Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

641–650 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#641
post #577

Earlier quoted context omitted.

> Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs. +1 for this at the consumer level. My oven may have a critical update, but - for right now - *nothing* is more critical than finishing dinner. I'll let the update apply the day after thanksgiving when I'm doing the dishes. There are a few connected appliances brands that do this well: updates…

I think this is oversimplifying things. Is finishing the dinner more important than applying a patch that fixes actively exploited bug that locks your oven into cleaning mode and burns everything inside into ash over the next three hours? Or something that disables the safety checks and lets the oven overheat and burn your house down? (Granted, the latter shouldn't physically be possible because it should have physic…

These seem like very rare scenarios. If we're concerned about dire threats like this, the manufacturer needs a way to remotely send devices into an internet-disconnected "safe mode" before anyone's even talking about updates.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#642

Earlier quoted context omitted.

I think if the box says updates until the beginning of 2025, and they've stopped providing updates before then, you have a pretty good contract lawsuit against them. You'd have to show that their failure to issue a patch for four months constitutes a breach, but that is exactly the kind of thing that gets hashed out in lawsuits. You could even have a class action of all the owners suing the manufacturer. We think one…

Yep, the labeling would enable exactly the kind of class-action false advertising/fraud lawsuits against companies that simply lie on the packaging. So companies would be forced to disclose their actual level of support, and risk consumers not wanting the product, lie on their disclosure and risk a significant class-action lawsuit, or improve their level of support. I would hope the market would tip us towards the la…

I figure like everything else, this will just advantage the fly-by-night imports who you can't sue in the first place. They will continue to have no incentive to comply with any laws whatsoever.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#643

Earlier quoted context omitted.

Seriously. I'm a SWE and I would throw out a TV and get a new one before spending hours minimum figuring out how to switch the firmware to a open source version.

Because right now we have to actually perform some exploit to run custom firmware most of the time. What if there were just a toggle in the settings menu for which repo to look at?

Probably not, honestly. I get paid to do things like manage dependencies, and I'm not trying to do it at home. If this was one and done, just click a button and forget about it again, then maybe, but if I have to do things like think about what model number I have, and is it compatible with this version of the firmware, then no way.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#644

Earlier quoted context omitted.

Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn. Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen. This is literally a national security issue. We currently stifle security research on essential IoT device…

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

Part of systemic improvement to security comes from the market forces that reward producers putting out carefully designed and tested products and punish producers that don't. Your suggestion of requiring prior notice, coordination, approval etc. incentivises them to defer the cost of proper development until there is a crisis, so they can rush out any rubbish product, and force users and researchers to do their security testing for them. Let them fear the unknown, with their necks on the line, and design accordingly.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#645

Earlier quoted context omitted.

> Remote update mechanisms can themselves present security problems in some domains. I've proposed many times that the device have a physical write-enable switch on it, not a software switch. That way, a malware infestation won't survive a reboot, and your backup hard drives won't get compromised. I'm amazed that nobody does this. (Hard drives used to have a write-enable switch on them.)

Many flash chips have write enable pins at the hardware level. So this support really does still exist in theory! However, these pins mostly aren't used for any kind of switch in basically every PCB design I've seen. Either it's "always enabled" so the storage can always be written, or it's a chip that's programmed from the factory and always disabled to prevent any kind of user update.

I'd sure hate to have my system ransomware compromised, and when I try to restore from a backup drive, the ransomware encrypts it, too, as soon as I plug it in.

I also have, on occasion, flipped the from and to parts of the command to restore from a backup. I'd really like to have a hardware switch to make the drive read-only.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#646

Earlier quoted context omitted.

Also, security researchers should have strong legal protections; they should be given the benefit of the doubt at every turn. Currently, researchers are sometimes threatened with decades in prison for testing the security of websites or devices. If they act in good faith as researchers, this should never happen. This is literally a national security issue. We currently stifle security research on essential IoT device…

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

> there needs to be consent from the company being probed for vulnerabilities

So they never give consent and no vulnerabilities are ever discovered?

If I make and sell bread, there could be a surprise food safety inspection in the middle of the night on Christmas Eve, but don't we dare inconvenience some software firm that holds intimate data on millions of people.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#647

Earlier quoted context omitted.

> stuck on a derivative of Ubuntu 18.04 [...] as our project was being developed in Python, we were stuck on 3.6 I might be missing something but why do you need to rely on the OS provided Python version? Newer versions that 3.6 should run on older Ubuntu versions. You could have installed newer versions using the deadsnake PPA for example onto 18.04 up until earlier this year (since LTS only has a 5 year support win…

If we had the resources to disentangle the entire Python situation, trust me we would. Unfortunately the web of dependencies for that project was quite intricate, and at one point you just need to swallow the vendor's proprietary libraries that they've built against what they've shipped in the base OS. (L)GPL is good on paper, but the effort to actually make use of the freedom it grants is disproportionate. (Which is…

GPL is burdensome for businesses to comply with, so I would support public funding for drop in replacements for common GPL tools and libraries

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#648

It is extremely disheartening to see one of our many bureaucrats come to an anoymous international forum for input on an American domestic policy issue. A domestic policy issue that should be exclusively taken care of by the elected legislature rather than an unelected bureaucracy. I hope that all of the comments in this thread are fully discarded by all who hold actual power at the FCC; the opinions of the internati…

That's silly. If you see good advice you take it. Doesn't matter where it came from.

That is, unless you're too clueless to tell the difference between good and bad advice. Then you find someone to trust.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#649

This boils down the Right to Repair and Maintain. I always advise my friends and relatives to NOT buy smart appliances. The doom scenario is buying a $20k furnace that becomes useless. Imagine a scenario where you need an app (that's never updated) to adjust your house temperature. Or requiring people run insecure wireless protocols to control it. Appliances like this need to operate over an open control protocol, wh…

I think any device that is end of life should have its firmware be open source, with fines for non compliance.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#650
post #568

Earlier quoted context omitted.

This is what is referred to as "security through obscurity." If companies are going to publish/sell closed source software to the general public, and make any claims regarding it's security, that should provide more than enough consent to probe it.

I think the difference is in what's yours and what's theirs. If it's yours, I agree. If it's theirs, I disagree. The idea of absolute ownership is being eroded. You purchase a device but that device may use information you do not own. If you are manipulating the device to allow it to give you information you did not purchase and the contract you agreed to with the purchase was that you would not do this, then that is…

> If what you learn by probing it allows you to breach the security of other people using the same service, then that is threatening

What is threatening is that the company that sells baby monitors and keeps video recordings of your family members being naked has zero accountability for their security and almost no chance of being caught if they misuse it.

Post reply on HN