Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

171–180 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#171

What is a router? Really, do they have a definition?

Good question for devices that ship with multiple network interfaces, multiple video outputs, no RAM and no software.

All routers ship with software.

(edit: and RAM!)

(edit: and NOT multiple video outputs!!)

Re: FCC updates covered list to include foreign-made consumer routers

#172

If war breaks out you better bet a bunch of equipment will turn off. Numerous papers showing the ability to easily map indoors areas with WiFi (including occupancy) it’s a liability. There will be excuses “tariffs” etc but I heard a few have gotten calls from three letter agencies coyly telling you to improve your systems. It’s a chance to refresh the product line! (of course at the worst time when mem prices are ble…

"Will turn off"... are you claiming that consumer-grade routers have a secret backdoor kill switch that one government or another can use to turn them off? That's a little hard to believe (even when they are security Swiss cheese).

Seeing the operational capability of Mossad in Iran means if desired, one should assume the US and China are equally capable.

The US didn’t make a space force to please the ego, it was likely to occur eventually. They aren’t spending all their time wargaming a moon invasion lol

Logistically, hacking tons of different model routers is not feasible. It would be more useful to yank the power grid.. which can be accomplished with missiles or software.

Re: FCC updates covered list to include foreign-made consumer routers

#173

Earlier quoted context omitted.

Good question for devices that ship with multiple network interfaces, multiple video outputs, no RAM and no software.

All routers ship with software. (edit: and RAM!) (edit: and NOT multiple video outputs!!)

x86 multi NIC barebone fanless PC is not for routing, nope.

Re: FCC updates covered list to include foreign-made consumer routers

#174
my instinct is open source is part of the answer. the market monetizes with differentiation on the open source base, support, hardware, etc. vibrant enough market = the foss is secure (always a relative term) and continues to evolve, partially paid for by the companies who are monetizing

Re: FCC updates covered list to include foreign-made consumer routers

#175

Earlier quoted context omitted.

"Will turn off"... are you claiming that consumer-grade routers have a secret backdoor kill switch that one government or another can use to turn them off? That's a little hard to believe (even when they are security Swiss cheese).

Seeing the operational capability of Mossad in Iran means if desired, one should assume the US and China are equally capable. The US didn’t make a space force to please the ego, it was likely to occur eventually. They aren’t spending all their time wargaming a moon invasion lol Logistically, hacking tons of different model routers is not feasible. It would be more useful to yank the power grid.. which can be accompli…

I'm not sure what you're suggesting, exactly, but we seem to have escalated from "kill the consumer-grade WiFi routers" to "kill the entire US power grid" in one post? If anyone did that, with missiles or software, things are going to escalate very quickly from there.

Re: FCC updates covered list to include foreign-made consumer routers

#176
post #51
post #38

Earlier quoted context omitted.

Are you saying that other manufacturers don't do this?

If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable. Not so with China. (That is not to say that the FCC change will move the needle on the underlying issue of router security; as some of the ancestor comments have said, lax security practices are common industry-wide, irrespective of country of development/manufacture.)

The Snowden leak showed that Cisco routers had been altered to enable surveillance [1]. Whether or not the manufacturer is complicit, or how the alteration is performed is ultimately irrelevant to the end user. Ultimately, the only people that got in legal trouble for this were Snowden and people who provided service to him.

[1]: https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...

Re: FCC updates covered list to include foreign-made consumer routers

#177

This part of the press release seems pretty crucial: > Producers of consumer-grade routers that receive Conditional Approval from DoW or DHS can continue to receive FCC equipment authorizations. In other words, foreign-made consumer routers are banned by default. But if you are a manufacturer, you can apply to get unbanned ("Conditional Approval"). In the FAQ ( https://www.fcc.gov/faqs-recent-updates-fcc-covered-list…

I’m reading this as “tariffs didn’t work, so now we need different pain levers to wield against trading partners to bully them at the expense of consumers”.

Re: FCC updates covered list to include foreign-made consumer routers

#178

Earlier quoted context omitted.

All routers ship with software. (edit: and RAM!) (edit: and NOT multiple video outputs!!)

x86 multi NIC barebone fanless PC is not for routing, nope.

It definitely could be! And some people do use it for that!

(edit: but it's not considered a consumer grade router, that's for sure!)

Re: FCC updates covered list to include foreign-made consumer routers

#179

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

That’s a technical solution to a business and incentives problem.

How does one ensure the support for the devices is funded?

Re: FCC updates covered list to include foreign-made consumer routers

#180

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

> And "require longer support" doesn't fix it because many of the vendors will go out of business.

Which is not a real issue in practice. It's like arguing that warranty doesn't matter because the vendor might go out of business.

Post reply on HN