Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

841–850 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#841

This looks to treat only the symptom. What we need is regulation that controls spam and punishes cyber attacks. We should not accept the constant round-the-clock break in attempts on every system in the country as just normal "background noise" on the Internet. If people were going up and down every street testing the locks on every door we would do something about it instead of just saying "how can we coerce compani…

Couldn't agree more

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#842

Thanks for reaching out to the community. Instead of mandatory updates, there are lower hanging fruits you can win, and will have just as much, if not more positive security impact. 1. No default password, one must be set at initial configuration 2. Devices must function without public internet connection (unless it is one of the device's primary function to transmit out) 3. Devices must function without centralized…

1. - routers have mainly solved this by having a unique, random password which is provided on a sticker on the device. Other than that, these are really good. I'd add something to address the problem of manufacturers going bust and then all their devices becoming paperweights. Perhaps: 6. it should be possible for the user to install their own firmware / updates. Optionally at the cost of losing guarantee and access…

Routers are decently large , generally have enclosures, and are meant to be placed in a reasonably accesible position for those who should have access to them while at the same time out of sight for those unauthorized, which makes putting a sticker on it, keeping it there, and having the right people read it when needed is trivial.

Some IoT devices could be handled the same way, but there are plenty of reasonable IoT applications where a password written on the device is impractical or a security risk.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#843
What I'd like to see:

Foreign manufacturers shipping devices to this country should make frequent firmware updates available. If they use open source / GPL'ed software then should release that too.

There should be a period of X (maybe 5) years after which a device is considered obsolete. At that time all sources inclusive of the opaque binary blobs should be released.

There should be a site / infra by FCC where manufacturers could dump those files.

The FCC itself should get a copy of the source of opaque binary blobs as soon as the device is introduced in the local market.

If that is made a mandate, there are couple of benefits: No device that suspiciously sends data to foreign servers. Less e-trash as community can build / maintain firmware as there is access to source code.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#844

What I'd like to see: Foreign manufacturers shipping devices to this country should make frequent firmware updates available. If they use open source / GPL'ed software then should release that too. There should be a period of X (maybe 5) years after which a device is considered obsolete. At that time all sources inclusive of the opaque binary blobs should be released. There should be a site / infra by FCC where manuf…

This will have a world wide positive impact.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#845
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

30 years of expected support is pretty unreasonable. Stating a requirement like this makes the discussion about competing dogmas. Rather, it's about the right way to keep devices operational as long as possible while also allowing companies to remain possible. 30 years of support expectations immediately makes the cost of any device go up to hedge against the risk of fines during the entire 30 years. It also makes it…

> I don't have a single computing device that has lasted longer than 10 years. Reasonably speaking, either performance or features start to make the device largely obsolete and unusable.

Are you just buying cheap junk? An i7-3770 PC - a good example of an 11 year old PC, and one I happen to use every day - can be quite usable today.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#846

Earlier quoted context omitted.

I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glass, and get a sticker from the US Government saying so, it better be brick-proof.

> If someone wants to sell brick-proof glass, and get a sticker from the US Government In a free society, why would we ask government (lowercase g) for a window certification sticker? Should government also provide condom anti-breakage stickers? If we want this, maybe UL can set the standard and ask for volunteer testers to affirm the condom or window anti-breakage quality. Or maybe we can put the Bell System back to…

Are you suggesting the stakes are the same for digital communications as for condoms? How big of an actual problem is condom breakage? How big of a problem is digital surveillance and theft? How do these two problems compare economically today?

Reasons I think we might want some government certification that has real teeth include: the freedom to protect and control our own digital data. A statistically high rate of surveillance and cyber crime with no tools to prevent it impedes the very freedom you’re defending. Absolute freedom for all cannot exist. You can’t be free to keep your money & privacy while I’m free to take it. Real certifications with enforcement teeth wouldn’t solve all problems, but it might make an actual dent. It would be nice to have national security and privacy standards, make purchasing decisions easier (actually sane), prevent some of the crime before it happens, and reduce the crime and surveillance that we know exists. That’s just from a consumer point of view. I’m sure there are many many companies and organizations who would love to be able to have some level of trust in their equipment purchasing without expensive vetting (or far more realistically for most orgs, little to no vetting at all, just hope).

Didn’t the government break the Bell system apart in the first place? When did they get back together and upcharge handsets? I don’t know what you’re referring to. Are you saying that what was needed after the Bell breakup is stronger regulatory oversight with bigger teeth?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#847
post #577

Earlier quoted context omitted.

> Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs. +1 for this at the consumer level. My oven may have a critical update, but - for right now - *nothing* is more critical than finishing dinner. I'll let the update apply the day after thanksgiving when I'm doing the dishes. There are a few connected appliances brands that do this well: updates…

I think this is oversimplifying things. Is finishing the dinner more important than applying a patch that fixes actively exploited bug that locks your oven into cleaning mode and burns everything inside into ash over the next three hours? Or something that disables the safety checks and lets the oven overheat and burn your house down? (Granted, the latter shouldn't physically be possible because it should have physic…

You make a good point, but this kills me. I've been writing software a long time, and there's nothing I trust less to control my oven than software. God help us. I yearn for simple physical controls

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#848

Earlier quoted context omitted.

I agree the laws are too broad. I think we need add layers of granularity to them. Create more of a framework for settling the rules on what is and isn't allowed. Maybe we settle on everything goes, but the company should be involved. A legitimate researcher should be notifying the company that they are going to be looking for vulnerabilities in the first place. That is part of the distinction in behavior that I am e…

> A legitimate researcher should be notifying the company that they are going to be looking for vulnerabilities in the first place. That is part of the distinction in behavior that I am encouraging. This way if someone is caught poking around for things to abuse unsolicited, at least there's a little more merit to holding them accountable. We are able to treat it more like the threat it is. The issue is this. You hav…

You can't give them a slap on the wrist if you assert what they are doing isn't criminal. Having an issue with the punishment model is no reason to throw out the law.

I think the subject has enough depth and complexity to it that we need to promote cooperation with companies. We can build protections against companies being dicks much easier that we can codify the difference between malicious or innocent intent behind actions that are more or less identical up until damages happen.

I don't think I'm proposing anything that assertive. I'm suggesting we just put it all in the open and down on paper in a way that addresses most of the concerns and involves the company.

Documented evidence that companies were notified of security issues by people who declared that they were researchers, who the company approved to research, is a great thing to have in the fight against ignorant companies.

I completely agree that a degree of this is quaint with respect to a lot of the trouble coming from outside your jurisdiction. I just really don't see an issue with creating protected avenues for people to do research.

Opening someone's front door "on a lark" can get you shot in some states. I get that innocent people do technically illegal actions sometimes but that doesn't change whether or not an action is perceived as threatening.

So I recommend we start writing down the actions that need to be protected and at the very least give someone acting in good faith a bulletproof way to both conduct research and preserve innocence.

If you happen to uncover something accidentally and are concerned, then you can make the request afterwards and repeat your finding and report it. So no need to feel the need to stay silent

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#849

I'd be really happy with products having to be labeled with: 1. Final date the manufacturer will provide firmware updates & security updates 2. If the manufacturer will support open source alternative firmware & security updates. 3. If there are any subscription fees (and how much) to get firmware updates & security updates. Issue #1 is a big deal: I've purchased equipment, new in the box, after the mfg had discontin…

> I've purchased equipment, new in the box, after the mfg had discontinued support. Exactly the kind of thing that sounds crazy but still happens. > 1. Final date the manufacturer will provide firmware updates & security updates 2. If the manufacturer will support open source alternative firmware & security updates. 3. If there are any subscription fees (and how much) to get firmware updates & security updates. It wo…

I'll did so. Thanks for the encouragement!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#850
post #719

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

This is a very poor analogy. For one thing, casing someone's home is not interesting research. It's not news to anyone that locks only keep honest people out. You need physical access to break in. The legal system and the people nearby (neighbors and residents, and their firearms in the USA) are the main lines of defense here. Unlocked doors are a harm targeting one household. Conversely, with vulnerable IoT devices,…

Building codes analogy still supports my argument. You cannot just walk into a strangers home and inspect it for whether or not it is up to code.

I agree analogies are going to be imperfect, which is why it's important not to criticize an anology based on where it fails but to work with it on the point it is meant to express, and then yes if it doesn't actually convey the point then it could be a bad analogy.

I think it might help if we clarify WHY a lock keeps honest people out. If a house is locked, you MUST commit a crime to gain entry. So by nature of bypassing the lock, you are no longer acting honest. It is not about what type of person you are, it is about clearly delineating honest actions from criminal actions.

If the door is unlocked, then a person could walk in and then pretend they didn't know better if they get caught. This is assuming we say it's okay to walk through unlocked doors

However, since we acknowledge it as criminal behavior to even test whether or not a door is unlocked - the existence of locks in general and the common knowledge of where they should be expected to be found establishes a barrier honest people know not to cross.

With respect to cybersecurity, I am proposing we accept a similar relationship while also creating protected legal paths for honest people to conduct security research.

The thing we can all likely agree on is what cybersecurity is and where it applies. By nature of knowing where it should apply, we establish a barrier that honest people should not be crossing without permission.

I agree that there is a lot of foreign danger involved with the topic and botnets are a concern. However, progress there is not going to be made by random hobbyists testing websites for sql injections for fun. It's going to be made by cybersecurity professionals who can easily be educated to and comply with a regulation to declare their intent and get approval before poking around.

The rules for an approval process are a totally open book. It does not need to be restrictive or limiting to researchers

Post reply on HN