Live data from Hacker News

Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

bloomberg.com

151–160 of 300 posts

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#151

Earlier quoted context omitted.

This seems suspiciously like government getting something right... with regards to a quickly-evolving new technology market... has this ever happened before?

Can you think of a concrete example where the government got it wrong?[1] For the sake of argument, the federal government in the last 50 years? Maybe the encryption export ban. Or the CDA, but that was quickly reversed and the part that's left (Section 230) was really instrumental in the rise of the modern web. [1] And I don't mean wrong as in "NSA spying" because you disagree with the policy. I mean like, "regulati…

How about the DMCA? It's routinely abused; it's easy to issue takedown notices and difficult to defend against them.

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#152
post #141

Earlier quoted context omitted.

Can you think of a concrete example where the government got it wrong?[1] For the sake of argument, the federal government in the last 50 years? Maybe the encryption export ban. Or the CDA, but that was quickly reversed and the part that's left (Section 230) was really instrumental in the rise of the modern web. [1] And I don't mean wrong as in "NSA spying" because you disagree with the policy. I mean like, "regulati…

Some HIPAA regulations that pre-date the rise of shared virtual servers in "the cloud" are quite outdated and cause quite a bit of trouble for no real benefit.

Such as? HIPAA generally has to do with organizational access controls and not specific technologies.

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#153

I'm surprised that self-driving technology is focusing on replacing the driver as an autonomous actor, processing visual and radar/lidar signals in order to know about its surroundings. I've always thought we'd get further faster by having automobiles also talk to other vehicles nearby, and design roads to support the computer driven vehicles. Two examples are: 1) If the vehicle is talking to the cars in front of it,…

While networked cars are interesting, there is also a massive security issue here. Hackers will easily figure out a way to spoof the communication, and could play with traffic. There are mitigations for most issues, but it's a complex topic. Just imagine some scenarios: -) Spoof an emergency break advisory that causes tailing cars to also do an emergency break. (could be mitigated by first observing that cars in fron…

>Hackers will easily figure out a way to spoof the communication, and could play with traffic.

It's far far easier and quicker to throw a brick off a highway bridge but that surprisingly happens very infrequently.

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#154
post #141

Earlier quoted context omitted.

Can you think of a concrete example where the government got it wrong?[1] For the sake of argument, the federal government in the last 50 years? Maybe the encryption export ban. Or the CDA, but that was quickly reversed and the part that's left (Section 230) was really instrumental in the rise of the modern web. [1] And I don't mean wrong as in "NSA spying" because you disagree with the policy. I mean like, "regulati…

Some HIPAA regulations that pre-date the rise of shared virtual servers in "the cloud" are quite outdated and cause quite a bit of trouble for no real benefit.

> Some HIPAA regulations that pre-date the rise of shared virtual servers in "the cloud" are quite outdated and cause quite a bit of trouble for no real benefit.

What HIPAA regulations are you talking about? Other than HITECH guidance (which can sort-of be seen as a "HIPAA regulation"), HIPAA regulations don't generally specify technologies at all, and I can't think of any that I would describe as outdated or troublesome due to the rise of shared virtual servers and "the cloud", whether they predate it or not.

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#155
post #141

Earlier quoted context omitted.

Can you think of a concrete example where the government got it wrong?[1] For the sake of argument, the federal government in the last 50 years? Maybe the encryption export ban. Or the CDA, but that was quickly reversed and the part that's left (Section 230) was really instrumental in the rise of the modern web. [1] And I don't mean wrong as in "NSA spying" because you disagree with the policy. I mean like, "regulati…

Some HIPAA regulations that pre-date the rise of shared virtual servers in "the cloud" are quite outdated and cause quite a bit of trouble for no real benefit.

Also, certain provisions of FERPA precluding use of cloud accounts for holding student data. I think those may be the archetypal examples.

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#156

From the regulations: "Fall back strategies should take into account that—despite laws and regulations to the contrary—human drivers may be inattentive, under the influence of alcohol or other substances, drowsy, or physically impaired in some other manner." NHTSA, which, after all, studies crashes, is being very realistic. Here's the "we're looking at you, Tesla" moment: "Guidance for Lower Levels of Automated Vehic…

Excellent analysis. It makes me optimistic that we as a society are going to be able to work this out. We might not of course, but it's possible.

