Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

111–120 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#112
post #62
post #30

Earlier quoted context omitted.

Why shouldn’t people have a reaction to a policy that mandates a new approval process on a large class of consumer products?

Especially since the announcement provides no information about how the DoD or DHS will be evaluating what to approve, and it's unlikely that they have the resources to do any meaningful security evaluation on that many products.

The DOH and DOW have a lot of resources. And I would guess the DOW has a lot of intelligence resources and most likely the DOH also I mean it is their job to keep the homeland safe. But I would agree. It probably will involve a lot of marshaling of those resources and reorganization. But who's to say they haven't done that already. My general point is that the conversation in this thread completely ignores that this is an imposition of a different regulatory scheme, not a banning. And actually it's in favor of enforcing more security on routers which everybody has been screaming for for years.

Re: FCC updates covered list to include foreign-made consumer routers

#113
post #25

If we wanted secure products, we wouldn't ban devices. We'd mandate they open their firmware to audits.

It'd be great if open firmware could be commercially viable. Finding a business model is hard. The OpenWRT One [1] sponsored by the Software Conservancy [2] and manufactured by Banana Pi [3] works lovely. [1] https://openwrt.org/toh/openwrt/one [2] https://sfconservancy.org/activities/openwrt-one.html [3] https://docs.banana-pi.org/en/OpenWRT-One/BananaPi_OpenWRT-O...

Open to audits doesn't mean free software, it just means visible source. The business model for selling routers with auditable firmware is selling routers.

Re: FCC updates covered list to include foreign-made consumer routers

#114

Because of this, I'm going to plan my next network upgrade based on open source hardware like Banana Pi. My setup is based on WiFi 7 so this might not apply for a few years. From my understanding, the hardware from proprietary manufacturers is sufficiently advanced to do some advanced surveillance and spyware, whereas previous generations didn't require advanced processing to achieve fiber optic speeds. Back to the o…

IMHO an underrated comment. The CCP isn't going to break down my door in the middle of the night, but I'm sure I'm on lists at the FBI and ATF just for my political org memberships alone. I think a foreign actor is more likely to use compromised hardware to create service interruptions and general chaos in the event they are attacked by our government, not come put me in a gulag.

The only thing I'm missing right now that would be a nice to have is a wifi card so I can ditch my access point. My hardware isn't open source by any means, but my reliance on non-free networking code is minimal.

Re: FCC updates covered list to include foreign-made consumer routers

#115

What is a router? Really, do they have a definition?

Good question for devices that ship with multiple network interfaces, multiple video outputs, no RAM and no software.

If multiple network interfaces defines a router, then every cell phone is one, because every cell phone has a cellular and Wifi interface, and is a router in hotspot mode. Three interfaces if you count USB which can also be a network interface (hotspot works over USB in both Windows and Linux) and four if Bluetooth PAN is still a thing.

Re: FCC updates covered list to include foreign-made consumer routers

#116

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

>The problem is that "secure firmware" is a relativistic statement.

No it isn't, software formally verified to EAL7 is guaranteed to be secure.

Re: FCC updates covered list to include foreign-made consumer routers

#117
post #84

Earlier quoted context omitted.

> however we have been working on the wifi security problem for a long time and we have a lot to say about it Great, please share it with us! If what you've said is true, the kind of comment you're uniquely qualified to share is the very thing the thread most needs.

You can check our comment history https://news.ycombinator.com/threads?id=supernetworks

Right; about 20 comments over nearly three years, and nothing substantive in the current thread.

The whole point I'm trying to make is that you're qualified to make a substantive comment in the current thread and instead you've just posted a low-substance promotional comment.

Re: FCC updates covered list to include foreign-made consumer routers

#118

Earlier quoted context omitted.

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

>The problem is that "secure firmware" is a relativistic statement. No it isn't, software formally verified to EAL7 is guaranteed to be secure.

I would like to introduce you to Spectre and Rowhammer.

Re: FCC updates covered list to include foreign-made consumer routers

#119

Earlier quoted context omitted.

It could be part of dissolution of the company to mandate community firmware. But it depends on their licenses… Anyhow, this is a common enough practice. Many companies that provide infrastructure type software and sell to Fortune 500 companies often have a clause whereby they deliver their software to their customers if the shut down.

We don't care about their licenses; that's their problem. If they need firmware with a license that allows them to redistribute it there are plenty of free ones to choose from. And you can't wait until after they're dead to have them do something. By then they're gone or judgment proof because they're already bankrupt. Especially when you're talking about companies that aren't in the jurisdiction because you can't ev…

> It has to be from Day 1.

There was a promising design from Azure Sphere for 10 years of IoT device Linux security updates from Microsoft, even if the IoT vendor went out of business. This required a hardware design to isolate vendor userspace code from device security code, so they could be updated independently. Could be resurrected as open standard with FRAND licensing.

Re: FCC updates covered list to include foreign-made consumer routers

#120
post #22

Will this impact the Mono Gateway[0]? [0] https://mono.si/

It looks like it probably won't matter. The site says you can preorder a DevKit "Shipping between June and September 2025." The fact that they haven't updated that webpage with new information since October 1st 2025 seems to indicate bad news...

The founder puts regular updates on his YouTube channel: https://youtu.be/RS2igvW3DIk

Shortly put, they're going through hardware startup woes but will probably make it out the other end just fine.

Post reply on HN