Earlier quoted context omitted.
> This support is expensive Most of IoT is that way. We had sales cycles that were 2-3 years long and they would in the end buy 300 units. I then go back to my suppliers and say 'hey support these 500 ic's that you sold me for 10 years from right now' They would laugh me out of the room unless I am showing up with big bags of cash. That instantly makes the whole project unviable to sell/support.
Yes, absolutely. This is the exact conditions of most of our higher-end products (500-1000 units sold of a particular configuration is common). It's funny to get laughed out of the room even asking some chipmakers "can you sell us 1000 parts, please?"
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
931–940 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#932Earlier quoted context omitted.
Tampering with a device increases your liability compared to not tampering with it. Don't install it in your home if you don't trust it. Don't buy things with terms and conditions where you dont own the device if you want to own the device. This is a different problem
I have things installed in my home that I don't own. Electric, gas and water meters. The common factor with all of those is that their liability also remains on their respective utility provider companies. You do not get to retain ownership and transfer liability. It's that simple. If you insist that you own the device, then YOU are fully liable for it.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#933Earlier quoted context omitted.
I proposed protected legal channels for researchers. It does remove any pressure from companies. Their neck is still on the line. It adds pressure to companies because it creates a paper trail. It enables good faith companies to work with researchers as well. They can even have researchers contact each other if they are both looking into the same thing. There's a lot of good that can come of it Companies can already…
You proposed requiring consent from the producer of a product/service to have their offering probed. And did so with an example of a house not owned by that producer. If the production company declines, that DOES remove pressure from that company. Companies that rush out rubbish products can presently be named and shamed by independent, uncooperative or even adversarial researchers. Your proposal considers that resea…
In this thread I expanded the detail to include the system to do this could (and imo should) be a legal framework that creates effective communication between companies and researchers.
I also try to adapt my language to try to parallel what the person I'm speaking with is trying to say, rather than telling them they didn't mean what they are telling me they meant. I apologize if created a misunderstanding with my word choice.
Yes I did mention requiring consent from the company as the ideal goal of the model. I am not suggesting the implementation of the model full stop at that just that sentence. In other areas of law, if you can prove a message was received by a company that can sometimes be considered implied consent if they do not respond to it.
We can also require that companies cannot simply refuse for no reason, but leave legal room here for any legitimate reasons to deny should they exist.
And so on and so forth.
It makes the intent of the researcher very clear.
Declining is obviously less pressure for the company in this situation, I agree. But it is not less pressure compared to the current situation. Companies currently have no obligations at all to researchers, and they certainly do not build security out of concern that white hat hackers will out them. They fear black hat hackers. Those are not going away, and if a legal framework exists for companies to work with researchers and better arrange fair conditions for both sides, I would bet companies will be MORE willing to allow research than less.
Because right now they company gets the research for free and then gets to decide whether or not they want to throw the researcher a Starbucks gift card or not. Or just press charges because they are assholes.
I dont really care what the market decides to do. The point of this is to protect the researchers regardless of what the market does. Because to your point, the market has already chosen poorly which is why we have issues on this subject to begin with.
Does this clarify my stance?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#934Earlier quoted context omitted.
If they bought a prefab house which was sold to many people in the neighborhood, and part of the terms and conditions were do not open up the walls, and the owner opened up all the walls to find out weakspots it can be robbed, then that does seem criminal, no? However, the owner should still have a right to validate the security of his house - so he should be able to request for permission to break the terms of his c…
At present, I'm not sure it's actually possible to sell someone a house with terms like that, since it would interfere with ordinary, even essential aspects of maintaining a liveable dwelling. It does highlight the oddity of the situation we are in with many IoT devices.
Sticking with the example, there is not reason a company cannot have terms that you can't open the walls, while the state also has laws that regardless of what the terms are - you are allowed to open the walls for maintenence purposes, renovations, etc, but maybe you have to notify the company about what you are doing.
It feels like territory somewhere in between the complete freedom of ownership and the total lockdown of renting.
I'd imagine there is a whole legal tug of war that would need to happen to know where the lines would or should fall, but the main point is that both sides are at the table and no one needs to be keeping their activity in the dark because of how uncertain they are about how the law is going to treat them
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#935Earlier quoted context omitted.
The Ship has not sailed. The ship is still on its way to port. Complete internet surveillance is arguably an unstoppable force on the way to shore. I think when it gets here there is going to be a lot more trouble for cybersecurity experts due to a lack of clear understanding around what is considered legal activity or not from them. Right now the obscurity is something they hide in - they can choose whether or not t…
I just don't think that sending port scans to random internet addresses is a big violation of privacy, or undue conduct for a government to participate in. Having your connection details public is the price you pay for connecting to the internet. If you don't like it, than run a private network and firewall the ports on your gateway - the default behavior of all consumer routers. Quite simply, you will absolutely get…
There would still be upside of potentially addressing the scan spam as well, though
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#936Earlier quoted context omitted.
