Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

831–840 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#831

Earlier quoted context omitted.

I proposed a preference for systemic solutions over building a soft dependence on white hat hackers. This benefits society as a whole because it clearly delineates actions with intent. If doing X is always not allowed, then all you need to do is find people doing X and you can hold them accountable. If you allow or disallow the same activity based on merit of intent, then you increase the level of plausible deniabili…

You attempt to solve the problem of chaos (think grey-hat) by expanding law enforcement--by enforcing order on every internet user world wide. That's going to require a lot of boots to squash a lot of faces. Curious kids who run port scans will stand before judges, journalists who press F12 will face the ire of the most powerful and decades in prison[0]. This will probably require some national firewalls as well. Thi…

The status quo is not sufficiently codified. I am suggesting we codify it so that we can look at the rules and change them so that they make sense.

I also think it would be a good thing to have a legally protected avenue for people to declare their intent before checking for unlocked doors and such.

Imo I think a lot of the problems are coming from companies feeling like they are getting fleeced by security experts. If a company has acknowledged you as a researcher beforehand, then you have a pretty strong legal defense if they decide later that they don't like what you find.

I am not suggesting a new world order over everyone that uses the internet. People who stumble upon vulnerabilities without looking for them, or through incredibly basic means like a port scan, can be protected. We can feasibly list enough ways someone can uncover a security hole without a direct effort to do so such that the spirit of the law is sufficiently obvious to any judge to include any new ways that pop up on a case by case basis.

However, we cannot currently offer any protection to people directly trying to find vulnerabilities when such actions are identical to people who are trying to abuse it. The only possible differentiating action would be someone to announce beforehand that they are aware what they are doing looks like criminal activity and to request permission to proceed.

The argument that we have the technology to make in infeasible to hack systems is moot and imo naive. There is cost, significant cost, to maintaining the highest level of cybersecurity. Cybersecurity experts are some of the highest paid IT professionals on the market right now.

So I do not see how educating people who want to look for vulnerabilities to reach out for approval on what they are doing is too much order, but requiring everyone who creates anything that uses the internet to successfully implement state of the art cybersecurity defenses is not

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#832
post #781

Earlier quoted context omitted.

I imagine someone in the many many comments has already suggested this. But just in case: It wound be great if all of my emails to security@somewebsite.con could be CC’d to security@fcc.gov and that would immediately convey to me, somewebsite, and the FCC (and anyone else) that I am indeed disclosing and not ransoming. I understand there would be a cost that the FCC would bear. I just think it would be a worthwhile c…

This seems like a pretty clear breach of first amendment rights (we have a right to choose what we say, and who we say it to). It is probably a good idea for researchers to implement this strategy, and obviously more protections are needed for researchers in this area, but eroding the bill of rights is not the way.

Im a little confused. Can you explain how their proposal is a first ammendment violation? If you're reffering to "could be CC'd to security@fcc.gov," I assume they mean make it an option, not make it mandatory. Some companies attack you for trying to disclose bugs and exploits -- saying that you're attempting to ransom.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#833
post #719

Earlier quoted context omitted.

This is a very poor analogy. For one thing, casing someone's home is not interesting research. It's not news to anyone that locks only keep honest people out. You need physical access to break in. The legal system and the people nearby (neighbors and residents, and their firearms in the USA) are the main lines of defense here. Unlocked doors are a harm targeting one household. Conversely, with vulnerable IoT devices,…

Another analogy could be someone doesn't realize they left their back door open and these guys come and point it out.

I think the analogy would be someone doesn't realize they left their backdoor unlocked.

You can see an open door. You can see an unlocked door unless you go up and try to open the door.

if a stranger informed me that my backdoor was unlocked, then I would be immediately suspicious. Why were you at my door trying to open it without trying to contact me first?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#834
post #757
post #694

Earlier quoted context omitted.

