Earlier quoted context omitted.
[flagged]
This has been in the works for a while now. This is not a last minute thing.
White House unveils Cyber Trust Mark program for consumer devices
21–30 of 164 posts
Re: White House unveils Cyber Trust Mark program for consumer devices
#22Earlier quoted context omitted.
> They describe it as being like EnergyStar which suggests they'll have a consumer accessible registry I've seen Energy Star logos for 30 years and never knew there was a public database, never thought to verify, and I don't think anyone else has either. The only thing Energy Star has been useful for is extracting rebates from utility companies and buying shitty dishwashers which were certain to be worse than what th…
https://www.energystar.gov/ - Here's the registry. And I'm not saying this will be that useful, just that it's not going to be a sticker and nothing else. That would be truly useless and pretty much just make money for sticker makers.
Re: White House unveils Cyber Trust Mark program for consumer devices
#23Earlier quoted context omitted.
This has been in the works for a while now. This is not a last minute thing.
[flagged]
EDIT:
Found the answer for you since you can't be bothered (previously saw the date in some other doc reading about this):
https://www.fcc.gov/CyberTrustMark
> When was the U.S. Cyber Trust Mark program created?
>> In August 2023, the FCC sought public comment on how to create the Cyber Trust Mark program. In March 2024, based on public input, we adopted rules establishing the framework for the program.
Re: White House unveils Cyber Trust Mark program for consumer devices
#24Re: White House unveils Cyber Trust Mark program for consumer devices
#25Earlier quoted context omitted.
This has been in the works for a while now. This is not a last minute thing.
[flagged]
Re: White House unveils Cyber Trust Mark program for consumer devices
#26Earlier quoted context omitted.
This has been in the works for a while now. This is not a last minute thing.
[flagged]
Re: White House unveils Cyber Trust Mark program for consumer devices
#27Re: White House unveils Cyber Trust Mark program for consumer devices
#28User upgradability if the Company Folds or Sunsets the product. When that happens, the user will need to buy a new device or live with comprised devices. Most will live with the comprised device.
So, IMO, the product should be fully open source and easily upgraded in order to get the Cyber Trust Mark.
Re: White House unveils Cyber Trust Mark program for consumer devices
#291) What are the requirements for the mark? E.g. no passwords stored in plaintext on servers, no blank/default passwords on devices for SSH or anything else, a process for security updates, etc.?
2) Who is inspecting the code, both server-side and device-side?
3) What are the processes for inspecting the code? How do we know it's actually being done and not just being rubber-stamped? After all, discovering that there's an accidental open port with a default password isn't easy.
Re: White House unveils Cyber Trust Mark program for consumer devices
#30Things like this are useless, in my mind, because hackers are always going to innovate and find ways around protection mechanisms. Today's "locked down" IoT device could easily become tomorrow's "vulnerable to an easily exploitable pre-auth RCE". What the government probably _should_ do is begin establishing a record of manufacturers/vendors which indicates how secure their products have been over a long period of ti…
Picking and choosing companies like that could work if it could somehow remain apolitical. This registry can work despite the tendency for these things to become political. What you’ve described is maybe more possible if provided by a Consumer Reports-style org that consumers could subscribe to.