Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

761–770 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#761
There don't need to be complicated rules.

1. Manufacturers must maintain a VDP. 90 day common fix committment; 180 days for medical devices and certain other "loss of life" critical equipment that may be quite more difficult to update than your standard IoT device; 30 days for security equipment, incl cameras that have a physical security application.

2. GDPR level of fines, liability extending to directors. Window of liability is a "security warranty" lifetime of the product, minimum 1 year.

eg Jeep has a vulnerability that allows remote control of the vehicle. As we score this CVSS 10.0, they must fix and deliver a fix to all users within 90 days. We don't consider this a medical device, even though a vehicle malfunction certainly can lead to loss of life. Failure to have a fix available in 90 days results in 0.5% revenue fine per month after 90 days.

eg Vulnerabilities are found and announced in St Jude Medical pacemakers in August. St Jude Medical sues the disclosers and refutes the claims. In October they release an update to fix some of the vulns. In Aug of the following year they fix the remaining vulns. Because the remaining vulns are CVSS medium, a fine of 0.25% per month is levied against Abbot, the new owner of St Jude Medical, for the 6 months beyond the 180 day window that the medium vulns were not repaired. No additional penalty is levied for suing the disclosers because the vulns were not responsibly disclosed. If instead, Abott never bought St Jude Medical and St Jude Medical had to declare bankruptcy, the fines are transferred to the directors.

eg TrackingPoint smart rifles are found to have a vuln where the hacker can change the aim of the rifle. TrackingPoint goes out of business before the 90 day window is up, for unrelated reasons. The company has no assets so liability goes to the directors. However, in this case there is no liability since the repair is easy: disable wifi. The wifi function is not essential to the operation of the device so this is deemed an adequate repair, even had the company survived.

eg Vulnerabilities are found in TRENDnet cameras, commonly used for security/surveillance application. The window on this is 30 days. 27 days later, TRENDnet announces an upcoming fix and 3 days later releases an update fixing the vulnerability. Liability is zero.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#762

Earlier quoted context omitted.

> Manufacturer voluntary guarantee of 1/3/5 years security updates with an expiration date. I just have to point out that these are all extraordinarily short numbers. There are industrial control systems that are still in operation despite being made out of mechanical relays from before the advent of microprocessors. We got used to electronics getting replaced every 3-5 years because if it's a laptop by then it will…

> these devices are now being permanently affixed to real estate I predict the NEC will start demanding the use of Wago style splices, no more wire nuts, due to how frequently people are swapping out smart switches and the like. Even non-smart dimmers have been changed multiple times in my residence due to evolving LED compatibility (another "wild west" situation right now). I haven't broken any copper, but the incre…

That's for the people who actually change them out.

Then you're going to have the guy who loves Smart Thingies, fills his house with them, and sells it to someone content to use the Smart Switch as a switch and the Smart Stove as a stove even if they're >10 years old and none of the smart apps are supported anymore.

But they're all still sitting there soliciting incoming connections.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#763
post #568

Earlier quoted context omitted.

This is what is referred to as "security through obscurity." If companies are going to publish/sell closed source software to the general public, and make any claims regarding it's security, that should provide more than enough consent to probe it.

I think the difference is in what's yours and what's theirs. If it's yours, I agree. If it's theirs, I disagree. The idea of absolute ownership is being eroded. You purchase a device but that device may use information you do not own. If you are manipulating the device to allow it to give you information you did not purchase and the contract you agreed to with the purchase was that you would not do this, then that is…

A device that is installed in my home but which I do not own is an increased liability on me.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#764
post #675

Earlier quoted context omitted.

If the attacker has total control, then all bets are off no matter what mechanisms you put in first. Adding a safe mode would at least allow manufacturer to stop any non-total exploit without relying on the more complicated update mechanism. Also, the appliance would more likely work in a kinda normal way in the meantime.

>If the attacker has total control, then all bets are off no matter what mechanisms you put in first. Great, so we now agree that it's important to keep the system patched and up to date.

Just as smart people agree that the manufacturer knows nothing about the situation at the appliance, and a forced update mechanism a la the first iteration of Windows forced updated ("update's here, restarting, too bad you're currently doing important stuff that won't be saved") is a stupid idea and outside of private use often a non-starter. That kind of condescension is generally only something you can do to private tech users.

Though I guess making the experience frustrating could keep more people from needlessly connecting everything to the network because it sound futuristic...

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#765

Earlier quoted context omitted.

I'm wondering why you'd have a smart oven in the first place. Seems like all risk and no reward.

Lucky guy, it sounds like you've never experienced overwhelming anxiety over having possibly left the oven on while out of the house.

A simple timer that switches off after a couple of hours would do. The timer could reset every time the oven door is opened. This should solve most issues. Long cooking could have a bypass button or somethong (if the door open reset is not enough).

