Live data from Hacker News

White House unveils Cyber Trust Mark program for consumer devices

nextgov.com

61–70 of 164 posts

Re: White House unveils Cyber Trust Mark program for consumer devices

#61
This is a bit scary. Knowing how software is developed, I know there's no government program that could actually ensure a device is secure. It's one thing to measure an electronic device's EMI or pump it full of power and see if it catches fire. But black box testing of software is itself a black art, as software security is a lot more complex than [typical] electronic design.

The scary bit is that this label is going to be found to be ineffective, and then consumers may lose trust in government-issued safety stamps.

Re: White House unveils Cyber Trust Mark program for consumer devices

#62

This is a bit scary. Knowing how software is developed, I know there's no government program that could actually ensure a device is secure. It's one thing to measure an electronic device's EMI or pump it full of power and see if it catches fire. But black box testing of software is itself a black art, as software security is a lot more complex than [typical] electronic design. The scary bit is that this label is goin…

In Germany we had something like this from the TUEV Süd, where they certified online shops and online banking websites for their security.

Suffice it to say, but the keywords are a google dork for finding easy to hack pentesting victims.

Now the BSI (German institute for cybersecurity, similar to CISA) also started to push out certifications for the BSI Grundschutz, which is an absolute meaningless certificate and literally tests the absolute bare minimum things.

The problem here is that there is no market, this cyber security crisis cannot be solved economically, because customers want a certificate without having to do further work. So they'll get it at whatever auditor that accepts their money.

This is how it's done, even for ISO 27001 and SOC2 certifications. Nobody gives a damn if a single working student has 20+ role descriptions laying on their table. Findings are always ignored and never corrected.

Cyber security policies and their effects over time need to be measurable first before there can be certification processes.

Additionally there needs to be legislation that cannot be interpreted. Things like "reasonably modern" cannot be used as a law text because it doesn't mean anything, and instead standardized practices have to be made mandatory requirements. Preferably by a committee that is not self controlling, maybe even something like the EFF, FSF, OWASP or Linux foundation.

Re: White House unveils Cyber Trust Mark program for consumer devices

#63
This is equivalent to requiring an Underwriters Laboratory (UL) approval on every electrical appliance before settling on requirements for fuses or circuit breakers.

No matter how good everyone in this trust mark program is, you're only one confused deputy[1] away from disaster.

[1] https://en.wikipedia.org/wiki/Confused_deputy_problem

Re: White House unveils Cyber Trust Mark program for consumer devices

#66
post #65

Who are these UL Solutions? They seem to have come out of nowhere and hit the jackpot, inserting themselves as arbiters for security. Smells a bit like how Common Criteria proffered independent certification labs, which were no panacea either.

Underwriters Laboratories, UL. Look at the back of pretty much any mains powered device and you'll see their mark. They were founded 130 years ago, and test and warrant devices (typically high voltage) to be safe. Security is a new thing for them, but they're well suited to provide the services.

Re: White House unveils Cyber Trust Mark program for consumer devices

#67

This is a bit scary. Knowing how software is developed, I know there's no government program that could actually ensure a device is secure. It's one thing to measure an electronic device's EMI or pump it full of power and see if it catches fire. But black box testing of software is itself a black art, as software security is a lot more complex than [typical] electronic design. The scary bit is that this label is goin…

> I know there's no government program that could actually ensure a device is secure

Well, there's SELinux, TOR

Re: White House unveils Cyber Trust Mark program for consumer devices

#68

I'm interested in the actual details here -- 1) What are the requirements for the mark? E.g. no passwords stored in plaintext on servers, no blank/default passwords on devices for SSH or anything else, a process for security updates, etc.? 2) Who is inspecting the code, both server-side and device-side? 3) What are the processes for inspecting the code? How do we know it's actually being done and not just being rubbe…

Here are requirements if you follow the China-bad politics:

1) Don’t be select Chinese products

2) Be select American products

It’s not reaaaally 3d chess, but a relatively crude misnomer for the “Made in America” stamp or “Its American and definitely not Chinese”.

The security practices are probably the same across products, it’s just the wrong time wrong presidency for China.

Re: White House unveils Cyber Trust Mark program for consumer devices

#69

Interesting. I'm not sure if the public comment period is over (The original proposal is dated August, 2023), but this stands out to me from their paper: We propose to focus the scope of our program on intentional radiators that generate and emit RF energy by radiation or induction.31 Such devices – if exploited by a vulnerability – could be manipulated to generate and emit RF energy to cause harmful interference. Wh…

You might be getting a bit too far ahead of where the industry is at with some of those wishlist items. NIST's requirements are things that are best practices that everyone agrees with, like: * data stored/transmitted is secured by some kind of means * the device supports software updates * the device requires users to authenticate * the device has documentation * you can report security vulnerabilities to the develo…

The software update angle has already been commented on, but I'm not sure this one is a good idea either:

> the device requires users to authenticate

Re: White House unveils Cyber Trust Mark program for consumer devices

#70
This is doomed to failure.

Cybersecurity best practices are a point in time snapshot, the label will be dependent on at purchase time, how will that help people who have purchased second hand, or had products where items on shelves suddenly had a vulnerability discovered? You really think they are going to go through the cost of sending those back?

All software bugs can potentially be security bugs. This follows classic shock doctrine.

Post reply on HN