Live data from Hacker News

White House unveils Cyber Trust Mark program for consumer devices

nextgov.com

21–30 of 164 posts

Re: White House unveils Cyber Trust Mark program for consumer devices

#22

Earlier quoted context omitted.

> They describe it as being like EnergyStar which suggests they'll have a consumer accessible registry I've seen Energy Star logos for 30 years and never knew there was a public database, never thought to verify, and I don't think anyone else has either. The only thing Energy Star has been useful for is extracting rebates from utility companies and buying shitty dishwashers which were certain to be worse than what th…

https://www.energystar.gov/ - Here's the registry. And I'm not saying this will be that useful, just that it's not going to be a sticker and nothing else. That would be truly useless and pretty much just make money for sticker makers.

[deleted]

Re: White House unveils Cyber Trust Mark program for consumer devices

#23

Earlier quoted context omitted.

This has been in the works for a while now. This is not a last minute thing.

[flagged]

At least as early as August 2023. Less than three quarters of the way through his presidency. Something that started at least 17 months ago can hardly be considered "last minute".

EDIT:

Found the answer for you since you can't be bothered (previously saw the date in some other doc reading about this):

https://www.fcc.gov/CyberTrustMark

> When was the U.S. Cyber Trust Mark program created?

>> In August 2023, the FCC sought public comment on how to create the Cyber Trust Mark program. In March 2024, based on public input, we adopted rules establishing the framework for the program.

Re: White House unveils Cyber Trust Mark program for consumer devices

#24
Cool, I'd rather have a stamp that indicates a company will support their product for X number of years, and if they don't, they will release the software as OSS so you can maintain yourself. I have an extremely expensive scale that came with wifi support and an app, only bought it 3 years ago, half the features already don't work because they nuked the app and stopped supporting the scale. did I need a smart scale? Absolutely not, and I don't really need any other "smart" devices the more I think about stuff like this, and now seek to buy "stupid" devices as much as possible. I'm not sure what such security stamps are supposed to provide other than false sense of security, as most things can be hacked eventually with enough determination or someone unknown zero day.

Re: White House unveils Cyber Trust Mark program for consumer devices

#25

Earlier quoted context omitted.

This has been in the works for a while now. This is not a last minute thing.

[flagged]

This is from July 2023: https://www.nextgov.com/cybersecurity/2023/07/white-house-an...

Re: White House unveils Cyber Trust Mark program for consumer devices

#28
This is all well and good. You can have thousands of "mark of approvals", but is the most important item needed required ?

User upgradability if the Company Folds or Sunsets the product. When that happens, the user will need to buy a new device or live with comprised devices. Most will live with the comprised device.

So, IMO, the product should be fully open source and easily upgraded in order to get the Cyber Trust Mark.

Re: White House unveils Cyber Trust Mark program for consumer devices

#29
I'm interested in the actual details here --

1) What are the requirements for the mark? E.g. no passwords stored in plaintext on servers, no blank/default passwords on devices for SSH or anything else, a process for security updates, etc.?

2) Who is inspecting the code, both server-side and device-side?

3) What are the processes for inspecting the code? How do we know it's actually being done and not just being rubber-stamped? After all, discovering that there's an accidental open port with a default password isn't easy.

Re: White House unveils Cyber Trust Mark program for consumer devices

#30
post #20

Things like this are useless, in my mind, because hackers are always going to innovate and find ways around protection mechanisms. Today's "locked down" IoT device could easily become tomorrow's "vulnerable to an easily exploitable pre-auth RCE". What the government probably _should_ do is begin establishing a record of manufacturers/vendors which indicates how secure their products have been over a long period of ti…

Picking and choosing companies like that could work if it could somehow remain apolitical. This registry can work despite the tendency for these things to become political. What you’ve described is maybe more possible if provided by a Consumer Reports-style org that consumers could subscribe to.

Wouldn't it be simpler to have a QR code below the symbol with anything relevant to make this work ?
Post reply on HN