Greetings from Ukraine, European country with real Great war just now. I must say, we see extreme grow of cyber-crime as part of modern war. I think, in nearest future, cold war will guaranteed have huge cyber-crime part. And, hacking of IoT devices has very significant share of cyber-crime now. For real war it is question of life and death, because hacked devices with radio emission, are used by hostile intelligence…
Hi and thanks for commenting. My concern with this topic is motivated in part by the AcidRain family of energy infrastructure attacks and the larger questions they raise about infrastructure security. Teardowns on Chinese-sourced equipment have been somewhat worrying as well -- one report I've read highlighted about two dozen versions of SSH in a single base station. Best wishes and good luck.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
891–900 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#892Earlier quoted context omitted.
In order to make it a consumer problem, we'd have to make it a criminal violation to participate in a botnet. We could make it a punishable infraction I suppose, much like a speeding ticket for automobiles, but somehow I just don't see this happening in a coordinated fashion across the world.
I think it is already illegal to participate in DDOS. Even though enforcement is .. pretty much nonexistent? And how could you enforce it? It would create an outcry if done consequently. (But maybe a neccessary one) But it also will be a consumer problem, if they cannot access important services anymore, because their IP has been blacklisted, because their toaster participated in too many DDOS or spam attacks.
While it is unlawful to knowingly or intentionally participate in a DDoS, what I'm talking about is the potential of also "criminalizing" (in the sense of a speeding ticket, not jail time - an infraction, not a misdemeanor or felony) using a vulnerable device that is then hijacked by an attacker.
Like you, I don't think it's a realistic outcome; I'm merely brainstorming how one could make this a consumer problem through economics.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#893Earlier quoted context omitted.
Sure you can. For example, we have vehicle codes that hold people accountable for dangerous driving.
We don't hold people accountable for buying the wrong model of car and using it.
In some sense, cars are better examples for responsible ownership, because almost every state requires you possess insurance to drive it. The price of an insurance premium is (supposed to be) commensurate with the risk of driving it, and insurance premium rates do influence the market for vehicles.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#894Earlier quoted context omitted.
You can't give them a slap on the wrist if you assert what they are doing isn't criminal. Having an issue with the punishment model is no reason to throw out the law. I think the subject has enough depth and complexity to it that we need to promote cooperation with companies. We can build protections against companies being dicks much easier that we can codify the difference between malicious or innocent intent behin…
> You can't give them a slap on the wrist if you assert what they are doing isn't criminal. Having an issue with the punishment model is no reason to throw out the law. The law is too broad in addition to being too punitive. But here's an argument for throwing it out entirely. There are two kinds of people who are going to spot a vulnerability in someone else's service: Amateurs and professionals. Professionals expec…
At the end of the day, I am arguing for promoting people to try to work with companies, and to put out to the public a process for making that effort effective.
I feel like we agree but our solutions are opposite. The current laws are insufficient, so we need adjustments to the laws.
You (and others) propose we make hacking into systems fully legal, presumably because we can target malicious activity based on what they do with that access instead of the access itself. Is that correct?
I also disagree that a ban is equivalent to shooting an intruder. The connection is not the actor, the person using it is. If a person chooses to enter into a protected space they do not have permission to be in, then they are susceptible to consequences to that. I think just because it is easy to do it from your bedroom doesn't change it. Much like how virtual bullying is still bullying; virtual breaking and entering is still breaking and entering.
If we formally adopt this attitude then we also enable ourselves to pressure other jurisdictions to raise their standards to match.
An uncontrolled internet appareny has 1 outcome - malicious spam. That is what everyone in this thread seems to agree on, and the arguments against what I suggest all seem start with the assumption "there is nothing we can do about it" and the corollary "there is nothing we need to do about it"
I think we can actually do something about it, and I think we ought to. But before all of that, I think the first place to start is making a clear legal relationship between security researchers and the private sector and debate the laws that should be in place to facilitate that in a fair way
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#895Earlier quoted context omitted.
This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…
You give up consent for a device to not be scanned the second it is connected to the public internet. There are botnets that are continuously scanning all allocated IP blocks for potentially vulnerable devices - try logging requests to an open 22 port and take a look at the kinds of requests you get. That's the price you pay for connecting to an open world wide network. Now the conduct and what the operators of a mas…
I think when it gets here there is going to be a lot more trouble for cybersecurity experts due to a lack of clear understanding around what is considered legal activity or not from them. Right now the obscurity is something they hide in - they can choose whether or not to reveal they found a vulnerability.
But what if that's not always the case? What if you get "caught" before you are able to show you had no intentions of doing anything malicious?
We can have the trial by fire we usually do, and let a round of innocent people face unjust consequences and use them as martyrs to create new laws - or we can use some foresight and build some legal frameworks in advance that enable researchers to be "by the book" and not worry at all about legal repercussions
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#896The members of the alliance for DER devices have recently started working towards standards and solutions for cybersecurity of their devices which could overlap with what you are trying to do within FCC.
There might be opportunities to collaborate if you see fit.
Best
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#897Earlier quoted context omitted.
If it were really unrelated, nobody would pay you to reverse engineer.
Which is why I believe I'm biased: I support releasing source codes, even if it sounds like it's going to reduce my pay.
Also, there are high-profile instances of hardware security that rely on obscurity, like secure enclaves or the iPhone passcode unlock. They tend to get cracked eventually, but it's still hard.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#898They are the ones that provide sdk’s for manufacturers to write firmware with ota firmware updates, flash encryption, secure boot, etc.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#899Earlier quoted context omitted.
> There is an inherent risk of your vulnerabilities being broadcasted somewhere either on purpose or accidentally once that information is collected and organized by the researcher. A legitimate researcher is going to promptly notify you of any vulnerabilities they discover and you as a large organization are going to promptly remediate them. But the trouble isn't that the law might impose a $100 fine on a smug profe…
I once found a vulnerability. I pressed F12 and saw unintended information in the source of a webpage. I just closed the tab, I didn't report it. Our laws made it risky to do the right thing, so I didn't do the right thing.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#900Earlier quoted context omitted.
Part of systemic improvement to security comes from the market forces that reward producers putting out carefully designed and tested products and punish producers that don't. Your suggestion of requiring prior notice, coordination, approval etc. incentivises them to defer the cost of proper development until there is a crisis, so they can rush out any rubbish product, and force users and researchers to do their secu…
I proposed protected legal channels for researchers. It does remove any pressure from companies. Their neck is still on the line. It adds pressure to companies because it creates a paper trail. It enables good faith companies to work with researchers as well. They can even have researchers contact each other if they are both looking into the same thing. There's a lot of good that can come of it Companies can already…
If the production company declines, that DOES remove pressure from that company.
Companies that rush out rubbish products can presently be named and shamed by independent, uncooperative or even adversarial researchers. Your proposal considers that research illegitimate unless said dodgy company decides to open itself up to scrutiny, which it obviously would not be inclined to do.
If you want to suggest the market would respond by not selecting products from such an opaque company, look into how many WhatsApp users care about auditable, open source code vs. those using Signal.