Earlier quoted context omitted.
Looks like you just have not deal with bad traders on platforms. I once found on local aggregator product too cheap to be good (unfortunately at that moment only two stores sell these product). I stored their number in my notebook and going to my shopping, calling them from bus stop, and they answered me some nonsense. I made my shopping, and some walk, then opened platform and these shops already disappear. Less tha…
Sorry my post was sarcasm. If English is a second language I can see where that could be lost in translation. I don't expect any of these vendors, especially Amazon 3rd party, to check.
White House unveils Cyber Trust Mark program for consumer devices
51–60 of 164 posts
Re: White House unveils Cyber Trust Mark program for consumer devices
#52The combined requirements of govt purchasing must carry the mark and major US surveillance tech manufacturers like Amazon are leading the rollout, makes this seem less like a cybersecurity concern and more of a protectionist carve out.
Laser safety glasses in Amazon are so fake anyone could come up with a conspiracy theory about some country trying to blind the population of another.
Re: White House unveils Cyber Trust Mark program for consumer devices
#53What's to stop the bad actors from just printing the logo on their gear anyways? Like they do with UL and N95?
They describe it as being like EnergyStar which suggests they'll have a consumer accessible registry as described here: https://www.ul.com/news/ul-solutions-named-lead-administrato... > UL Solutions will also work with the FCC and program stakeholders to develop a national registry of certified products that consumers can access via QR code on the label. The registry will have more detailed information about each pro…
Re: White House unveils Cyber Trust Mark program for consumer devices
#54Earlier quoted context omitted.
The vendor is supposed to check I think. Not that that makes sense in a comingling inventory world.
I'm sure Amazon - whose store is mostly generic Chinese schlock nowadays - will check. Not that it matters, posters on this very site who claim to care will continue buying stuff off AliExpress, proud they got it for pennies on the dollar. Look ma, a mini PC for $22! And they didn't even charge for the preinstalled malware! Has anyone ever considered this junk is sold at a loss as a price of doing business, to expand…
Re: White House unveils Cyber Trust Mark program for consumer devices
#55What's to stop the bad actors from just printing the logo on their gear anyways? Like they do with UL and N95?
> What's to stop the bad actors from just printing the logo on their gear anyways? This is federal offense, like document falsification. So if somebody will be caught on doing it - could go to jail.
Re: White House unveils Cyber Trust Mark program for consumer devices
#56Interesting. I'm not sure if the public comment period is over (The original proposal is dated August, 2023), but this stands out to me from their paper: We propose to focus the scope of our program on intentional radiators that generate and emit RF energy by radiation or induction.31 Such devices – if exploited by a vulnerability – could be manipulated to generate and emit RF energy to cause harmful interference. Wh…
You might be getting a bit too far ahead of where the industry is at with some of those wishlist items. NIST's requirements are things that are best practices that everyone agrees with, like: * data stored/transmitted is secured by some kind of means * the device supports software updates * the device requires users to authenticate * the device has documentation * you can report security vulnerabilities to the develo…
'Cause they need somewhere to load in those exploits!
A hypothetical device which is all read-only (except perhaps for a very carefully crafted, limited set of configurable parameters) might in some cases be more secure than the bulk of what's on the shelves today. After all, how many widespread hacks do you read about on old, single-purpose fixed analog or digital devices (which in a sense are similarly 'read-only').
Re: White House unveils Cyber Trust Mark program for consumer devices
#57I'd still put my faith in other indicators like a company's track record, third party audits, robustness of open source library choices where applicable, my own analysis of their stack and engineering choices based on signs I can observe about their product / interface / etc (there are usually several present), my own testing and so forth.
I'd argue the generally accepted pace of consumer product development these days is reckless, and not sustainable if you want truly robust results.
I would have been glad to see this step in the right direction if I weren't convinced all it will likely amount to in practice is security theatre. Here's hoping my skepticism is unwarranted.
Re: White House unveils Cyber Trust Mark program for consumer devices
#58Things like this are useless, in my mind, because hackers are always going to innovate and find ways around protection mechanisms. Today's "locked down" IoT device could easily become tomorrow's "vulnerable to an easily exploitable pre-auth RCE". What the government probably _should_ do is begin establishing a record of manufacturers/vendors which indicates how secure their products have been over a long period of ti…
NIST isn't a bunch of dummies that don't know this. The requirements posed are not micromanagement of device design; some address your concern exactly... like a requirement that developers provide contact information to report vulnerabilities and that devices makers just can't ignore authentication entirely. But this is IoT stuff we're talking about here, not Lenovo/Cisco... but ReoLink/PETLIBRO/eufy/roborock/FOSCAM/…
They've provided thorough definitions and a label that implies they've all been understood by the manufacturer. It doesn't mean that this solves any real world problem.
> Security (or the lack of it) in the IoT world is a whole different ball game.
Those can be described as IoT devices. They're more appropriately categorized as "consumer electronics" and often have a firmware update right out of the box. That's what makes this badging program an absurd idea with no meaningful outcome. This segment is not going to care.
This isn't "Energy Star" where the purchased product does not have additional functionality which can be exposed or exploited through software and no third party testing can be exhaustive enough to prevent the obvious exploit from occurring.
Even to the extent they can it then enforces a product design which cannot be upgraded or modified by the user under any circumstances. Worse the design frustrates the users ability to do their own verification of the device security.
It's a good idea applied to the wrong category of products and users.
Re: White House unveils Cyber Trust Mark program for consumer devices
#59Earlier quoted context omitted.
> They describe it as being like EnergyStar which suggests they'll have a consumer accessible registry I've seen Energy Star logos for 30 years and never knew there was a public database, never thought to verify, and I don't think anyone else has either. The only thing Energy Star has been useful for is extracting rebates from utility companies and buying shitty dishwashers which were certain to be worse than what th…
https://www.energystar.gov/ - Here's the registry. And I'm not saying this will be that useful, just that it's not going to be a sticker and nothing else. That would be truly useless and pretty much just make money for sticker makers.
So, the product search works like a shopping cart site, and has no historical products, only new ones, and helpfully lists the prices.
Who is this meant to benefit?