Live data from Hacker News

White House unveils Cyber Trust Mark program for consumer devices

nextgov.com

11–20 of 164 posts

Re: White House unveils Cyber Trust Mark program for consumer devices

#11
post #7

The combined requirements of govt purchasing must carry the mark and major US surveillance tech manufacturers like Amazon are leading the rollout, makes this seem less like a cybersecurity concern and more of a protectionist carve out.

[flagged]

Re: White House unveils Cyber Trust Mark program for consumer devices

#12
post #7

The combined requirements of govt purchasing must carry the mark and major US surveillance tech manufacturers like Amazon are leading the rollout, makes this seem less like a cybersecurity concern and more of a protectionist carve out.

[flagged]

This has been in the works for a while now. This is not a last minute thing.

Re: White House unveils Cyber Trust Mark program for consumer devices

#13
Interesting. I'm not sure if the public comment period is over (The original proposal is dated August, 2023), but this stands out to me from their paper:

    We propose to focus the scope of our program on intentional radiators that generate and emit RF energy by radiation or induction.31 Such devices – if exploited by a vulnerability – could be manipulated to generate and emit RF energy to cause harmful interference. While we observe that any IoT device may emit RF energy (whether intentionally, incidentally, or unintentionally), in the case of incidental and unintentional radiators, the RF energy emitted because of exploitation may not be enough to be likely to cause harmful interference to radio transmissions.
I guess it is the FCC so this makes sense from their point of view. From my perspective, I'd like to see marks indicating:

* If the devices can be pointed to an alternate API provider if the company stops supporting

* If firmware has been escrowed / will be made available if the company stops supporting

* If device data is stored by the company

* If that data is certified as end to end encrypted

* Some marks for who / how the data is used

Re: White House unveils Cyber Trust Mark program for consumer devices

#14
post #4

Digging for more details, but a lot of the technical requirements (e.g. encryption, password handling, etc.) are still unclear. https://www.fcc.gov/CyberTrustMark

"Which products will be included in the program? The program applies to consumer wireless IoT products.

Examples of eligible products include internet-connected home security cameras, voice-activated shopping devices, smart appliances, fitness trackers, garage door openers, and baby monitors."

Ok, nothing I use then. I hope this comes to home and SMB network gear.

Re: White House unveils Cyber Trust Mark program for consumer devices

#15
post #7

The combined requirements of govt purchasing must carry the mark and major US surveillance tech manufacturers like Amazon are leading the rollout, makes this seem less like a cybersecurity concern and more of a protectionist carve out.

Laser safety glasses in Amazon are so fake anyone could come up with a conspiracy theory about some country trying to blind the population of another.

Re: White House unveils Cyber Trust Mark program for consumer devices

#17
Things like this are useless, in my mind, because hackers are always going to innovate and find ways around protection mechanisms. Today's "locked down" IoT device could easily become tomorrow's "vulnerable to an easily exploitable pre-auth RCE".

What the government probably _should_ do is begin establishing a record of manufacturers/vendors which indicates how secure their products have been over a long period of time with an indication of how secure and consumer-friendly their products should be considered in the future. This would take the form of something like the existing travel advisories Homeland Security provides.

Should you go to the Bahamas? Well, there's a level 2 travel advisory stating that jet ski operators there get kinda rapey sometimes.

Should you buy Cisco products? Well, they have a track record of deciding to EOL stuff instead of fixing it when it's expensive or inconvenient to do the right thing.

Should you buy Lenovo products? Well, they're built in a country that regularly tries and succeeds in hacking our infrastructure and has a history of including rootkits in their laptops.

Re: White House unveils Cyber Trust Mark program for consumer devices

#18
post #3

What's to stop the bad actors from just printing the logo on their gear anyways? Like they do with UL and N95?

They describe it as being like EnergyStar which suggests they'll have a consumer accessible registry as described here: https://www.ul.com/news/ul-solutions-named-lead-administrato... > UL Solutions will also work with the FCC and program stakeholders to develop a national registry of certified products that consumers can access via QR code on the label. The registry will have more detailed information about each pro…

> They describe it as being like EnergyStar which suggests they'll have a consumer accessible registry

I've seen Energy Star logos for 30 years and never knew there was a public database, never thought to verify, and I don't think anyone else has either. The only thing Energy Star has been useful for is extracting rebates from utility companies and buying shitty dishwashers which were certain to be worse than what they were replacing.

Verification is useless if no one knows about it, or if the data isn't actionable. I have verified UL mark numbers for questionable products, but they often resolve to some Chinese ODM you've never heard of like 'Xionshang Industrial Electric Company' whose name certainly doesn't match the product label. Do you know the components haven't been swapped out since certification was achieved? Was the product actually sourced from there or counterfeit? You have no way to verify any of that.

UL issues holographic stickers but I've seen those like 10% of the time and probably just as easily faked.

Re: White House unveils Cyber Trust Mark program for consumer devices

#19

Earlier quoted context omitted.

They describe it as being like EnergyStar which suggests they'll have a consumer accessible registry as described here: https://www.ul.com/news/ul-solutions-named-lead-administrato... > UL Solutions will also work with the FCC and program stakeholders to develop a national registry of certified products that consumers can access via QR code on the label. The registry will have more detailed information about each pro…

> They describe it as being like EnergyStar which suggests they'll have a consumer accessible registry I've seen Energy Star logos for 30 years and never knew there was a public database, never thought to verify, and I don't think anyone else has either. The only thing Energy Star has been useful for is extracting rebates from utility companies and buying shitty dishwashers which were certain to be worse than what th…

https://www.energystar.gov/ - Here's the registry.

And I'm not saying this will be that useful, just that it's not going to be a sticker and nothing else. That would be truly useless and pretty much just make money for sticker makers.

Re: White House unveils Cyber Trust Mark program for consumer devices

#20

Things like this are useless, in my mind, because hackers are always going to innovate and find ways around protection mechanisms. Today's "locked down" IoT device could easily become tomorrow's "vulnerable to an easily exploitable pre-auth RCE". What the government probably _should_ do is begin establishing a record of manufacturers/vendors which indicates how secure their products have been over a long period of ti…

Picking and choosing companies like that could work if it could somehow remain apolitical. This registry can work despite the tendency for these things to become political.

What you’ve described is maybe more possible if provided by a Consumer Reports-style org that consumers could subscribe to.

Post reply on HN