> You can't give them a slap on the wrist if you assert what they are doing isn't criminal. Having an issue with the punishment model is no reason to throw out the law. The law is too broad in addition to being too punitive. But here's an argument for throwing it out entirely. There are two kinds of people who are going to spot a vulnerability in someone else's service: Amateurs and professionals. Professionals expec…
I think you're getting way ahead of the conversation, and there is no way to know what the implementation would be like and how communication would go between researchers and companies because if you can think of the communication problem today, then we can consider a solution for that problem in the implementation tomorrow. At the end of the day, I am arguing for promoting people to try to work with companies, and t…
A major problem is that communicating with a large bureaucracy, even to just find a way to contact someone inside of it who will know what you're talking about, is a significant time commitment. So you're not going to do it just because you think you might see something, and as soon as you add that requirement it's already over.
You might try to require corporations to have a published security contact, but large conglomerates, especially the incompetent ones, are going to implement this badly. In many cases the only effective way to get their attention is to embarrass them in public by publishing the vulnerability.
> You (and others) propose we make hacking into systems fully legal, presumably because we can target malicious activity based on what they do with that access instead of the access itself. Is that correct?
So one of the existing problems is that it's not always even obvious what is and isn't authorized. Clearly if you forget your password to your own PC but you can find a way to hack into it, it should be legal for you to do this and recover your data. What if the same thing happens, but it's your own VM on AWS? What if it's your webmail account, and all you use it for is to recover your own account? You made an API call with a vulnerability that allows you to change your password without providing the old one, but you are authorized to change your own password.
There are many vulnerabilities that result from wrong permissions. You to go the service and ask for some other customer's account page and instead of prompting for a login or coming back with "401 UNAUTHORIZED" their server says "200 OK" and gives you the data. Is that "unauthorized access"? What do you even use to determine whether you're supposed to have access, if their server says that you do?
This kind of ambiguity is poisonous in a law, so the best way to resolve it is to remove it. Punish malicious activity rather than trying to subjectively evaluate ambiguous authorization. It doesn't matter whether their server said "200 OK" if you're using the data to commit identity theft, because identity theft is independently illegal. Whereas if you don't actually do anything bad (i.e. violation of some other law), what need is there to punish it?
> I also disagree that a ban is equivalent to shooting an intruder. The connection is not the actor, the person using it is.
The justification for being able to shoot an intruder is not to punish them, it's self-defense. Guess what happens if you tie them up first and then shoot them.
You don't need to physically destroy someone to defend yourself when all they're doing is transferring data. All you have to do is block their connections.
> If we formally adopt this attitude then we also enable ourselves to pressure other jurisdictions to raise their standards to match.
The reason other jurisdictions don't punish this isn't that no one is setting a positive example. It's that their governments have no resources for enforcement or are corrupt and themselves profiting from the criminal activity whose victims are outside of their constituency.
Or if you're talking about the jurisdictions who do the same thing as the US does now, it's because their corporations don't like to be embarrassed either, and we could just as well set the example that the best way to avoid being humbled is to improve your security practices.
> I think the first place to start is making a clear legal relationship between security researchers and the private sector and debate the laws that should be in place to facilitate that in a fair way
Companies will want to try to retain the ability to threaten researchers who embarrass them so they can maintain control over the narrative. But that isn't a legitimate interest and impairs their own security in order to save face. So they should lose.
The embarrassment itself is a valuable incentive for companies to get it right from the start and avoid the PR hit. Nothing should allow them to be less embarrassed by poor security practices and if anything cocksure nerds attempting to break into public systems for the sole purpose of humiliating major organizations should be promoted and subsidized in the interest of national security. (It's funny because it's true.)
> An uncontrolled internet appareny has 1 outcome - malicious spam. That is what everyone in this thread seems to agree on, and the arguments against what I suggest all seem start with the assumption "there is nothing we can do about it" and the corollary "there is nothing we need to do about it"
It's not that there is nothing we can do about it. It's that imposing criminal penalties on the spammers isn't going to work if they're on another continent, and correspondingly isn't a productive thing to do whenever it has countervailing costs of any significance at all.
You can still use technical measures. Email from an old domain with a long history of not sending spam and all the right DNS records, probably isn't spam. Copies of near-identical but never before seen messages to a thousand email addresses from a new domain, probably spam.
You can also retaliate in various ways, like stealing back the cryptocurrency they scammed out of people by using your own exploits.
What you can't do is prevent Nigerians from running scams from Nigeria by punishing innocuous impudence in the United States.
And one of the best things we can do is improve the security of our own systems, so they can't be exploited by malicious actors we have no effective means to punish. Which the existing laws are misaligned with, because improving security is more important than imposing penalties.
I'm much reminded of the NTSB approach to plane crashes: It's more important to have the full cooperation of everyone involved so you can identify the cause and prevent it from happening again, than to cause everyone to shut up and lawyer up so they can avoid potential liability.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#937Disclaimer: I've developed and consumed firmware of multiple categories of products except for military and aerospace.
