Earlier quoted context omitted.
It sounds like you're looking for a carve out so you don't have to upgrade your devices to have a modern microcontroller that supports remote updates and are using saltwater as a scary thing so no one challenges you on it. You can conformal coat a ESP32 with a sensor and battery and a wireless charger, and get remote updating. If hobbyists are doing that without commercial backing, what industry experts like you have…
You appear to be under a lot of mistaken assumptions. And in any case, the default ideal is to have an option to update or reprogram devices in-person. It's never an ideal, that I've ever seen expressed on HN, to have a remote actor capable of doing so, unless in a totally air gapped environment.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
791–800 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#792Earlier quoted context omitted.
It's good that consumers have much less power in context of forcing manufacturers to the described choice?
What do you mean by less power? It's different. One manufacturer can't force you to buy stuff you don't want, nor ban you from buying from a different manufacturer that does what you want. (In contrast with the FCC, which has a lot of power over you, by banning you from buying what you want.)
Why would one want specifically to buy a product not conforming to the choice described in the first-level comment?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#793Uh, first, I'll assume that "IoT" abbreviates Internet of Things.
===>>> IoTs?
Okay what things, IoTs, are being considered?
(a) I have some computers that run Windows. These computers are such "things"? The Windows software itself is such a "thing"?
(b) My Windows computers connect to a box, likely called a cable modem, I got from my ISP (Internet service provider). The box communicates with the rest of the world via a coaxial cable likely originally installed to carry cable TV. My computers communicate with the box via Ethernet cables or WiFi. The box also provides land line telephone. Soooo, that box is an example of an IoT under consideration?
(c) Recently I got a smart phone. Once I used a USB (universal serial bus) cable to connect the phone to one of my computers running Windows 10 Home Edition and via that cable was able to send an image from the phone to Windows 10. Then I disconnected the cable from the Windows computer, and now occasionally Windows 10 puts a popup window on my screen reporting that the cable connection is no longer receiving a signal. Apparently now forever Windows will keep that reporting and popup window. Sounds like an error in software design and maybe a security issue.
I only got the smart phone for emergencies, and otherwise, net, in one word, I HATE it. I keep it in my car in an envelope that claims to be a Faraday cage. My guess is, since the software is so bad, just awful, the worst I've ever seen in computing, there are likely many serious security problems. Since I want no problems of any kind, I can only hope that the envelope really is a Faraday cage.
(d) Several devices, e.g., table lamps in my office, have a USB socket for charging smart phones. Then these devices are IoTs?
(e) On Windows my favorite Web browser is Firefox. Is that an IoT?
I'm concerned about Firefox: Last week I went shopping for an emergency electric generator, and now when I use Firefox I get ads for such generators. Sooo, that looks like a security problem. Firefox should fix that. I tried the Web browser Brave and then didn't get the ads. Hmm ....
===>>> Updates
On "updates", I get lots of those from Microsoft for Windows 10, whether I want the updates or not. Maybe their next update will fix the USB popup window problem.
Firefox pesters me like a flock of flying insects to download an "update". I have a lot of Firefox options set and no good list of those options independent of Firefox. So I'm concerned that an update might change my option settings, and fixing that could take a few hours -- bummer. So, one update each six months, maybe one a year, should be often enough.
I like Windows 7 Professional, and apparently some security updates are still available. Are there really some new security threats not handled by the latest security updates to Windows 7 Professional?
I intend to move to Windows Server 2019 and suspect that there Microsoft will be very careful about updates.
My computer running Windows 10 is a laptop from Hewlett-Packard, HP, and they offer various updates frequently, continually.
So, I do get some updates, really more updates than I want.
===>>> Security
I still like Windows 7 Professional. Since the main concern here is security, are there some serious security problems with Windows 7? Windows 10? The cable modem? What serious computer security problems are we talking about?
===>>> The Other Side
I'm reminded of various possible consequences:
"Ah, we got concerns, right here in River City. Concerns starts with a 'C', and that rhymes with a 'T', and that stands for things as in IoT."
Ah, there is this really big threat, and you need Federal Government officials and lawyers to save you??? Hmm, ..., really???
"I'm from the Federal Government, and I'm here to help you."
Two very old, very broad items of advice:
(A) Always look for the hidden agenda.
(B) Follow the money.
So, here in the security and updates of IoTs, what now or soon how might we apply (A) and (B)?
Well, there is "regulatory capture" where the businesses being regulated use the power of the government and lawyers to help the business make money.
Regulations tend to make products more complicated and expensive.
Laws involve lawyers: Then can spend many thousands, or even millions, of dollars in legal fees and years in legal fights just to argue over some issue that, really, has much easier resolutions.
My experience is that lawyers mess up everything. In a legal fight, only the lawyers do well. E.g., recently some lawyers talked my main bank into demanding that I drive from TN to NY and bring a death certificate for my wife who died in 1992. I've been with that bank since before 1992.
