Earlier quoted context omitted.
Have you hear about customs?
None of the electronic widgets I've bought stateside from overseas sources have ever shown any evidence that they've ever been actually-inspected by US Customs. How would they know that an item is fraudulently marked if they never look?
White House unveils Cyber Trust Mark program for consumer devices
111–120 of 164 posts
Re: White House unveils Cyber Trust Mark program for consumer devices
#112Seems like good fodder for a tongue twister. Try saying it 10 times fast: - Must the Cyber Truck (Musk) bear the Cyber Trust Mark?
It's adding a standards and governance layer to tech, which creates a capacity for compliance management in regualted industries. annoying for sure, but the US has lost its unipolar superpower role because its critical infrastructure systems were made of garbage code and its population is effectively defenseless.
it doesn't solve it, but it improves the dynamic.
Re: White House unveils Cyber Trust Mark program for consumer devices
#113Earlier quoted context omitted.
Most software vulnerabilities aren't intentionally added backdoors, but flaws in the software that shipped on a device. > After all, how many widespread hacks do you read about on old, single-purpose fixed analog or digital devices (which in a sense are similarly 'read-only'). Quite a lot -- these are some of the easiest devices to hack. The only saving grace is that most of them are not connected to the internet so…
> Most software vulnerabilities aren't intentionally added backdoors, but flaws in the software that shipped on a device. Disagree, it is extremely common for e.g. TVs and smart phones to ship with malware included. In fact it is almost impossible to buy some classes of devices that aren't intentionally compromised. Having the thing never connect to the Internet at all and never receive updates is a far better securi…
Both are common! But there are many hundreds of thousands of known software vulnerabilities.
> Having the thing never connect to the Internet at all and never receive updates is a far better security posture
It might be, depending on the particular situation. But it doesn’t really matter for IoT devices, because they all, by definition, connect to the internet. “Don’t connect to the internet” is a nonsensical suggestion for IoT devices.
Re: White House unveils Cyber Trust Mark program for consumer devices
#114Earlier quoted context omitted.
> Those can be described as IoT devices. They're more appropriately categorized as "consumer electronics" IoT devices are a subset of a much broader 'consumer electronics' category. > and often have a firmware update right out of the box. From major, established, mature companies, yes. Many device manufacturers in this category never issue firmware updates. Which is precisely why this is one of the requirements. > Th…
> because they will be forced by law to comply. Which means the program will have zero value outside of federal purchasing offices. They will not evaluate the criteria or care about the reality of the offering, they'll see the sticker, and know it's "default approved." Is this a good outcome? > mitigate risk A sticker cannot do this.
I can’t guarantee much but I can guarantee a non zero number of non federal purchasers will consider the sticker.
>> mitigate risk
> A sticker cannot do this.
Correct. The sticker itself doesn’t mitigate the risk. The adherence to the requirements necessary to qualify for the sticker do.
Re: White House unveils Cyber Trust Mark program for consumer devices
#115Re: White House unveils Cyber Trust Mark program for consumer devices
#116Earlier quoted context omitted.
Most software vulnerabilities aren't intentionally added backdoors, but flaws in the software that shipped on a device. > After all, how many widespread hacks do you read about on old, single-purpose fixed analog or digital devices (which in a sense are similarly 'read-only'). Quite a lot -- these are some of the easiest devices to hack. The only saving grace is that most of them are not connected to the internet so…
> Most software vulnerabilities aren't intentionally added backdoors, but flaws in the software that shipped on a device. Disagree, it is extremely common for e.g. TVs and smart phones to ship with malware included. In fact it is almost impossible to buy some classes of devices that aren't intentionally compromised. Having the thing never connect to the Internet at all and never receive updates is a far better securi…
One thing the government can or perhaps should mandate, and is easily verifiable, is kill switches - devices should be physically incapable of connecting to any wireless network when a kill switch is engaged. If the FTC or a trade regulator wants to regulate at another level, maybe they could also say certain classes of devices must continue to function when disconnection (I might want the Apple TV plugged in to the TV connected to the internet, but the TV itself totally disconnected.) Because some devices now will surreptitiously search for open WiFi networks and try to go online even if a user does not connect via WiFi, this seems reasonable.
If we go down the route of a government agency creating and mandating security,
#1 Government back doors will persist and perhaps even be required (relevant to the whole TikTok thing this week.) #2 They will be unable to quickly respond to new threat surfaces while still representing that whatever is present is secure (it isn't.)
Re: White House unveils Cyber Trust Mark program for consumer devices
#117Earlier quoted context omitted.
Not at all. Many old mjpeg IP cameras worked this way and they ended up on the open internet. Shodan is full of them, still.
So don't put them on the open Internet. It's much easier to do that than it is to secure a device that creates outbound connections to some untrusted external server (which manufacturers are). If it doesn't try to use UPnP or anything, it will not be in the open by default. If your threat model for consumer IoT devices does not include manufacturers in 2025, you are completely confused about computer security. Having…
https://news.ycombinator.com/item?id=42624930
I do not know for sure whether these devices use UPnP or similar, but considering that they are not intended to be accessible from the Internet, probably not. The blame probably lies with (in this case) all the random government agencies deploying the devices in an insecure way. But assigning blame won’t fix the problem. Something needs to change, and it’s probably going to be the devices.
Consumer devices are different. On one hand, they’re less likely to be exposed to the public Internet… at least proportionally. I think. But on the other hand, consumers expect to be able to access their devices from anywhere, and right now in practice that means going through a manufacturer-controlled proxy server. I would love if someone would come up with a standardized mechanism to make home devices securely remotely accessible, without a manufacturer-controlled proxy, but just as easy to use as the status quo. Until that happens, don’t expect anything to change.
Re: White House unveils Cyber Trust Mark program for consumer devices
#118Earlier quoted context omitted.
https://www.energystar.gov/ - Here's the registry. And I'm not saying this will be that useful, just that it's not going to be a sticker and nothing else. That would be truly useless and pretty much just make money for sticker makers.
"Find all the information you need to start shopping for ENERGY STAR certified products, including product details, rebates, and retailers near you." So, the product search works like a shopping cart site, and has no historical products, only new ones, and helpfully lists the prices. Who is this meant to benefit?
Re: White House unveils Cyber Trust Mark program for consumer devices
#119Re: White House unveils Cyber Trust Mark program for consumer devices
#120Earlier quoted context omitted.
Not at all. Many old mjpeg IP cameras worked this way and they ended up on the open internet. Shodan is full of them, still.
So don't put them on the open Internet. It's much easier to do that than it is to secure a device that creates outbound connections to some untrusted external server (which manufacturers are). If it doesn't try to use UPnP or anything, it will not be in the open by default. If your threat model for consumer IoT devices does not include manufacturers in 2025, you are completely confused about computer security. Having…
That's a valid answer for an audience familiar with computer networking concepts. It's a silly suggestion for consumer IoT customers, who do not understand those concepts. They don't know what is or is not 'on the open internet'; they buy a product at the store and plug it in.
> We should have certifications that devices create no outbound TCP/UDP flows.
This is the "bury your head in the sand" method of solving the problem. If you design your requirement so that zero consumer accessible devices are capable of meeting them, then what's the point? As long as people (1) want to watch their camera away from home, and (2) don't have the networking expertise to configure a remote access VPN tunnel, the devices are going to have to reach outbound to traverse home router firewalls.