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#766
There is no possible regulation of iOT software upgrades/downgrades/sideloads or installs from the US Government, the FCC, or any other regulatory agency of any other country on the planet we call "Earth".

No hardware or software product can be regulated "to function properly" or "for any period of time" beyond the moment of its sale, and receipt of orderly condition by its consumer regardless of the expectation of perpetuity by a consumer of its potential for hardiness over a period of time due to its "solid state circruitry" or backing by "standards bodies", or large well capitalized companies which to this day deliver expensive products to consumers in the guise of "new-ness", which will not function by-design in a few short years.

This FCC proposed regulation is not just folly, ignores the state of the software/hardware market going back several decades, ignores standard tech industry business practices, consumer reality going back decades and tries to create a "phony", invented hardware/software "category", called "IOT" which is just a marketing term invented by the tech industry to sell into established embedded, industrial, commercial, and domestic markets things which are more or less obvious and some which are less obvious. But iOT is a full stop marketing term that means literally nothing except there's some semblance of a computer running some semblance of software in SOMETHING.

As such, being a product of marketing and enticing people to embed, extend or purchase as part of a larger system "half baked" electronics running "half baked" software that may or may not work tomorrow is simply not novel, special or imperative to any possible regulatory regime unless that regime has the completely innoble, unnenforceable, and mundane title of "Buyer Beware".

It is in this sense in which I must call out the abject and unforgivable immaturity of the FCC for having the immaturity to neither understand the markets as they have existed for decades, the market forces that drive the current behavior and the lack of specialness of the recipient of ANY product, that is a civilian or government consumer who purchases on a lark some product of any category and has a foregone expectation which can never be satisfied to the fullest due to naivte, and the lack of proper inspection prior to purchase.

But rather than try to convince this esteemed committee, I will reject this proposal from the FCC based on the following OBVIOUS prior art in the age of planned obsolescence.

1) There is no discrete, nor regulatable device category that exists under the name iOT - iOT is a marketing term. 2) If there WERE such a category of devices there would be no way to exclude mobile devices such as cell phones or desktop computers from it. 3) Computers running software whether embedded or not cannot be regulated for content, durability or express suitability for a purpose outside of an EXPLICIT contract between seller and purchaser. Regulatory bodies are not capable of establishing such a contract between the tech industry and any consumer. 4) The biggest collection of iOT devices ever produced by the US government, is no longer reproducible, the circuitry and software in the orbiters and landers in the moon missions. The US government cannot possibly hold industry to a higher standard than it itself can produce. 5) Noone on the committee seems to have even the slightest knowledge that every modern cellphone is designed to NOT run software after a decaying series of updates intentionally renders it obsolete. This includes garage door openers, battery chargers for transportation devices, heart monitors, mp3 players, note takers calendars, email apps, messaging apps, home automations clients and any other app that has been made or can be made to run on a cell phone. Not a single piece of software on a modern iphone, runs on the first iPhone. 6) The products and services of a company that may or may or may not exist tomorrow has never been nor will ever be made reproducible due to a government mandate. I will support this proposal when I can buy a new 1967 Corvette. 7) In essence the treating of a phony marketing category of computer is just more govt overreach of trying to regulate the software and hardware components of products which are no different than any other products on the market that break, cease to be sold and often failt o live up to marketable expectations. No govt can put the burdens of regualtion sought in this proposal on any company regardless of product. Its illegal, and Unconstitutional, unworkable, and flies in the face of common sense.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#768

Thanks for reaching out to the community. Instead of mandatory updates, there are lower hanging fruits you can win, and will have just as much, if not more positive security impact. 1. No default password, one must be set at initial configuration 2. Devices must function without public internet connection (unless it is one of the device's primary function to transmit out) 3. Devices must function without centralized…

1. - routers have mainly solved this by having a unique, random password which is provided on a sticker on the device.

Other than that, these are really good.

I'd add something to address the problem of manufacturers going bust and then all their devices becoming paperweights. Perhaps:

6. it should be possible for the user to install their own firmware / updates. Optionally at the cost of losing guarantee and access to future manufacturer provided updates.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#769
Thank you for doing this. I think you should go even further than mandating security updates. Companies should have to provide schematics, source code, everything we need to maintain the devices ourselves, especially if they have reached end of life. The corporations don't even need to incur the costs of maintaining the stuff if they don't want to. They just need to stop getting in our way.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#770

Earlier quoted context omitted.

I'm wondering why you'd have a smart oven in the first place. Seems like all risk and no reward.

Lucky guy, it sounds like you've never experienced overwhelming anxiety over having possibly left the oven on while out of the house.

Even if you left the oven on, I believe it’s very unlikely to burn down the house.

These devices are designed to work for hours with minimal supervision. Given the size of the user base, IMO ovens are extremely reliable. And electricity prices are too low to be anxious about the costs.

Post reply on HN