Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

891–900 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#891
post #517

Greetings from Ukraine, European country with real Great war just now. I must say, we see extreme grow of cyber-crime as part of modern war. I think, in nearest future, cold war will guaranteed have huge cyber-crime part. And, hacking of IoT devices has very significant share of cyber-crime now. For real war it is question of life and death, because hacked devices with radio emission, are used by hostile intelligence…

Hi and thanks for commenting. My concern with this topic is motivated in part by the AcidRain family of energy infrastructure attacks and the larger questions they raise about infrastructure security. Teardowns on Chinese-sourced equipment have been somewhat worrying as well -- one report I've read highlighted about two dozen versions of SSH in a single base station. Best wishes and good luck.

Can you share this report?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#892

Earlier quoted context omitted.

In order to make it a consumer problem, we'd have to make it a criminal violation to participate in a botnet. We could make it a punishable infraction I suppose, much like a speeding ticket for automobiles, but somehow I just don't see this happening in a coordinated fashion across the world.

I think it is already illegal to participate in DDOS. Even though enforcement is .. pretty much nonexistent? And how could you enforce it? It would create an outcry if done consequently. (But maybe a neccessary one) But it also will be a consumer problem, if they cannot access important services anymore, because their IP has been blacklisted, because their toaster participated in too many DDOS or spam attacks.

> I think it is already illegal to participate in DDOS.

While it is unlawful to knowingly or intentionally participate in a DDoS, what I'm talking about is the potential of also "criminalizing" (in the sense of a speeding ticket, not jail time - an infraction, not a misdemeanor or felony) using a vulnerable device that is then hijacked by an attacker.

Like you, I don't think it's a realistic outcome; I'm merely brainstorming how one could make this a consumer problem through economics.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#893

Earlier quoted context omitted.

Sure you can. For example, we have vehicle codes that hold people accountable for dangerous driving.

We don't hold people accountable for buying the wrong model of car and using it.

We do -- in a sense. For example, in CA, you can't lawfully drive a car that has failed a mandatory emissions test.

In some sense, cars are better examples for responsible ownership, because almost every state requires you possess insurance to drive it. The price of an insurance premium is (supposed to be) commensurate with the risk of driving it, and insurance premium rates do influence the market for vehicles.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#894

Earlier quoted context omitted.

You can't give them a slap on the wrist if you assert what they are doing isn't criminal. Having an issue with the punishment model is no reason to throw out the law. I think the subject has enough depth and complexity to it that we need to promote cooperation with companies. We can build protections against companies being dicks much easier that we can codify the difference between malicious or innocent intent behin…

> You can't give them a slap on the wrist if you assert what they are doing isn't criminal. Having an issue with the punishment model is no reason to throw out the law. The law is too broad in addition to being too punitive. But here's an argument for throwing it out entirely. There are two kinds of people who are going to spot a vulnerability in someone else's service: Amateurs and professionals. Professionals expec…

I think you're getting way ahead of the conversation, and there is no way to know what the implementation would be like and how communication would go between researchers and companies because if you can think of the communication problem today, then we can consider a solution for that problem in the implementation tomorrow.

At the end of the day, I am arguing for promoting people to try to work with companies, and to put out to the public a process for making that effort effective.

I feel like we agree but our solutions are opposite. The current laws are insufficient, so we need adjustments to the laws.

You (and others) propose we make hacking into systems fully legal, presumably because we can target malicious activity based on what they do with that access instead of the access itself. Is that correct?

I also disagree that a ban is equivalent to shooting an intruder. The connection is not the actor, the person using it is. If a person chooses to enter into a protected space they do not have permission to be in, then they are susceptible to consequences to that. I think just because it is easy to do it from your bedroom doesn't change it. Much like how virtual bullying is still bullying; virtual breaking and entering is still breaking and entering.

If we formally adopt this attitude then we also enable ourselves to pressure other jurisdictions to raise their standards to match.

An uncontrolled internet appareny has 1 outcome - malicious spam. That is what everyone in this thread seems to agree on, and the arguments against what I suggest all seem start with the assumption "there is nothing we can do about it" and the corollary "there is nothing we need to do about it"

I think we can actually do something about it, and I think we ought to. But before all of that, I think the first place to start is making a clear legal relationship between security researchers and the private sector and debate the laws that should be in place to facilitate that in a fair way

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#895

Earlier quoted context omitted.

