Is this just another mass surveillance operation?
FCC updates covered list to include foreign-made consumer routers
111–120 of 452 posts
Re: FCC updates covered list to include foreign-made consumer routers
#112Earlier quoted context omitted.
Why shouldn’t people have a reaction to a policy that mandates a new approval process on a large class of consumer products?
Especially since the announcement provides no information about how the DoD or DHS will be evaluating what to approve, and it's unlikely that they have the resources to do any meaningful security evaluation on that many products.
Re: FCC updates covered list to include foreign-made consumer routers
#113If we wanted secure products, we wouldn't ban devices. We'd mandate they open their firmware to audits.
It'd be great if open firmware could be commercially viable. Finding a business model is hard. The OpenWRT One [1] sponsored by the Software Conservancy [2] and manufactured by Banana Pi [3] works lovely. [1] https://openwrt.org/toh/openwrt/one [2] https://sfconservancy.org/activities/openwrt-one.html [3] https://docs.banana-pi.org/en/OpenWRT-One/BananaPi_OpenWRT-O...
Re: FCC updates covered list to include foreign-made consumer routers
#114Because of this, I'm going to plan my next network upgrade based on open source hardware like Banana Pi. My setup is based on WiFi 7 so this might not apply for a few years. From my understanding, the hardware from proprietary manufacturers is sufficiently advanced to do some advanced surveillance and spyware, whereas previous generations didn't require advanced processing to achieve fiber optic speeds. Back to the o…
The only thing I'm missing right now that would be a nice to have is a wifi card so I can ditch my access point. My hardware isn't open source by any means, but my reliance on non-free networking code is minimal.
Re: FCC updates covered list to include foreign-made consumer routers
#115What is a router? Really, do they have a definition?
Good question for devices that ship with multiple network interfaces, multiple video outputs, no RAM and no software.
Re: FCC updates covered list to include foreign-made consumer routers
#116The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…
> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…
No it isn't, software formally verified to EAL7 is guaranteed to be secure.
Re: FCC updates covered list to include foreign-made consumer routers
#117Earlier quoted context omitted.
> however we have been working on the wifi security problem for a long time and we have a lot to say about it Great, please share it with us! If what you've said is true, the kind of comment you're uniquely qualified to share is the very thing the thread most needs.
You can check our comment history https://news.ycombinator.com/threads?id=supernetworks
The whole point I'm trying to make is that you're qualified to make a substantive comment in the current thread and instead you've just posted a low-substance promotional comment.
Re: FCC updates covered list to include foreign-made consumer routers
#118Earlier quoted context omitted.
> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…
>The problem is that "secure firmware" is a relativistic statement. No it isn't, software formally verified to EAL7 is guaranteed to be secure.
Re: FCC updates covered list to include foreign-made consumer routers
#119Earlier quoted context omitted.
It could be part of dissolution of the company to mandate community firmware. But it depends on their licenses… Anyhow, this is a common enough practice. Many companies that provide infrastructure type software and sell to Fortune 500 companies often have a clause whereby they deliver their software to their customers if the shut down.
We don't care about their licenses; that's their problem. If they need firmware with a license that allows them to redistribute it there are plenty of free ones to choose from. And you can't wait until after they're dead to have them do something. By then they're gone or judgment proof because they're already bankrupt. Especially when you're talking about companies that aren't in the jurisdiction because you can't ev…
There was a promising design from Azure Sphere for 10 years of IoT device Linux security updates from Microsoft, even if the IoT vendor went out of business. This required a hardware design to isolate vendor userspace code from device security code, so they could be updated independently. Could be resurrected as open standard with FRAND licensing.
Re: FCC updates covered list to include foreign-made consumer routers
#120Will this impact the Mono Gateway[0]? [0] https://mono.si/
It looks like it probably won't matter. The site says you can preorder a DevKit "Shipping between June and September 2025." The fact that they haven't updated that webpage with new information since October 1st 2025 seems to indicate bad news...
Shortly put, they're going through hardware startup woes but will probably make it out the other end just fine.