Live data from Hacker News

White House unveils Cyber Trust Mark program for consumer devices

nextgov.com

101–110 of 164 posts

Re: White House unveils Cyber Trust Mark program for consumer devices

#101

Things like this are useless, in my mind, because hackers are always going to innovate and find ways around protection mechanisms. Today's "locked down" IoT device could easily become tomorrow's "vulnerable to an easily exploitable pre-auth RCE". What the government probably _should_ do is begin establishing a record of manufacturers/vendors which indicates how secure their products have been over a long period of ti…

When I buy technology today, I'm 10X more worried about the manufacturer deliberately changing, killing or nerfing the product after I bought it, than I am worried about hackers compromising it. This goes for connected hardware, IOT devices, and software.

Oddly "hackers" are the ones who often revive defunct hardware or give users back control over their devices. Things like DRM laws seem to only enhance corporate interests.

Re: White House unveils Cyber Trust Mark program for consumer devices

#102

Earlier quoted context omitted.

the device supports software updates 'Cause they need somewhere to load in those exploits! A hypothetical device which is all read-only (except perhaps for a very carefully crafted, limited set of configurable parameters) might in some cases be more secure than the bulk of what's on the shelves today. After all, how many widespread hacks do you read about on old, single-purpose fixed analog or digital devices (which…

Most software vulnerabilities aren't intentionally added backdoors, but flaws in the software that shipped on a device. > After all, how many widespread hacks do you read about on old, single-purpose fixed analog or digital devices (which in a sense are similarly 'read-only'). Quite a lot -- these are some of the easiest devices to hack. The only saving grace is that most of them are not connected to the internet so…

> Most software vulnerabilities aren't intentionally added backdoors, but flaws in the software that shipped on a device.

Disagree, it is extremely common for e.g. TVs and smart phones to ship with malware included. In fact it is almost impossible to buy some classes of devices that aren't intentionally compromised.

Having the thing never connect to the Internet at all and never receive updates is a far better security posture, and is the common recommendation among knowledgeable people for e.g. TVs.

In practice, your neighbors are almost certainly quite a bit less malicious than whatever a smart device might talk to on the Internet. Your neighbor isn't going to hack your cordless phone. Your TV manufacture is definitely going to drop malware onto it, disable functionality (i.e. damage it), etc.

Re: White House unveils Cyber Trust Mark program for consumer devices

#103

Earlier quoted context omitted.

It's proprietary but relatively easy to reverse engineer, the details are out there. In the US it uses like 914.5 MHz or something, and I can send instructions to devices with an extremely simple serial protocol on my computer. No Bluetooth, no Wi-Fi, no protocol sophisticated enough to distribute code. Just locally transmitted instructions.

Do they require auth and use solid crypto? If not, they are vulnerable, it's just that the vulnerability requires the attacker to be within range. People thought old analog 900mhz cordless phones were fine until others realized you could just tune a radio to that freq and listen to your neighbors.

They're not vulnerable in any way that matters. If you manage to get a device in range you can... turn my lights on and off? You can't program them to do malicious things over the Internet. They don't have any sensitive information you can access. There's no damage you can do them.

The problem with saying you need auth and crypto is now you just added a bunch of complexity you have to maintain and update and hence now you've introduced vulnerabilities.

Re: White House unveils Cyber Trust Mark program for consumer devices

#104
post #90

Earlier quoted context omitted.

the device supports software updates 'Cause they need somewhere to load in those exploits! A hypothetical device which is all read-only (except perhaps for a very carefully crafted, limited set of configurable parameters) might in some cases be more secure than the bulk of what's on the shelves today. After all, how many widespread hacks do you read about on old, single-purpose fixed analog or digital devices (which…

Some things to realize about read-only devices is that once they are cracked, they are cracked forever. The devs have dev time to secure the device, the hackers have infinite time to crack it. Once done, the game is up. All instances are now easily exploited. The more popular the device, the more knowable upside to an exploit. If the device can be updated, then usually the exploitable timeframe is limited and its unk…

A really dumb camera that just has an interface that's polled for data by a remote host is more likely to be used in a secure way than a 'smart' camera that tries to remember state and talk to an external server itself.