The easiest system to model is the automotive industry: recalls & TSBs. But don't consume CVEs directly (optional / weak link) because they don't necessarily mean anything.
::Policywonking braindump ahead::
1. Device updates
1.a. Should be enumerable using simple metadata AND
1.b.i. Have a canonical, simple, and fixed URI address website with static content website following accessibility guidelines AND/OR
1.b.ii. Similarly provide updates as static content via HTTP GET requests from a stable, stateless API.
i.b.iii. Unsecured conventional FTP shall be prohibited as an insecure and obsolete technology.
1.c. Device updates shall not be hindered by stateful, conditional access such as logins or CSRF tokens.
1.d. There shall be machine- and user-accessible checksums of all firmware files.
1.e. Optionally, there can be cryptographic signatures of the firmware files themselves (NOT THE CHECKSUM FILES).
1.f. Past updates shall be made available in perpetuity at a fixed URI address.
2. EOL devices: Shouldn't disable themselves. Should be repurpose-able, retaining significant functionality.
3. EOL API services: There should be open sourcing of source or binary installations of server APIs to facilitate repurposing of devices.
3.a. AND a final firmware update to permit changing the URI or DNS address of the API service to facilitate hardware reuse.
4. Paid security updates: It should be expressly forbidden to extort money from users for security updates like Schneider Electric Global (née APC) is now doing to users.
5. Login with (brand): If using first- or third-party credentials to login with a provider, it should use OAuth and SAML.
6. Manual password logon: salted password hashing using PBKDF2, scrypt, bcrypt, or argon2 should be REQUIRED.
7. Default password:
7.a. the default password should either be common OR randomly assigned to each article
7.b AND changed on first use.
8. Remote logon
8.a. If using remote logon, ssh version 2 should be required.
8.b. Telnet should be forbidden as an obsolete and insecure technology.
8.c. Optionally provide a simple manner to disable remote logon, preferably disabled by default.
9. Unique identifier labeling.
9.a. The WiFi/Ethernet MAC address, bluetooth address, or WWN of the device shall be printed on the exterior
9.b. in a manner that is clearly visible with 20/40 eyesight without aid of magnification.
9.c. It SHALL NOT be printed on a removable label.
10. IOT service APIs.
10.a. Should use ordinary technologies, be stable, and function as per documentation.
10.b. Provide a test API with a simulated virtual device.
10.c. Be of minimal cost to use.
10.d. Documentation
10.d.i. Should be published to a static content website that conforms to accessibility guidelines.
11. Telemetry and analytics
11.a. It shall be prohibited without affirmative, opt-in consent to transmit, to any first- or third-party, the following for purposes not strictly necessary for functionality:
11.a.i. Location, position, or geographic region.
11.b.ii. System, bus, network addresses, or identifiers, including but not limited to: Ethernet MAC, WWN, IPv4, IPv6, Bluetooth, Thread, Z-Wave, ZigBee, USB, PCIe, I2C, JTAG.
11.c.iii. Content or metadata of network packets or data EITHER not intended for the device OR not required for interoperability with connected devices. "Connected devices" have a prior, affirmative relationship opted-in by the user explicitly OR are widely-known to automatically configure themselves to associate trust with each other.
11.b.iii. Audio or visual recordings.
11.c.iv. Personal details such as legal name or nickname, postal or physical address, email address, telephone number.
11.c.v. Personal information such as contacts, notes, photographs, videos, audio recordings, browser history, miscellaneous user-generated files, or files known to contain unprotected secrets such as passwords or tokens.
12. Hard reset.
12.a. There should be a simple manner to clear all "data" (personal, state, configuration, and other data) from a device to restore it similar to factory setting.
12.b. The hard reset process MUST EXPLICITLY overwrite all types of data to make it permanently unretrievable.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#938I think that IOT device manufacturers should be required to support their device for some minimum period of time AND be obligated to release the full source code for the device once they decide to end support. This also requires releasing the keys to any firmware signing mechanism or publishing a firmware update that removes such checks. The core problem is that without control of the firmware, consumers don't really…
>AND be obligated to release the full source code for the device once they decide to end support. This is unreasonable. Code is often reused in the next generation of a product. The company may not have the rights to release all of the code.
Manufacturing millions of widgets that go into the garbage every three years is bad and should carry heavy consequence. If the company isn't willing to support the devices they sell, it should be possible for consumers to do it.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#939I think that IOT device manufacturers should be required to support their device for some minimum period of time AND be obligated to release the full source code for the device once they decide to end support. This also requires releasing the keys to any firmware signing mechanism or publishing a firmware update that removes such checks. The core problem is that without control of the firmware, consumers don't really…
This is great for hackers but doesn't it make IoT devices incredibly insecure for normal users who wouldn't even know their device has reached end of support?
The vulnerabilities exist and will be exploited either way. But with source available, we now have the possibility of a whitehat group springing up to patch them.
Would you rather have no chance of ever patching exploits or giving people the ability to patch them?