Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

861–870 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#861
post #790

Earlier quoted context omitted.

I hate it too, but the heart of this is that ownership is under question. People should not have agreed to buy things where there are parts of it they don't own that they don't even need, but they did. They did it a lot because it didn't matter to them and now those devices are prevalent everywhere and it's a PITA to try to buy the type of item you actually want - where you own it entirely. Ownership has never actual…

Out of curiosity - why should I be required to ask for permission from given company to probe company owned infrastructure? What I mean here is that if there's a bug / vulnerability on given company infrastructure, then that company should fix it and not put on a blame on a user that was affected by it (even if device that communicates with given infrastructure always follows happy path)

I try to get back to a real world analogy, think of a bank:

Can you try opening the public door off hours and discover it is locked? Yes, of course.

If the the public door is unlocked, can you now go inside the bank and start trying different combinations to open the safe? No, you will be arrested.

Anytime you move from probing a website with a browser to using other tools, your actions are subject to interpretation

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#862

Earlier quoted context omitted.

This may be beyond the FCC's purview, but given some of the comments (e.g., https://news.ycombinator.com/item?id=37393644 ) perhaps an entirely different strategy is warranted. Instead of trying to compel manufacturers, who may no longer even exist, to support their old products; perhaps the government should focus on protecting consumers and aftermarket vendors who update / modify / reverse-engineer older revisions-…

I imagine someone in the many many comments has already suggested this. But just in case: It wound be great if all of my emails to security@somewebsite.con could be CC’d to security@fcc.gov and that would immediately convey to me, somewebsite, and the FCC (and anyone else) that I am indeed disclosing and not ransoming. I understand there would be a cost that the FCC would bear. I just think it would be a worthwhile c…

I like the general idea of improving communication / transparency.

Perhaps some branch of the government could provide a registry for responsible disclosure (e.g., `https://some-branch.gov/responsible-disclosure`). As a security researcher, you could notify the government of your intent to disclose as a demonstration of due diligence and good faith.

The registry/site could return a case/reference number that could be included with the disclosure to the manufacturer. In addition to discouraging an attitude of defensive reprisal, it might also prevail a greater sense of urgency upon the manufacturer to follow through with remediations.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#863

Earlier quoted context omitted.

I think the difference is in what's yours and what's theirs. If it's yours, I agree. If it's theirs, I disagree. The idea of absolute ownership is being eroded. You purchase a device but that device may use information you do not own. If you are manipulating the device to allow it to give you information you did not purchase and the contract you agreed to with the purchase was that you would not do this, then that is…

> If what you learn by probing it allows you to breach the security of other people using the same service, then that is threatening What is threatening is that the company that sells baby monitors and keeps video recordings of your family members being naked has zero accountability for their security and almost no chance of being caught if they misuse it.

That does suck and we should do something about that. Accountability could be part of the legal framework.

Trying to gain access to those video recordings by exploiting the device is still threatening too.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#864

Earlier quoted context omitted.

Did not know it was $450k per product, my second responsibility outside of software engineering was being the risk manager at my previous company as well which is FDA-regulated. Still, many IoT companies that sell products don't even have protocols or a QMS at all, and need some kind of heat applied to them.

I might be a bit cynical, but if you divide the world of IoT into companies that do things well (but charge more) and companies that do things badly (but charge less), then I think the following might happen if you mandate QMS and audits. The companies that do well already just add to their costs (and prices) as they need to employ people to maintain these systems, and companies that do badly will also have to hire t…

It's not just covered by hiring compliance people. You need to have an actual quality management system, e.g. a Jira (or whatever) instance that links from bug reports to documentation to code commit to feature deployment. Instead of just having an email address and sometimes letting the engineers know, and the engineers sometimes make a code commit with a message that makes any kind of sense, and engineers sometimes reviewing code, and engineers sometimes forgetting a region to deploy the update to.

You might think these kinds of things are table stakes, and I would agree.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#865

Earlier quoted context omitted.

But I can walk to my oven and turn it on, which wasn't a real problem even when I lived in a huge house. What am I missing?

In my case, being able to start it heating when I'm ten minutes away from home, so that I can get the kids fed ten minutes sooner.

A timer to turn on an oven has been a thing for 25 years or more, probably there were clockwork ones before that. So it is down to very fine control on timing, or not turning the oven on, say, if you're in a traffic jam.

I'd expect the network connection to go down and the oven not to turn on at least as often as 10 minute makes an operable difference.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#866

Earlier quoted context omitted.

I'm wondering why you'd have a smart oven in the first place. Seems like all risk and no reward.

Lucky guy, it sounds like you've never experienced overwhelming anxiety over having possibly left the oven on while out of the house.

If you think the oven can burn the house down, how about the anxiety of trusting some companies IoT oven not to be exploited by script kiddies to burn your house down?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#867

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

Part of systemic improvement to security comes from the market forces that reward producers putting out carefully designed and tested products and punish producers that don't. Your suggestion of requiring prior notice, coordination, approval etc. incentivises them to defer the cost of proper development until there is a crisis, so they can rush out any rubbish product, and force users and researchers to do their secu…

I proposed protected legal channels for researchers.

It does remove any pressure from companies. Their neck is still on the line.

It adds pressure to companies because it creates a paper trail. It enables good faith companies to work with researchers as well. They can even have researchers contact each other if they are both looking into the same thing.

There's a lot of good that can come of it

Companies can already rush out any product they want with no security. Lack of security is still a risk, regardless of how we address researching vulnerabilities

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#868

Earlier quoted context omitted.

I imagine someone in the many many comments has already suggested this. But just in case: It wound be great if all of my emails to security@somewebsite.con could be CC’d to security@fcc.gov and that would immediately convey to me, somewebsite, and the FCC (and anyone else) that I am indeed disclosing and not ransoming. I understand there would be a cost that the FCC would bear. I just think it would be a worthwhile c…

I like the general idea of improving communication / transparency. Perhaps some branch of the government could provide a registry for responsible disclosure (e.g., ` https://some-branch.gov/responsible-disclosure `). As a security researcher, you could notify the government of your intent to disclose as a demonstration of due diligence and good faith. The registry/site could return a case/reference number that could…

I'm not sure if it'd be necessary/useful but it might also be interesting to leverage zero-knowledge proofs so that interested parties could verify when the contents of a disclosure were made available without actually accessing the contents until after some attempts at remediation.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#869
I hope that your team has considered the excellent work being done by IEEE and UL in the standards space, along with ISO. I think aligning and requiring management of these connected devices like any other computing device just like the EU requires will be of great benefit.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#870

Earlier quoted context omitted.

I might be a bit cynical, but if you divide the world of IoT into companies that do things well (but charge more) and companies that do things badly (but charge less), then I think the following might happen if you mandate QMS and audits. The companies that do well already just add to their costs (and prices) as they need to employ people to maintain these systems, and companies that do badly will also have to hire t…

It's not just covered by hiring compliance people. You need to have an actual quality management system, e.g. a Jira (or whatever) instance that links from bug reports to documentation to code commit to feature deployment. Instead of just having an email address and sometimes letting the engineers know, and the engineers sometimes make a code commit with a message that makes any kind of sense, and engineers sometimes…

Agree; I make software as a medical device. My point is you often don't have to do that. You just have to fling a lot of paper at an auditor, which can be generated well (as you describe, and as I would do, and the good companies in my example would already do) or badly (which the bad companies in my example would do) where it's basically generated post hoc in a hurry.
Post reply on HN