There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…
Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
901–910 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#902Earlier quoted context omitted.
right, so then people will not buy your product because you don’t have the label and you cannot afford to pay 10K-20K to some testing lab while vc backed startups or big tech can… so it takes away any chance for you as a small guy to compete in the market. no thanks.
I don't see why a small shop can't do this. The testing should be supported by the government. You don't need to be a food scientist to get FDA approval to sell a cookie.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#903How is a small business going to be able to pay for this? This will be something that big tech can do but not startups that are bootstrapped.
This is being proposed as a completely voluntary program. No need to participate in it if you don't want an FCC cybersecurity label on your product.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#904[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…
> Please do not propose this regulation. If consumers actually cared about their IoT devices receiving security updates, companies would be doing it. The fact that companies are not already doing this is evidence it's not important to consumers. People may express frustration, but their purchasing behavior speaks louder than their words. Or, maybe, companies are exploiting consumer ignorance and we're not dealing wit…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#905[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…
>Please do not propose this regulation. If consumers actually cared about their IoT devices receiving security updates, companies would be doing it. The fact that companies are not already doing this is evidence it's not important to consumers. People may express frustration, but their purchasing behavior speaks louder than their words. In 1980 11% of American adults used automobile seat belts.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#906[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…
"The fact that companies are not already doing this is evidence it's not important to consumers. People may express frustration, but their purchasing behavior speaks louder than their words." I would like to see evidence before anyone accepts this premise as true. That's like saying smokers don't care about lung cancer, or parents don't care about lead in baby toys, as shown by their purchase behavior. Security updat…
They may care about "about lung cancer" and other aspects of the product, but they make trade-offs.
Consumers are ignorant about many aspects of the products they use. I do not trust politicians to somehow know what those asymmetries are and divine what our true preferences are.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#907[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…
> If consumers actually cared about their IoT devices receiving security updates, companies would be doing it. I don't think this is true. Security issues don't matter until they do , and consumers -- by which I mean "people" -- are notoriously bad at estimating risk for sufficiently rare outcomes. To take a common example, insecure internet-connected baby monitors can literally give strangers video access to your ho…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#908[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…
> If consumers actually cared about their IoT devices receiving security updates, companies would be doing it. This seems like a crazy response to me. The _entire_ program is _voluntary_. If a manufacture doesn't want to jump through any hoops the only downside is that they don't get an "FCC cybersecurity" label on it. So if the customers _actually_ don't care, then don't do the program and don't get the sticker on t…
> Customers _want_ to purchase more secure products but do not have the option, and do not have the information required to do so.
Again, if customers really were demanding this, why haven't these greedy corporations provided the service already?
If I'm wrong, then there's an market opportunity that I hope an entrepreneur will take advantage of.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#909[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…
If you ask an average consumer about their IoT devices' security updates their eyes will glaze over. I imagine the average car buyer in the 1950s would react the same way to talk of "crumple zones." Consumers absolutely need to be protected from corporate negligence here.
I agree. They don't care.
If anything, consumers need to be protected from predatory politicians claiming to serve the public interest.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#910[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…
I don't think customers not caring is a valid reason to not do this. Compromised IoT devices don't only cause harm to their owners, but also external networks and the internet as a whole. A compromised doorbell, or lightbulb etc can be used as part of a botnet to perform DDoS attacks or other nasty activities. An analogy is like saying we shouldn't work on reducing the pollution emmitted by motor vehicles because the…
Something to keep in mind though, government regulation itself is an externality.