Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

131–140 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#131

Earlier quoted context omitted.

> based on their behavior, they don't care. Personally I see it as "based on their behavior, they don't understand " We also need far more computer/tech literacy in the education system and populace.

In a healthy person, caring should pretty surely imply efforts to research the topic and eventual understanding.

Yes, but not caring could mean either not understanding or understanding but still not caring.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#132
post #84
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

You as a customer can already give the manufacturer that choice, and simple refuse to buy from any manufacturer that doesn't comply.

So what we need is giant warning stickers on products of which their parent companies don't follow good practices. Kind of like tobacco products.

"Leaks your personal data to unknown servers" Or "Manufacturer typically does not support their products beyond 2 years after which critical features and functions may stop working"

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#133
What is the policy on manufacturer installed backdoors on commodity hardware?

See https://arstechnica.com/information-technology/2016/11/chine... for an example.

Attempting to rule on this might involve conflict with the NSA, which has a decades long history of getting backdoors into commercial tech. https://www.reuters.com/article/us-usa-security-congress-ins... says a bit about this. But a lot of our tech is built in China. They're almost certainly doing the same thing, and history shows that those backdoors get discovered then become a source of security holes for the rest of us.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#134
post #84
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

You as a customer can already give the manufacturer that choice, and simple refuse to buy from any manufacturer that doesn't comply.

I've been not-buying IOT trash as hard as I can for decades. But nothing's changing... please tell me how to do this correctly!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#135
post #80

Earlier quoted context omitted.

Sounds like you are making an argument based on externalities. That's fine. But economic theory also gives you standard answers for externalities: Don't ban the behaviour you dislike. Either let people sort it out themselves (like the Coase Theorem https://en.wikipedia.org/wiki/Coase_theorem describes), or at most tax the offending behaviour.

I don't get what you're saying here. What "offending behavior" are you referring to in this case that might be taxed to disincentivize it?

Suppliers can already make binding promises about their hardware. If you open your wallet wide enough, you can already buy enterprise grade hardware that comes with guaranteed long term support.

OP says, amongst other things:

> I’ve advocated for the FCC to require device manufacturers to support their devices with security updates for a reasonable amount of time [1].

So the offending behaviour in this case would be for a manufacturer not to provide security updates.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#136

While the IoT security situation is out of control I doubt that regulating security updates will have any other result than radically reducing competition and innovation in the space by making it impossible to operate as a small company. It will simply push more hardware innovation out to China. Having worked in the space I came to the conclusion the only viable secure future is to adopt star topology local networks…

>Having worked in the space I came to the conclusion the only viable secure future is to adopt star topology local networks where local traffic for all devices goes into a single secure regularly updated broker device that then decides what to do with it. Any access out to the Internet or between devices needs to be mediated.

Yes, yours is (IMHO) the only possible way out, still there are things that simply should be not allowed or be only optional, as I see it the "mistake" is confounding the "Internet" in IoT with the "Cloud".

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#137
post #84
post #32

Simple. Give the manufacturers the choice: either they must provide full (FLOSS) source code and documentation (full schematics) to the user to enable them to maintain, patch and thus secure their devices (see also: right to repair), OR they are liable for all damages (direct, indirect) for a 30 year expected lifetime that arise from security issues with the device AND must have insurance to cover those damages (so t…

You as a customer can already give the manufacturer that choice, and simple refuse to buy from any manufacturer that doesn't comply.

A relatively small group of people won't have an effect, that's why regulation plays an important role.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#138

Earlier quoted context omitted.

Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.

99% of users don't know their iot devices have firmware nor that it can be updated.

They may have trusted family members, friends, or neighbors who they feel comfortable allowing the management of their internet connected devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#139
post #17
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

I am all for alternative free software firmware. But I don't think it adresses IoT security in any meaningful way.

[flagged]

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#140
post #84

Earlier quoted context omitted.

You as a customer can already give the manufacturer that choice, and simple refuse to buy from any manufacturer that doesn't comply.

I've been not-buying IOT trash as hard as I can for decades. But nothing's changing... please tell me how to do this correctly!

Well, lots of people have been not-buying liquorice their whole life, but nothing's changing. The market for liquorice candy is alive and well.

Less snarky: if other people still want to buy certain products, manufacturers will provide. But that's not a bad thing. Different folks have different preferences.

Post reply on HN