This might be an unpopular opinion but I respectfully do not see it that way. I agree with promoting security for IoT devices, but there needs to be consent from the company being probed for vulnerabilities or else I find it hard to consider it legitimate research, regardless of intent. I dont think anyone would like it very much if someone came to their house and documented all the ways to rob it they could find, ev…

You give up consent for a device to not be scanned the second it is connected to the public internet. There are botnets that are continuously scanning all allocated IP blocks for potentially vulnerable devices - try logging requests to an open 22 port and take a look at the kinds of requests you get. That's the price you pay for connecting to an open world wide network. Now the conduct and what the operators of a mas…

The Ship has not sailed. The ship is still on its way to port. Complete internet surveillance is arguably an unstoppable force on the way to shore.

I think when it gets here there is going to be a lot more trouble for cybersecurity experts due to a lack of clear understanding around what is considered legal activity or not from them. Right now the obscurity is something they hide in - they can choose whether or not to reveal they found a vulnerability.

But what if that's not always the case? What if you get "caught" before you are able to show you had no intentions of doing anything malicious?

We can have the trial by fire we usually do, and let a round of innocent people face unjust consequences and use them as martyrs to create new laws - or we can use some foresight and build some legal frameworks in advance that enable researchers to be "by the book" and not worry at all about legal repercussions

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#896
Thank you for bringing this to our attention and fighting the good fight. This is something that I have been working towards in the Distributed Energy Resource devices space as the DOE and DOD have realized that as more of those devices are connecting to our electric grids the more critical it's become to secure them for the nations security.

The members of the alliance for DER devices have recently started working towards standards and solutions for cybersecurity of their devices which could overlap with what you are trying to do within FCC.

There might be opportunities to collaborate if you see fit.

Best

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#897
post #794

Earlier quoted context omitted.

If it were really unrelated, nobody would pay you to reverse engineer.

Which is why I believe I'm biased: I support releasing source codes, even if it sounds like it's going to reduce my pay.

What I mean is, reverse-engineering takes time, effort, and special talent, hence your job. This is the little security moat they get by not releasing src code, or at least not the latest running version. Of course a well-maintained and audited open-source codebase is better than a closed one, but a lot of this stuff isn't well-maintained.

Also, there are high-profile instances of hardware security that rely on obscurity, like secure enclaves or the iPhone passcode unlock. They tend to get cracked eventually, but it's still hard.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#898
I would also push this onto the soc’s such as espressif, arduino, broadcom, nordic, arm, etc.

They are the ones that provide sdk’s for manufacturers to write firmware with ota firmware updates, flash encryption, secure boot, etc.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#899

Earlier quoted context omitted.

> There is an inherent risk of your vulnerabilities being broadcasted somewhere either on purpose or accidentally once that information is collected and organized by the researcher. A legitimate researcher is going to promptly notify you of any vulnerabilities they discover and you as a large organization are going to promptly remediate them. But the trouble isn't that the law might impose a $100 fine on a smug profe…

I once found a vulnerability. I pressed F12 and saw unintended information in the source of a webpage. I just closed the tab, I didn't report it. Our laws made it risky to do the right thing, so I didn't do the right thing.

I once saw a vulnerability in the same way. Some website from a really powerful org presented masked info, but the info was completely unmasked in the api responses. I’ll never tell anyone. I’m not American and don’t want my payments to suddenly stop settling or visas denied for unknown reasons.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#900

Earlier quoted context omitted.

Part of systemic improvement to security comes from the market forces that reward producers putting out carefully designed and tested products and punish producers that don't. Your suggestion of requiring prior notice, coordination, approval etc. incentivises them to defer the cost of proper development until there is a crisis, so they can rush out any rubbish product, and force users and researchers to do their secu…

I proposed protected legal channels for researchers. It does remove any pressure from companies. Their neck is still on the line. It adds pressure to companies because it creates a paper trail. It enables good faith companies to work with researchers as well. They can even have researchers contact each other if they are both looking into the same thing. There's a lot of good that can come of it Companies can already…

You proposed requiring consent from the producer of a product/service to have their offering probed. And did so with an example of a house not owned by that producer.

If the production company declines, that DOES remove pressure from that company.

Companies that rush out rubbish products can presently be named and shamed by independent, uncooperative or even adversarial researchers. Your proposal considers that research illegitimate unless said dodgy company decides to open itself up to scrutiny, which it obviously would not be inclined to do.

If you want to suggest the market would respond by not selecting products from such an opaque company, look into how many WhatsApp users care about auditable, open source code vs. those using Signal.

Post reply on HN