Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

921–930 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#921

IoT devices need regulatory standardization w.r.t a few things: 1. software stack – big fat "firmware" should not exist. Entire stack should be upgradable safely, securely and frequently during its official supported lifetime and should be open-sourced for owner's own upgrades past end of life. For this, the hardware stack needs some amount of standards compliance. 2. Vendor should clearly declare/advertise the perio…

I hate all of these well intentioned ideas, just like I hated when apple forced It also makes it so you can't operate devices in offline networks. (this is already a thing due to apple's cert changes)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#922

Earlier quoted context omitted.

Consumer don't have time, knowledge, or resources to demand all these things they use. When I buy a car, I want it to be safe. I spend zero time evaluating its technology and demanding labels. I already have a job.

That's true. Consumers rely on things like brand name, word of mouth, customer reviews, etc. Another label like this will likely do nothing.

> Another label like this will likely do nothing.

What is the basis of that?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#923
post #763

Earlier quoted context omitted.

A device that is installed in my home but which I do not own is an increased liability on me .

Tampering with a device increases your liability compared to not tampering with it. Don't install it in your home if you don't trust it. Don't buy things with terms and conditions where you dont own the device if you want to own the device. This is a different problem

I have things installed in my home that I don't own. Electric, gas and water meters. The common factor with all of those is that their liability also remains on their respective utility provider companies.

You do not get to retain ownership and transfer liability. It's that simple. If you insist that you own the device, then YOU are fully liable for it.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#924

Earlier quoted context omitted.

You give up consent for a device to not be scanned the second it is connected to the public internet. There are botnets that are continuously scanning all allocated IP blocks for potentially vulnerable devices - try logging requests to an open 22 port and take a look at the kinds of requests you get. That's the price you pay for connecting to an open world wide network. Now the conduct and what the operators of a mas…

The Ship has not sailed. The ship is still on its way to port. Complete internet surveillance is arguably an unstoppable force on the way to shore. I think when it gets here there is going to be a lot more trouble for cybersecurity experts due to a lack of clear understanding around what is considered legal activity or not from them. Right now the obscurity is something they hide in - they can choose whether or not t…

I just don't think that sending port scans to random internet addresses is a big violation of privacy, or undue conduct for a government to participate in. Having your connection details public is the price you pay for connecting to the internet. If you don't like it, than run a private network and firewall the ports on your gateway - the default behavior of all consumer routers.

Quite simply, you will absolutely get portscanned if you have a port open to the public internet today. Try it. No doubt CIA has access to at least some of those botnets. We need policy protections that face the reality of the world we live in today, and harden devices that would like to communicate over the internet in an automated fashion. That includes punishments for operating massive, systemic botnets, but also some auditing of critical infrastructure that is publicly accessible.

For all their problems, certificate authorities have largely let us figure this stuff out on the internet browser side, and I would argue that has had a positive effect on privacy and security. Now it is time to do something similar for devices that connect to the internet in an automated way. For all it's

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#925

Earlier quoted context omitted.

By default, no telemetry. NO DATA OUT OF MY HOUSE WITHOUT EXPLICIT PERMISSION.

Out of curiosity, in what context has IoT telemetry been meaningful to the consumer? In other words, what data has been gathered that can be sold or otherwise abused? I personally don't see a reason to be concerned about a manufacturer wanting to track which features are being used and how those features are being used.

Yea, totally OK except they have to ask me first.

Telemetry has huge implications and it can be literally anything. Photos captured by a webcam can be “telemetry”, manf can always say we were verifying our image sensor calibration.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#926

Earlier quoted context omitted.

Do you think your mother, your uncle, your niece, your sister would do the same? I don't really buy that even 1% of the consumers will care about this label to the point of voting with their wallet on that basis.

That's great, then this proposal has _no harm_. Manufacturers that believe the same thing as you can just opt to forego placing the FCC's mark on their packaging. We can just test the theory in the marketplace. If you and those manufacturer's suspicion is correct, then the mark will just fall by the wayside unused. The only way manufacturers could be harmed by the requirements to obtain this mark is if consumers _do…

It points to the question of why they would go for something so meek when they have the power to be effective. If the FCC displays submissiveness to the markets they're supposed to regulate then I want a reason for it, because I'm worried they're in some guy's pockets

Second issue is a cybersecurity label from a trusted source is already something that can be issued, by, say, the ISO consortium. You don't need the FCC to do that.