Re: White House unveils Cyber Trust Mark program for consumer devices

#105

Interesting. I'm not sure if the public comment period is over (The original proposal is dated August, 2023), but this stands out to me from their paper: We propose to focus the scope of our program on intentional radiators that generate and emit RF energy by radiation or induction.31 Such devices – if exploited by a vulnerability – could be manipulated to generate and emit RF energy to cause harmful interference. Wh…

You might be getting a bit too far ahead of where the industry is at with some of those wishlist items. NIST's requirements are things that are best practices that everyone agrees with, like: * data stored/transmitted is secured by some kind of means * the device supports software updates * the device requires users to authenticate * the device has documentation * you can report security vulnerabilities to the develo…

  > But for now, you can presume the Netflix button on your TV remote can't be configured to point to an alternative API if Netflix goes away. :)
It is HackerNews, so your statement is true UNLESS you're willing to hack your TV. (But this shouldn't be a thing people _have_ to do... ):

Warning, I haven't personally tried this

https://askanydifference.com/how-to-root-samsung-tv/

https://wiki.samygo.tv/index.php?title=SamyGO_for_DUMMIES

Re: White House unveils Cyber Trust Mark program for consumer devices

#106
post #90

Earlier quoted context omitted.

Some things to realize about read-only devices is that once they are cracked, they are cracked forever. The devs have dev time to secure the device, the hackers have infinite time to crack it. Once done, the game is up. All instances are now easily exploited. The more popular the device, the more knowable upside to an exploit. If the device can be updated, then usually the exploitable timeframe is limited and its unk…

A really dumb camera that just has an interface that's polled for data by a remote host is more likely to be used in a secure way than a 'smart' camera that tries to remember state and talk to an external server itself.

Not at all. Many old mjpeg IP cameras worked this way and they ended up on the open internet. Shodan is full of them, still.

Re: White House unveils Cyber Trust Mark program for consumer devices

#107
post #83

Earlier quoted context omitted.

except they are not in your country so how can to go to jail and why do they care about you laws?

Have you hear about customs?

None of the electronic widgets I've bought stateside from overseas sources have ever shown any evidence that they've ever been actually-inspected by US Customs.

How would they know that an item is fraudulently marked if they never look?

Re: White House unveils Cyber Trust Mark program for consumer devices

#108

Earlier quoted context omitted.

> NIST isn't a bunch of dummies that don't know this They've provided thorough definitions and a label that implies they've all been understood by the manufacturer. It doesn't mean that this solves any real world problem. > Security (or the lack of it) in the IoT world is a whole different ball game. Those can be described as IoT devices. They're more appropriately categorized as "consumer electronics" and often have…

> Those can be described as IoT devices. They're more appropriately categorized as "consumer electronics" IoT devices are a subset of a much broader 'consumer electronics' category. > and often have a firmware update right out of the box. From major, established, mature companies, yes. Many device manufacturers in this category never issue firmware updates. Which is precisely why this is one of the requirements. > Th…

> because they will be forced by law to comply.

Which means the program will have zero value outside of federal purchasing offices. They will not evaluate the criteria or care about the reality of the offering, they'll see the sticker, and know it's "default approved."

Is this a good outcome?

> mitigate risk

A sticker cannot do this.

Re: White House unveils Cyber Trust Mark program for consumer devices

#110

Earlier quoted context omitted.

A really dumb camera that just has an interface that's polled for data by a remote host is more likely to be used in a secure way than a 'smart' camera that tries to remember state and talk to an external server itself.

Not at all. Many old mjpeg IP cameras worked this way and they ended up on the open internet. Shodan is full of them, still.

So don't put them on the open Internet. It's much easier to do that than it is to secure a device that creates outbound connections to some untrusted external server (which manufacturers are). If it doesn't try to use UPnP or anything, it will not be in the open by default.

If your threat model for consumer IoT devices does not include manufacturers in 2025, you are completely confused about computer security. Having a standard to encourage devices to talk to manufacturers is completely backwards. We should have certifications that devices create no outbound TCP/UDP flows.

Post reply on HN