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#157
post #141

Earlier quoted context omitted.

Some HIPAA regulations that pre-date the rise of shared virtual servers in "the cloud" are quite outdated and cause quite a bit of trouble for no real benefit.

> Some HIPAA regulations that pre-date the rise of shared virtual servers in "the cloud" are quite outdated and cause quite a bit of trouble for no real benefit. What HIPAA regulations are you talking about? Other than HITECH guidance (which can sort-of be seen as a "HIPAA regulation"), HIPAA regulations don't generally specify technologies at all, and I can't think of any that I would describe as outdated or trouble…

The biggest thing is that we can't run software with unencrypted PHI on physical hardware that is simultaneously running other people's code. In practical terms this means that we have to pay AWS some $ to get dedicated instances and also we can't use ELBs in the standard (easy) way. There are some other things as well.

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#158

Earlier quoted context omitted.

This seems suspiciously like government getting something right... with regards to a quickly-evolving new technology market... has this ever happened before?

Can you think of a concrete example where the government got it wrong?[1] For the sake of argument, the federal government in the last 50 years? Maybe the encryption export ban. Or the CDA, but that was quickly reversed and the part that's left (Section 230) was really instrumental in the rise of the modern web. [1] And I don't mean wrong as in "NSA spying" because you disagree with the policy. I mean like, "regulati…

ITAR comes to mind. Its basically bans export of dual-use (mil/civ) technologies. Its has made for incalculable harm to our aerospace industry and other industries that produce things that are classed dual use (encryption used to be one of them). This is the same law that banned encryption.

You have things like companies in Aviation Week (a big aerospace industry mag/site) running full page ads for sensors and other aerospace items proudly claiming its ITAR free (means not made/designed in US). A company I worked for bought a high power (2.5kW) laser from Germany. It failed and cannot be sent back to Germany for repair due to ITAR (tooling needed to fix it cannot be easily moved and probably would fall under ITAR). High end CNC machine tools will brick themselves if they are moved without the manufacturer specifically blessing the move due to ITAR regulations (earthquakes can trigger the "I've been moved without permission" response).

There is a countless list of other harms it has caused, but I have no direct experience with. ITAR is fairly easy to get around for the "bad guys" because they can just not buy US goods.

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#159
post #157

Earlier quoted context omitted.

> Some HIPAA regulations that pre-date the rise of shared virtual servers in "the cloud" are quite outdated and cause quite a bit of trouble for no real benefit. What HIPAA regulations are you talking about? Other than HITECH guidance (which can sort-of be seen as a "HIPAA regulation"), HIPAA regulations don't generally specify technologies at all, and I can't think of any that I would describe as outdated or trouble…

The biggest thing is that we can't run software with unencrypted PHI on physical hardware that is simultaneously running other people's code. In practical terms this means that we have to pay AWS some $ to get dedicated instances and also we can't use ELBs in the standard (easy) way. There are some other things as well.

> In practical terms this means that we have to pay AWS some $ to get dedicated instances

This is a feature, not a bug. It also is neither HITECH nor HIPAA; it is instead AWS's requirement in order to sign your BAA.

> we can't use ELBs in the standard (easy) way

Also neither HITECH nor HIPAA. ELBs are used in a PHI-related scenario identically to any other scenario. Unless you are referring to using it as an SSL terminator, in which case I would say "the standard (easy) way is always wrong".

Re: Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance

#160
post #157

Earlier quoted context omitted.

> Some HIPAA regulations that pre-date the rise of shared virtual servers in "the cloud" are quite outdated and cause quite a bit of trouble for no real benefit. What HIPAA regulations are you talking about? Other than HITECH guidance (which can sort-of be seen as a "HIPAA regulation"), HIPAA regulations don't generally specify technologies at all, and I can't think of any that I would describe as outdated or trouble…

The biggest thing is that we can't run software with unencrypted PHI on physical hardware that is simultaneously running other people's code. In practical terms this means that we have to pay AWS some $ to get dedicated instances and also we can't use ELBs in the standard (easy) way. There are some other things as well.

That seems like a fairly reasonable thing given you're talking about encrypted PHI... it's some extra $ for a considerable reduction to overall attack surface when processing the most sensitive type of personal data.

I don't think this meets OP's definition of "wrong".

Post reply on HN