Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

701–710 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#701
post #84

Earlier quoted context omitted.

You as a customer can already give the manufacturer that choice, and simple refuse to buy from any manufacturer that doesn't comply.

Are there any that currently do comply?

Many large companies open their wallets to buy hardware (and software) that comes with guaranteed long term support.

If you are willing to pay, manufacturers are happy to comply with a lot of weird requests.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#702
post #71

Earlier quoted context omitted.

> There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up. If customers want it, there is a way: use contract law to commit the manufacturer. That's already the norm for enterprise grade equipment. Companies often pay more for their hardware to get guaranteed long term support. So the market is willing and able to provide this kind of service, when people vo…

Have you ever used contract law in that manner? Did you call up Apple and negotiate a contract for your new iPhone, imposing requirements on them? Give it a try and report back.

Have a look at https://www.apple.com/sg/support/professional/enterprise/

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#703

Earlier quoted context omitted.

Well, my comment is predicated on the, apparently erroneous :), assumption that no glass is brick-proof. It is impossible to build a secure software product with our current tooling & development practices. The number of security flaws in every software product is so high as to make the label meaningless. I don't think there's a meaningful distinction to end consumers between "this product has 1,000 holes, 100 of whi…

A car that's safe to crash in is also impossible to build, but the NHTSA has standardized crash tests that they built up over time that has meaningfully made cars safer.

+1 for having a bare minimum requirements for IOT sellers against some standard testing criteria. Raise the bar but

Possibly another important would be NHTSA gathers and publishes numbers on accidents. Having some regularly published numbers would certainly shine more light and is probably lowest hurdle to cross from a political standpoint.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#704
post #19

FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…

There is no security against all the threats you can possibly be imagine, but being free of well known, stupid simple vulnerabilities is still good.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#705
post #71

Earlier quoted context omitted.

> There is no way for people to know if products will still work in 2-5 years if it depends on some server staying up. If customers want it, there is a way: use contract law to commit the manufacturer. That's already the norm for enterprise grade equipment. Companies often pay more for their hardware to get guaranteed long term support. So the market is willing and able to provide this kind of service, when people vo…

Contract law actually is pretty universally used the other way around, to prevent you from updating. I have several old Android phones with locked bootloaders that I couldn't legally update even if the manufacturer hadn't locked the bootloader. I don't have access to the source code or the signing keys. I'm not sure the signing keys even exist anymore. And I can't buy a phone with the contract terms I want, they simp…

Yes, contract law only works for contracts that parties agree to.

Contract law can't force companies (nor consumers) to enter into contracts they don't want to be in. That's the whole point.

Have a look at eg https://www.apple.com/sg/support/professional/enterprise/ or the equivalent for Dell or Microsoft etc. All those companies already have programs where you can give them money in return for long term support and contractually guaranteed updates etc. I'm sure you can find similar programs for IoT suppliers.

Some people decide to pay for those programmes, many people don't. I don't see why we should force everyone into buying the equivalent of extended warranties, that they evidently don't want. This kind of stuff isn't free for companies to provide, you know.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#707

Earlier quoted context omitted.

This is a good point, some IoT devices really can't be designed to be physically serviceable, while still remaining reasonably compact, e.g. those that need very high levels of water resistance, especially saltwater resistance. And adding any remote update mechanism at all would more then likely decrease overall security. So there actually should be a counter mandate too, for devices that are impractical to design to…

It sounds like you're looking for a carve out so you don't have to upgrade your devices to have a modern microcontroller that supports remote updates and are using saltwater as a scary thing so no one challenges you on it. You can conformal coat a ESP32 with a sensor and battery and a wireless charger, and get remote updating. If hobbyists are doing that without commercial backing, what industry experts like you have…

You appear to be under a lot of mistaken assumptions.

And in any case, the default ideal is to have an option to update or reprogram devices in-person.

It's never an ideal, that I've ever seen expressed on HN, to have a remote actor capable of doing so, unless in a totally air gapped environment.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#708
post #577

Earlier quoted context omitted.

I think this is oversimplifying things. Is finishing the dinner more important than applying a patch that fixes actively exploited bug that locks your oven into cleaning mode and burns everything inside into ash over the next three hours? Or something that disables the safety checks and lets the oven overheat and burn your house down? (Granted, the latter shouldn't physically be possible because it should have physic…

One my favorite IoT botnet scenarios is an attacker taking control of thousands of ovens/air conditions/other high-wattage devices and using them to cause power outages. https://www.usenix.org/system/files/conference/usenixsecurit... I wonder how the impulse to connect everything to the internet will be remembered.

The flip side of that is you can use control of all those high wattage devices to prevent power outages by shifting load to times when more energy is available.

Hopefully, that's how the impulse will be remembered.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#709

Earlier quoted context omitted.

Hi and thanks for commenting. My concern with this topic is motivated in part by the AcidRain family of energy infrastructure attacks and the larger questions they raise about infrastructure security. Teardowns on Chinese-sourced equipment have been somewhat worrying as well -- one report I've read highlighted about two dozen versions of SSH in a single base station. Best wishes and good luck.

> the larger questions they raise about infrastructure security. Not your mission to fix a network design problem which should air gap all of those devices. USA taxpayers can't afford your agency scope creep.

I'll bite - so how do we get all those "air gapped"?

It's a leading question of course.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#710
post #157

Earlier quoted context omitted.

Well, making a voluntary sticker to opt-in to certain legal obligations is fine. But you are saying already that manufacturers don't really want to commit to anything? What makes you think the sticker would change that? (In principle, I'm all for manufacturers offering more warranties. But when it comes to spending money, privately I almost never opt for the enterprise grad hardware that does come with warranties lik…

The labeling program provides a signal to consumers that the device meets a certain standard. The incentive to the manufacturer is that it allows them to borrow the FCC's reputation and advertise a security that is well defined. The consumer can see that the device has that certification, and know that product has legal obligations, and It's a pretty reasonable first step. No manufacturer is being punished, there's n…

Sure, that's why I am saying that it's not too objectionable.

But that kind of reputation borrowing/lending already regularly happens with private entities. Both companies and foundations etc.

Post reply on HN