Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

741–750 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#741

Earlier quoted context omitted.

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

This may be beyond the FCC's purview, but given some of the comments (e.g., https://news.ycombinator.com/item?id=37393644 ) perhaps an entirely different strategy is warranted. Instead of trying to compel manufacturers, who may no longer even exist, to support their old products; perhaps the government should focus on protecting consumers and aftermarket vendors who update / modify / reverse-engineer older revisions-…

I imagine someone in the many many comments has already suggested this. But just in case:

It wound be great if all of my emails to security@somewebsite.con could be CC’d to security@fcc.gov and that would immediately convey to me, somewebsite, and the FCC (and anyone else) that I am indeed disclosing and not ransoming.

I understand there would be a cost that the FCC would bear. I just think it would be a worthwhile cost to incur.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#742
post #473

I've dealt with this multiple times, so let me give my perspective. - It is hard for manufacturers to do this with small teams. Mostly because they do not always have good CI/CD or platforms available to keep being on top of vulnerabilities and so on and so forth. - Not all manufacturers write their own software and often contract it out to other experts in the field. This includes firmware and app developers. - If a…

>> If a producer goes out of business they should be forced to

Going out of business is a loaded expression yhat covers many scenarios.

For example if my company is acquired am I 'going out of business' ?

If I go bankrupt then my assets are sold off to pay creditors. Certainly the IP is an asset and it ultimately turns up somewhere. Releasing it before sale would be illegal in some places (disposing of assets while the business is insolvent for below-market value. )

I know what we experience are abandoned PalmOS devices, but fundamentally PalmOS is owned by a legitimate company and has some nominal value.

I think mandating requirements on the owner is a better approach. They reduce the asset value, so if it doesn't sell it could be released as public domain. But that in turn gets very complicated if there are multiple code suppliers, and the downstream goes bust, but upstream is fine.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#744
I can't post on the official website (not a US citizen) but I have thought about this question a fair bit and have worked in security adjacent tech in a past life.

An important note: my suggestions would make many business models unviable. I see this as a win-win because I think that profiting on bad security is extremely unethical and should be illegal.

My requests are as follows:

1. It must be at least a 1-year jailable offence without bail to sell an IoT device that does not have the software and firmware 100% open source. This is the absolute minimum and allows end user auditing. Implementing anything else before this is meaningless.

2. The company must pledge to provide security updates for at least 5 years for any device they sell (if there is no sale, this should not apply).

3. For a security update to be valid in the eyes of the FCC, the update must be signed by an existing employee (accountability must be assigned).

4. If an IoT supplier wishes to aggregate data to sell to 3rd parties, this MUST be optional and it MUST be opt-in.

5. Vulnerability detection and registration must be handled by a 3rd party with a lodgement portal, and companies should have at most 1 month to patch it once the vulnerability has been lodged in the 3rd party portal. Failure to fix in time should accrue exponentiating fines.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#745
I don't have anything of value to contribute past the insightful comments already made by others, but seeing an FCC regulator reach out to our shoe stringed highly qualified community un YC / HN, has got to be the most encouraging thing I have seen from the US government in over a decade. Thank you for your efforts on this important topic of how we address the wide spread security concern of IoT internet connected devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#746

Earlier quoted context omitted.

Lucky guy, it sounds like you've never experienced overwhelming anxiety over having possibly left the oven on while out of the house.

That'd be a legit feature, but far less involved than a full-on smart oven. At most, it'd have a way to turn off the oven remotely (but not turn it on). Anyway, last time I had this anxiety, I checked my Ring camera in the kitchen that's posted there for reasons like this. Works for the stove and faucet too.

While I have neither, I'd much rather use a smart oven to see its status than have a constant camera feed of my kitchen.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#748
I might be late to the party but I think that the government simply should be kept out of regulating consumer electronics. Top-down control doesn't work well, and even if it did, I question the motivation. Why should my smart fridge be regulated essentially by the same body that has the ultimate right to excercise violence pro-actively? It makes no sense

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#749

Earlier quoted context omitted.

I'll bite - so how do we get all those "air gapped"? It's a leading question of course.

The example was "energy infrastructure", so network group in those firms use their skills to set it up. If any government group should be providing guidance and best practices on how to air gap devices, maybe NSA should write the standards. This FCC proposal looks like a ploy to spend the ever-growing pot (reportedly ten billion USD each year) from the regressive USF phone bill tax instead of reducing the USF tax. As…

I'm talking way out of my pay grade here.

> If any government group should be providing guidance and best practices on how to air gap devices, maybe NSA should write the standards.

I guess this is a bad joke? It's hard to tell w/ the internet.

> This FCC proposal looks like a ploy to spend the ever-growing pot (reportedly ten billion USD each year) from the regressive USF phone bill tax instead of reducing the USF tax.

I can agree this is what it is under the hood [0].

> As mentioned in another comment, a plug-and-play home device which provides network isolation and filtering for IoT devices may have a market. I would likely be a buyer at home.

Here's the key - there isn't a market. Otherwise there would already be one (you are unique). That's the crux of the problem. IoT is a race to the bottom when it comes to consumers. Consumers compare "smart devices" to what they already have - a light switch, a light bulb - commodities - they don't think about security until it's too late.

So, that leads to:

> If any government group should be providing guidance and best practices on how to air gap devices

You can't have "guidance" and actually get anything done in the consumer devices space. Standards and certifications - rejection of devices that don't meet them.

When it comes to dealing with communications FCC is the 3-letter-agency, and there's no changing that.

I guess the question boils down to - mass spying on Americans with un-secured devices sending data to China or let the FCC handle the problem by potentially expanding the USF?

[0] https://docs.fcc.gov/public/attachments/FCC-23-65A1.pdf page 45

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#750
post #746

Earlier quoted context omitted.

That'd be a legit feature, but far less involved than a full-on smart oven. At most, it'd have a way to turn off the oven remotely (but not turn it on). Anyway, last time I had this anxiety, I checked my Ring camera in the kitchen that's posted there for reasons like this. Works for the stove and faucet too.

While I have neither, I'd much rather use a smart oven to see its status than have a constant camera feed of my kitchen.

It only records on demand, mainly cause it's on battery. Also doesn't control anything in the house.
Post reply on HN