Earlier quoted context omitted.
>The problem is that "secure firmware" is a relativistic statement. No it isn't, software formally verified to EAL7 is guaranteed to be secure.
I would like to introduce you to Spectre and Rowhammer.
FCC updates covered list to include foreign-made consumer routers
121–130 of 452 posts
Re: FCC updates covered list to include foreign-made consumer routers
#122> all consumer-grade routers produced in foreign countries Are there even consumer-grade routers that are produced in the USA...?
But we can still buy old models: > As outlined below, today’s action does not impact a consumer’s continued use of routers they previously acquired. Nor does it prevent retailers from continuing to sell, import, or market router models approved previously through the FCC’s equipment authorization process. By operation of the FCC’s Covered List rules, the restrictions imposed today apply to new device models. I’m sure…
Re: FCC updates covered list to include foreign-made consumer routers
#123> all consumer-grade routers produced in foreign countries Are there even consumer-grade routers that are produced in the USA...?
Starlink?
Re: FCC updates covered list to include foreign-made consumer routers
#124Earlier quoted context omitted.
Yes. But a lot of people still got cars that were not as represented. So if we follow the same pattern, somebody will go to jail, but most routers will not be running verified or safe code.
Do you apply the same scrutiny to the food you eat? Some trust has to be created through testing standards and the law, but generally we do believe what the label says in day to day life.
Re: FCC updates covered list to include foreign-made consumer routers
#125Earlier quoted context omitted.
> So, foreign-made consumer routers can still be sold, but they are going to look at them with a fine-tooth comb, and they are going to use FCC approval as leverage to try to increase domestic manufacturing. You're assuming a non-partisan technocratic process, which this administration has amply shown is neither capable nor willing to provide. This requirement becomes another opportunity for Pay-to-Play, either in ca…
This is the problem with erosion of norms. We’ve all known for decades that consumer routers have shit security. We’ve all known about the risk of implants or intentional backdoors in the supply chain. And now when the FCC appears to be finally doing something about it, there’s a massive cloud of mistrust hanging over the whole idea.
Re: FCC updates covered list to include foreign-made consumer routers
#126Earlier quoted context omitted.
It'd be great if open firmware could be commercially viable. Finding a business model is hard. The OpenWRT One [1] sponsored by the Software Conservancy [2] and manufactured by Banana Pi [3] works lovely. [1] https://openwrt.org/toh/openwrt/one [2] https://sfconservancy.org/activities/openwrt-one.html [3] https://docs.banana-pi.org/en/OpenWRT-One/BananaPi_OpenWRT-O...
Just declare that any router that can be flashed to OpenWRT without loss of functionality is allowed to be imported.
Re: FCC updates covered list to include foreign-made consumer routers
#127Earlier quoted context omitted.
I would like to introduce you to Spectre and Rowhammer.
Secure software won't protect you from insecure hardware, which also needs to be formally verified for a secure system.
Then what's KPTI etc.?
> which also needs to be formally verified for a secure system.
Now we just need a correct and complete theory of quantum mechanics and to do something about that Heisenberg thing.
In general formal proofs tell you if something is true given a stipulated set of assumptions. They don't tell you if one of the stipulated assumptions is wrong or can be caused to be wrong on purpose by doing something nobody had previously known to be possible.
Re: FCC updates covered list to include foreign-made consumer routers
#128The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…
> This includes the FCC which license their devices The FCC licenses devices to the extent that devices can cause spurious transmissions in the radio spectrum. It’s not a general consumer protection agency. Computer security also is outside the mandate of the FTC, which exists to protect consumers from anticompetitive conduct and unfair business practices, not crappy products.
Sounds like it does to me. Also you're forgetting the part where the FTC under a prior administration either banned DLINK from selling in the US or heavily fined them for selling routers in the US that they knew were running insecure, buggy firmware.
(both quotes were taken verbatim from first, Netgear's US website, and secondly the Bureau of Consumer Protections' section of the FTC's website)