Third issue is while the FCC is doing that, they're not doing something else.

Fourth issue is while they're not doing something that works, the consumer still faces the issues that this was supposed to solve!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#927
post #788

Earlier quoted context omitted.

A competent technician with access to a workshop can make even 80 year old vehicles work. That is long past the service life of that vehicle but it can still be done, an iteration of the same technology is likely still in use today though in your car. That isn't possible for software simply because reverse engineering is not simple, reverse engineering a small microcontrollers firmware might be possible, reverse engi…

>That isn't possible for software simply because reverse engineering is not simple Nor is repairing a car. It is not as hard as you think to RE some random IoT device firmware.

Is it "Here's a manual and a pile of tools, follow the instructions" hard?

Most maintenance on vehicles is exactly that.

The smart fridge that has a buffer overflow leading to RCE cannot be fixed quite a easily as as replacing the brakes on my car, neither is easy but one of those a monkey with a spanner could figure out eventually.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#928

Earlier quoted context omitted.

I think a better analogy can be drawn by just considering the physical version of some things. For IoT, you can say if someone discovers a specific brand of physical lock can be broken in unexpected ways, they should be allowed to communicate this in a way that benefits the users of the lock without facing any legal risk. For internet banking, you can discuss a physical vault that safekeeps everyone's gold, and say t…

Well, in this analogy the problem starts with how the person is noticing the lock can be broken in unexpected ways Everything you said after that is a valid continuation from that, but the scope of the issue I am talking to centers around that how. Because locks have never actually been unbreakable, right? The main purpose of a lock, the generally accepted way that the lock keeps people out - is by existing, not by b…

What happens in that case is said tinkerer does it anyway.

And say they got that door by any of a number of legal means. Fact is they have it and could have a wide range of legal uses for said door too.

Is it better to drive that sort of thing underground?

I question that.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#929
post #545

Earlier quoted context omitted.

The problem here is that the thing I am probing is something I own: the device in my house that I ostensibly purchased and am allowed to smash with a hammer or put in a blender for all anyone should care; the context is that the DMCA is often used by companies to claim that DRM on the device is there to protect copyrights--whether music the device had access to, even if it isn't the reason many or even most people bu…

I hate it too, but the heart of this is that ownership is under question. People should not have agreed to buy things where there are parts of it they don't own that they don't even need, but they did. They did it a lot because it didn't matter to them and now those devices are prevalent everywhere and it's a PITA to try to buy the type of item you actually want - where you own it entirely. Ownership has never actual…

>People should not have agreed to buy things where there are parts of it they don't own that they don't even need, but they did.

I own zero IoT devices for the exact reasons you gave.

Frankly, I would prefer to change that state of affairs. I would also prefer far less waste. Tons of these devices end up in the garbage too. That is unacceptable and surely not sustainable.

I am not OK with partial ownership, unless there are clear obligations attached to the other partial owner that have real teeth.

Fact is we have law for this case and that is the rental agreement. That is exactly what partial ownership is.

And when people are asked to value something they will be renting, everything changes. A big change is purchase price. That goes down.

What I see happening is IoT companies business model is priced as if ownership happens when it really doesn't. And that is not OK.

I also find putting that onto people disturbing because it was not the people who who made the choice to advertise a sale and then act as if it is a rental.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#930

Earlier quoted context omitted.

>Please do not propose this regulation. If consumers actually cared about their IoT devices receiving security updates, companies would be doing it. The fact that companies are not already doing this is evidence it's not important to consumers. People may express frustration, but their purchasing behavior speaks louder than their words. In 1980 11% of American adults used automobile seat belts.

I support individual's choice of whether or not take personal safety measures.

As do I.

However, I'm also pretty happy that NHTSA mandated seatbelts be included in cars despite the fact that they were wildly unpopular.

Post reply on HN