Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

141–150 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#141

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

IMO they should have a choice between open source that can be updated out of band from the manufacturer or assuming direct liability for issues for the product's life.

Re: FCC updates covered list to include foreign-made consumer routers

#142
post #140

For the device manufacturers, the obvious solution is to sell them as general-purpose computers. You can already get devices that had started out as Raspberry Pi clones but evolved into excellent DIY network appliances, with multiple high-speed Ethernet and SSD ports that are great for running a NAS, proxy server, firewall, or all three, and more. Rarely do they have good WiFi, but if manufacturers start selling hard…

Companies want to sell what consumers want to buy. But the average consumer doesn't want a general-purpose computer for this job; they instead want to buy a "router". If companies market the devices as something other than "routers" then consumers will not buy them for routing duty. (Meanwhile, the non-average people who want to use general-purpose computers as homespun router/NAS/do-all boxes are already aware of ho…

> But the average consumer doesn't want a general-purpose computer for this job; they instead want to buy a "router".

So start your own company called usa router co, and sell some random arm board with a preinstalled router image... the end user won't know the difference.

Re: FCC updates covered list to include foreign-made consumer routers

#143
post #3

> all consumer-grade routers produced in foreign countries Are there even consumer-grade routers that are produced in the USA...?

> consumer-grade routers that are produced in the USA Starlink?

I believe they make satellite components not consumer hardware in the US

Re: FCC updates covered list to include foreign-made consumer routers

#144

Considering this is after Loper Bright Enterprises v. Raimondo (2024), it will be interesting to see if this holds up to judicial scrutiny. The FCC's power just got substantially nerfed, and "we've decided to slow lane all foreign-made routers" feels like that may have been beaten on the old, higher, standard. Let alone the new one that gives the FCC almost no power.

Nerfed to do their job. The corrupt republican Supreme Court judges are very happy to give more power to the executive to collect bribes, however.

[flagged]

Re: FCC updates covered list to include foreign-made consumer routers

#145
post #66

What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers! Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?

The computing freedom = a plausibly deniable backdoor. https://nvd.nist.gov/vuln/detail/CVE-2023-1389

Another favorite, https://www.synacktiv.com/publications/cool-vulns-dont-live-...

the router sniffed plaintext http to grab HTTP User agents to put them into a curl bash command line string. Nice RCE from the browser.

Re: FCC updates covered list to include foreign-made consumer routers

#146
post #130

Earlier quoted context omitted.

Probably made in Vietnam, like Amazon Eero.

Where it's manufactured has nothing to do with security.

  FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security.." FCC Updates Covered List to Include Foreign-Made Consumer Routers..

Re: FCC updates covered list to include foreign-made consumer routers

#147

Earlier quoted context omitted.

Good question for devices that ship with multiple network interfaces, multiple video outputs, no RAM and no software.

If multiple network interfaces defines a router, then every cell phone is one, because every cell phone has a cellular and Wifi interface, and is a router in hotspot mode. Three interfaces if you count USB which can also be a network interface (hotspot works over USB in both Windows and Linux) and four if Bluetooth PAN is still a thing.

Speaking of phone companies, Apple will be manufacturing Mac Mini in USA.

If Apple can make a Neo laptop out of phone parts, they could make a US Airport router out of US mini PC parts.

Re: FCC updates covered list to include foreign-made consumer routers

#148

Earlier quoted context omitted.

> foreign-made consumer routers can still be sold, but they are going to look at them with a fine-tooth comb, and they are going to use FCC approval as leverage to try to increase domestic manufacturing That is not what's going to happen. What's going to happen is that anyone coughing up payola to the current executive in chief's people will get approved, and anyone that doesn't will remain blocked. This practice is…

We're going to keep seeing this in all kinds of industries throughout the next three or so years: "Your products are banned or your country is tariffed, but if you pay enough in bribes, er I mean undergo our approval process, then you'll be exempt."

Bonus points if the ‘approval’ process exempts them from liability if misused - and there is no actual checking done as part of approval.

Re: FCC updates covered list to include foreign-made consumer routers

#149

Earlier quoted context omitted.

> It has to be from Day 1. There was a promising design from Azure Sphere for 10 years of IoT device Linux security updates from Microsoft, even if the IoT vendor went out of business. This required a hardware design to isolate vendor userspace code from device security code, so they could be updated independently. Could be resurrected as open standard with FRAND licensing.

The main thing you need is for the lowest-level code to be open and replaceable/patchable because it's the only part which is actually specific to the device. Windows running on Core Boot is a better place to be than custom Linux running on opaque blob, because in the first case you can pretty easily get to newer Windows, vanilla Linux or anything else you want running on Core Boot after the original version of Windo…

Modern coreboot depends on opaque blobs on CPU (FSP/ACM on Intel) and auxiliary processors (ME/PSP), but AMD is moving in the right direction with OpenSIL host firmware. Arm devices have their own share of firmware blobs.

A decade of security updates for routers would require stable isolation between low-level device security and IoT vendor userspace. In Sphere, the business model for 10 years of paid updates was backed by hardware isolation. Anyone know why it didn't get market traction? There was a dev board, but no products shipped.

Re: FCC updates covered list to include foreign-made consumer routers

#150

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

I know it's the norm to criticize the admin, but I don't think its what they're saying. I think they're saying "they know of the vulns they leave in and only fix them after it's been exploited by their states".

Not that any consumer router is super nice and safe, honestly, you're better off making your own these days.

Post reply on HN