Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

11–20 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#12
Awesome!

Thanks for engaging, where the rubber meets the road!

Hopefully, you are also looking into other venues, as well.

HN has a great group of folks that represent some of the most cutting-edge tech, but IT runs on Java 8[0].

[0] https://news.ycombinator.com/item?id=19877916

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#13
> Accordingly, incorporating our modifications, we propose, for purposes of the IoT labeling program, to define an IoT device as: (1) an Internet-connected device capable of intentionally emitting RF energy that has at least one transducer (sensor or actuator) for interacting directly with the physical world, coupled with (2) at least one network interface (e.g., Wi-Fi, Bluetooth) for interfacing with the digital world. We seek comment on our proposed definition.

I think this definition would apply to stuff like phones and cars, right? If so that's great.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#14
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

As far as I remember FCC about 8 years ago didn't liked OpenWRT, and even enforced on TP Link to lock it.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#15
What makes IoT devices special, and warrants carve outs for security / vulnerabilities?

I guess I am not surprised there are security issues with these devices, because I think of most of them as coming from small companies, and wonder what the impact would be on the IoT space if only large players can work through more regulation.

That said, I can't decide if I am more concerned about my Wyze camera sending data where I don't want it to, than my water heater leaking it's current temperature (implicating whether I am home or not).

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#16
These rules sound like reasonable steps, upon first reading. Not sure what the downstream effects might be.

Is there any thought given to cloud based devices becoming paperweight when companies behind them just stop supporting it or turn off the API? I'd like some "assurances" in place that if the company either goes out of business or decides to sunset the service, it would be required to open source (or at least make available for download). If memory services, that happened to some Nest models a while back.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#17
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#18
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

[deleted]

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#19
FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a sticker on the box won't change that. It is literally impossible to put out a software product with anything resembling security today. It'd be like putting a "secure against bricks" sticker on a window. Our industry is a joke. Building secure software products can't be done without completely rearchitecting how our industry operates, which isn't going to happen.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#20

Awesome! Thanks for engaging, where the rubber meets the road! Hopefully, you are also looking into other venues, as well. HN has a great group of folks that represent some of the most cutting-edge tech, but IT runs on Java 8[0]. [0] https://news.ycombinator.com/item?id=19877916

Pretty cool (or at least interesting) to see a government agency engage on HN like this. Never seen that before.
Post reply on HN