I reminded the bank that I'd been a good customer for 30+ years, wanted to remain a customer, and am happy to discuss solutions to any concerns they have, but I'm NOT driving from TN to NY, do NOT have a death certificate for my late wife's death, and as soon as they involve a lawyer I'm closing out my account and moving to another bank. Right away they regained some common sense. Uh, with lawyers and DC regulations, common sense can be in short supply.
With regulations, can need a trained, certified, licensed, insured professional to spend half a day and $2000+ just to turn a screw.
===>>> US Free Economy
Generally the US runs on a free economy. One of the pillars of that economy is competition. So, if one product causes trouble, then the customer might switch to another product from a competitor.
Soooo, for IoTs, what "trouble" are we considering???
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#794Earlier quoted context omitted.
> doesn't it make IoT devices incredibly insecure for normal users How secure or insecure a device is is unrelated to whether its source code is public. Disclosure: I might be biased on this, as I'm a reverse engineer.
If it were really unrelated, nobody would pay you to reverse engineer.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#795Earlier quoted context omitted.
Scroll down: https://arstechnica.com/author/dan-goodin/ This is just a teeny tiny sampling of the security vulnerabilities disclosed every day. Our industry is just not built with security as a goal, and even if we started caring about it today, we have 50 years of not caring to patch up. Caring about security in a meaningful way (i.e. formal verification, engineer licensing & liability) is really, really expensive.…
I'm sorry, I can't really debate with a reductionist claim that everything is 100% fucked when it's readily apparent that some threat actors are still being stopped. For what it's worth, I'm not disagreeing with your points about needing drastic, systemic improvements in how we handle security.
«A ragtag bunch of amateur hackers, many of them teenagers with little technical training, have been so adept at breaching large targets, including Microsoft, Okta, Nvidia, and Globant, that the federal government is studying their methods to get a better grounding in cybersecurity.»
My opinion is that we fail completely to build secure systems in a forward thinking way and the fact that we manage to stop threat actors that exploit holes that are already known to us is insignificant.
[0]: https://arstechnica.com/security/2023/08/homeland-security-d...
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#796As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…
IMO: one of the most important incentives towards secure IoT is: don't make it IoT unless it benefits the user greatly (instead of benefitting the manufacturer).
Don't let companies connect everything they want to the internet irresponsibly and if they must: force them to make it really really secure and long lasting (10+ years). Especially when there's high risk of causing physical damage to things and / or identity theft and / or privacy issues. Which en masse translate to national security issues.
Force them to sell devices that keep functioning even if the manufacturer (servers) cease to exist. Example: introduce a mandatory manufacturer IoT insurance that pays out in case the device ceases to function (securely) within x years (even in case of manufacturer bankruptcy).
Random chaotic brainfarts.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#797Earlier quoted context omitted.
> pick a better platform Unfortunately there isn't all that much competition in this space. The choice was try building on quicksand, or let the idea die. I'm glad we tried it.
Until there are consequences for building on quicksand, the vendors have no reason to improve their offerings.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#798Thanks for reaching out to the community. Instead of mandatory updates, there are lower hanging fruits you can win, and will have just as much, if not more positive security impact. 1. No default password, one must be set at initial configuration 2. Devices must function without public internet connection (unless it is one of the device's primary function to transmit out) 3. Devices must function without centralized…
I'd argue that even in that case it should still "function" without public internet connection, in the sense that everything but the egress transmission should be operable without public internet connection; e.g initial setup, later configuration changes, status, diagnostics, maintenance... Many devices use the "it's a transmission device by design" part as an excuse for "let's blanket require connection even for things that don't require it".
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#799Earlier quoted context omitted.
Lucky guy, it sounds like you've never experienced overwhelming anxiety over having possibly left the oven on while out of the house.
Even if you left the oven on, I believe it’s very unlikely to burn down the house. These devices are designed to work for hours with minimal supervision. Given the size of the user base, IMO ovens are extremely reliable. And electricity prices are too low to be anxious about the costs.
I wish. A while back, I put some (food) stuff to dry in the oven on a very low heat, knowing it would take all night to dry fully. After six hours, the oven decided that I must have accidentally left it on by mistake, and switched off automatically, and that stuff was wrecked when I got up in the morning and checked on it.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#800Earlier quoted context omitted.
I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glass, and get a sticker from the US Government saying so, it better be brick-proof.
> If someone wants to sell brick-proof glass, and get a sticker from the US Government In a free society, why would we ask government (lowercase g) for a window certification sticker? Should government also provide condom anti-breakage stickers? If we want this, maybe UL can set the standard and ask for volunteer testers to affirm the condom or window anti-breakage quality. Or maybe we can put the Bell System back to…
The condom comment is absolutely ridiculous because there are loads of regulations regarding condoms from the FDA. Unsurprisingly you aren't allowed to sell condoms that are likely to break.