How well did that work for bank oversight in 2008, and again in 2023 with SVB? The accountability of "my one vote will remove government's failed regulators" fails on the scale of $billions.

Is there an argument that the government failed in oversight with SVB?

I think this is a textbook slam-dunk by the government? They stepped in when the situation was _bad_, but not _catastrophic_ yet (mmmmaybe arguable), took over, and no depositors got hurt.

Is there an argument that this could've gone better, apart from "no banks ever fail"?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#594
post #312

Earlier quoted context omitted.

> I would love it if the lawmakers considered this scenario. You're building on quicksand, and you're asking for us to give you leeway when the building collapses. Either do the work of making all of those security fixes yourself, or pick a better platform to build on top of.

> pick a better platform Unfortunately there isn't all that much competition in this space. The choice was try building on quicksand, or let the idea die. I'm glad we tried it.

Until there are consequences for building on quicksand, the vendors have no reason to improve their offerings.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#595
post #319
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…

[deleted]

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#596

As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…

Good comments.

> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices.

This sounds like it is intended for consumer products, and it also sounds optional. I would hope that users with a legitimate reason to do so (defense, enterprise) would have the capacity to not participate and forego the label.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#598
post #547
post #473

I've dealt with this multiple times, so let me give my perspective. - It is hard for manufacturers to do this with small teams. Mostly because they do not always have good CI/CD or platforms available to keep being on top of vulnerabilities and so on and so forth. - Not all manufacturers write their own software and often contract it out to other experts in the field. This includes firmware and app developers. - If a…

> It is hard for manufacturers to do this with small teams. Mostly because they do not always have good CI/CD or platforms available to keep being on top of vulnerabilities and so on and so forth. "It is hard for hospitals to keep their ORs clean with small teams. Mostly because they do not always have good cleaning products or procedures available to keep being on top of contaminations and so forth". I do not believ…

Liability chain in many industries is a fantastic way to build a large legal moat to prevent competition from small players.

The goal of any regulatory agency must be to ensure as much safety as can be done while preserving the ability of small players to enter the field and compete & while keeping the costs low for consumers. Otherwise, safety becomes a rationale that larger corporations are excellent at spinning to justify more regulatory moats.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#599
post #568

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

This is what is referred to as "security through obscurity." If companies are going to publish/sell closed source software to the general public, and make any claims regarding it's security, that should provide more than enough consent to probe it.

I think the difference is in what's yours and what's theirs. If it's yours, I agree. If it's theirs, I disagree.

The idea of absolute ownership is being eroded. You purchase a device but that device may use information you do not own. If you are manipulating the device to allow it to give you information you did not purchase and the contract you agreed to with the purchase was that you would not do this, then that is threatening. If what you learn by probing it allows you to breach the security of other people using the same service, then that is threatening.

If you are concerned about the device, I don't understand why we can't live in a world where you are able to vocalize that and give the device provider a chance for feedback before probing it for weaknesses.

If there is a security concern that you want to shine a light on, why is it that we need to address that concern in the dark? It is giving too much unnecessary overlap with people looking to exploit those security issues when we might not need to

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#600
post #475

I think the most valuable security feature for IoT devices is being able to work without contact with a central service. If the value of a device is tied to opening a connection to and occasionally retrieving code from a third party it is inherently insecure . All I have to do is buy the company that owns the central server (or compromise it in some other less visible way) and I now have the ability to introduce mali…

> "All I have to do is buy the company that owns the central server (or compromise it in some other less visible way) and I now have the ability to introduce malicious code to all devices that are receiving 'security updates.' You won't be able to make a rule to prevent asset transfer (correct me if I'm wrong) so you won't be able to close this hole." Has this actually been a problem in the past? I do not know of any…

There are malicious actors in the business of buying popular App Store apps and introducing malware into updates.
Post reply on HN