> It's just a matter of implementing a signature verification correctly With rollback protection, a chain of signing keys to allow revocation, time stamping, correct parsing, enough scratch space to hold an entire separate image in A/B, enough processing power to verify image signatures, etc etc. Doing this well is very hard. Given most IoT vendors don’t yet know how to prevent XSS, there’s near zero chance they’ll g…

Also with right to repair, you need to be able to disable signiture checks and upload custom firmware

Yeah true, that’s a fascinating challenge that I haven’t seen particularly well discussed anywhere in detail.

It needs to be really well protected so that the owner, and only the owner can disable the chain of security, but that they can do it without unreasonable overhead and without actually involving the manufacturer (in my opinion. To handle examples like manufacturer trying to lock-in or charge fees or simply going out of business)

Perhaps the owner mints a public key pair, and the device only unlocks with proof of the private key. But in a way in which is easy for your every day person.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#835
post #785

Earlier quoted context omitted.

Finishing dinner can be more important than the house not burning down. A burned down house is likely insured. A dinner with a potential business client is not.

Surely this has to be a joke.

It’s just the Northern Lights.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#837
post #803

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

> but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. The reality of netsec has not born out this model. In practice, you have two broad categories of companies: - Ones that already have a culture of security, run pentests, have bug bounties, deploy patches, etc. These aren't the ones exacerbating the botnet-o…

People aren't white or grey or black hats. Actions are.

A person can wait until they find a vulnerability to decide what type of hat they want to be. That is not only possible, but also the most rational thing for someone to do if there are no negative consequences to declaring yourself one way or the other before you find the vulnerability.

All of the problems mentioned can be addressed above the table.

We don't allow people to test your defenses unsolicited in any other industry that i know of, and the cost of cybersecurity is very high.

We can make basic security defenses a law if we want to without giving cover to black hats.

You can't throw the book at someone who has approval to do research. Business does not need to have at-will rights over that approval, we can require sufficient reasoning to deny

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#838

Earlier quoted context omitted.

The ability to pre-heat my oven without standing in front of it. That's really the big win. But also to be able to tell if spouse or children left it on.

But I can walk to my oven and turn it on, which wasn't a real problem even when I lived in a huge house. What am I missing?

People with internet controlled ovens turn them on before arriving home to shorten the time it takes to get dinner on the table.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#839

Earlier quoted context omitted.

I agree the laws are too broad. I think we need add layers of granularity to them. Create more of a framework for settling the rules on what is and isn't allowed. Maybe we settle on everything goes, but the company should be involved. A legitimate researcher should be notifying the company that they are going to be looking for vulnerabilities in the first place. That is part of the distinction in behavior that I am e…

so are you saying that I shouldn't be testing a product I purchased or a product that someone mandated I have in my house? I shouldn't have to notify anyone, I own it and I should be able to do with it whatever I please. In addition if I do find an exploit I am not obligated to notify the company nor should I be. A good faith company should be doing their due diligence and not releasing unprotected/poorly protected d…

You don't own the inside of it. That's the core part of all this. Businesses decided to sell items with special conditions where you can own possession of the item as a whole but not the ability to dismantle it.

That's just a contract with terms. If you are in the position being addressed by my points, then you have already agreed to those terms.

your problem is with the ownership model, or something else. I am saying, since this model is already in existence and accepted by the public, we need to create some safeguards.

We cannot bypass the fact that you do not own the thing you are testing. So if you want to test something you do not own, then yes I think involving the entity that does own it is reasonable

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#840
Eliminate trust.

The thing must be functional and operational by its own volition. No clouds, no hosts, no servers controlled by 3rd parties that control anything.

You do this by: 1) encryption. Make all data useless. 2) standardization. IoT devices must be compatible with multiple hosts, one being one you can install and run yourself. 3) open source (source available)

Companies can still sell their goods by: 1) offering the "thing" that must be bought. 2) offering the software or point to the software, maybe with added bells and whistles (a source-available extension, audited by FCC plus 2 other parties etc).

Control must be localized. In the app of the user etc. No round trips to any clouds.

Post reply on HN