Earlier quoted context omitted.
The ability to pre-heat my oven without standing in front of it. That's really the big win. But also to be able to tell if spouse or children left it on.
But I can walk to my oven and turn it on, which wasn't a real problem even when I lived in a huge house. What am I missing?
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
851–860 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#852Earlier quoted context omitted.
This is a very poor analogy. For one thing, casing someone's home is not interesting research. It's not news to anyone that locks only keep honest people out. You need physical access to break in. The legal system and the people nearby (neighbors and residents, and their firearms in the USA) are the main lines of defense here. Unlocked doors are a harm targeting one household. Conversely, with vulnerable IoT devices,…
I think a better analogy can be drawn by just considering the physical version of some things. For IoT, you can say if someone discovers a specific brand of physical lock can be broken in unexpected ways, they should be allowed to communicate this in a way that benefits the users of the lock without facing any legal risk. For internet banking, you can discuss a physical vault that safekeeps everyone's gold, and say t…
Everything you said after that is a valid continuation from that, but the scope of the issue I am talking to centers around that how.
Because locks have never actually been unbreakable, right? The main purpose of a lock, the generally accepted way that the lock keeps people out - is by existing, not by being strong.
We have higher standards for the lock in more serious applications, like a vault, but if you buy a vault door, put it in your garage, and begin testing it for vulnerabilities- I feel like it's reasonable to view that as criminal. I admit 100% that it could be a curious tinkerer, but I do not think it is unreasonable to tell the tinkerer that they can't do that without permission.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#853Earlier quoted context omitted.
These seem like very rare scenarios. If we're concerned about dire threats like this, the manufacturer needs a way to remotely send devices into an internet-disconnected "safe mode" before anyone's even talking about updates.
If these are the kind of things we are worried about then the correct course of action is to ban needlessly internet connected devices. Your need for twitter on your fridge doesn't outweigh the botnet threat it poses.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#854Earlier quoted context omitted.
But I can walk to my oven and turn it on, which wasn't a real problem even when I lived in a huge house. What am I missing?
In my case, being able to start it heating when I'm ten minutes away from home, so that I can get the kids fed ten minutes sooner.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#855Earlier quoted context omitted.
This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…
What do you think about a person who bought a house and documented all the ways to rob it that they could find? As far as I am aware, there is no law against that; and that is more comparable to what security researchers are actually doing.
However, the owner should still have a right to validate the security of his house - so he should be able to request for permission to break the terms of his contract for the sake of security research. That is going to require approval from the company, who the contract is with. I think we should be looking to make some laws around making sure this communication can happen safely and fairly
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#856Earlier quoted context omitted.
>AND be obligated to release the full source code for the device once they decide to end support. This is unreasonable. Code is often reused in the next generation of a product. The company may not have the rights to release all of the code.
A competent technician with access to a workshop can make even 80 year old vehicles work. That is long past the service life of that vehicle but it can still be done, an iteration of the same technology is likely still in use today though in your car. That isn't possible for software simply because reverse engineering is not simple, reverse engineering a small microcontrollers firmware might be possible, reverse engi…
Nor is repairing a car. It is not as hard as you think to RE some random IoT device firmware.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#857Earlier quoted context omitted.
1. - routers have mainly solved this by having a unique, random password which is provided on a sticker on the device. Other than that, these are really good. I'd add something to address the problem of manufacturers going bust and then all their devices becoming paperweights. Perhaps: 6. it should be possible for the user to install their own firmware / updates. Optionally at the cost of losing guarantee and access…
Routers are decently large , generally have enclosures, and are meant to be placed in a reasonably accesible position for those who should have access to them while at the same time out of sight for those unauthorized, which makes putting a sticker on it, keeping it there, and having the right people read it when needed is trivial. Some IoT devices could be handled the same way, but there are plenty of reasonable IoT…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#858Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#859Earlier quoted context omitted.
1. - routers have mainly solved this by having a unique, random password which is provided on a sticker on the device. Other than that, these are really good. I'd add something to address the problem of manufacturers going bust and then all their devices becoming paperweights. Perhaps: 6. it should be possible for the user to install their own firmware / updates. Optionally at the cost of losing guarantee and access…
Routers are decently large , generally have enclosures, and are meant to be placed in a reasonably accesible position for those who should have access to them while at the same time out of sight for those unauthorized, which makes putting a sticker on it, keeping it there, and having the right people read it when needed is trivial. Some IoT devices could be handled the same way, but there are plenty of reasonable IoT…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#860Earlier quoted context omitted.
I think the difference is in what's yours and what's theirs. If it's yours, I agree. If it's theirs, I disagree. The idea of absolute ownership is being eroded. You purchase a device but that device may use information you do not own. If you are manipulating the device to allow it to give you information you did not purchase and the contract you agreed to with the purchase was that you would not do this, then that is…
A device that is installed in my home but which I do not own is an increased liability on me .
Don't install it in your home if you don't trust it. Don't buy things with terms and conditions where you dont own the device if you want to own the device. This is a different problem