Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

231–240 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#231
post #3

> all consumer-grade routers produced in foreign countries Are there even consumer-grade routers that are produced in the USA...?

Qualcomm is a US company right? I've worked on a few WiFi router devices and their chips are pretty popular in that segment. But WiFi is not a priority for Qualcomm (in fact they actively sabotage it for their more profitable 5G segment), and software is even less of a priority. So you had "parsing 802.11 TLVs in the kernel with obvious stack overflows" quality code drops.

(Which is why it's a bit ironic I saw the Google Fiber guy post on X about how they always had TPM^TM "security" in their routers; thats cool, but the drivers you used still made them "general purpose computing over the air" devices)

Re: FCC updates covered list to include foreign-made consumer routers

#232

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> no Gov agency would ever mandate secure firmware

Interestingly, Europe is about to try this: the Cyber Resilience Act is going to become obligatory for all sold digital products (hardware & software) by the end of 2027, with a bunch of strict minimum requirements: no hardcoded default passwords, must check for known vulnerabilities in components/dependencies, encryption for data at rest, automatic security updates by default (which must be separate from functionality updates), etc.

Remains to be seen whether this'll help, but good to see somebody have a go at fixing this.

Re: FCC updates covered list to include foreign-made consumer routers

#233
post #51
post #38

Earlier quoted context omitted.

Are you saying that other manufacturers don't do this?

If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable. Not so with China. (That is not to say that the FCC change will move the needle on the underlying issue of router security; as some of the ancestor comments have said, lax security practices are common industry-wide, irrespective of country of development/manufacture.)

When was the last time American intelligence agencies were held accountable?

Literally your own Congress is not even allowed to review their budget! Not that any US politician even WANTS to know.

Re: FCC updates covered list to include foreign-made consumer routers

#234
post #3

> all consumer-grade routers produced in foreign countries Are there even consumer-grade routers that are produced in the USA...?

Guys from heise.de [1] haven't found any.

[1] https://www.heise.de/en/news/USA-bans-all-new-routers-for-co...

Re: FCC updates covered list to include foreign-made consumer routers

#235

What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers! Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?

Lmao you're an IT guy, right? Get yourself a Raspberry Pi 5, PCIe adapter and a second hand gigabit Intel NIC. Slap a case on that, put OpenWRT on it and bam! High performance, high quality router built from trustworthy parts running open source operating system. Not the prettiest and simplest solution but at least that way you don't have to depend on Realtek chips and Chinese firmware.

Re: FCC updates covered list to include foreign-made consumer routers

#236

Does it occurs to someone that in this time of encryption backdoor and such, this is also a good starting point to another mass surveillance system ? Mandate US manufacturers to embed remote access for the use of the government, then as you've made those routers the only ones authorized on the us soil (let's not be foolish about that approval process, it will be a smoke screen) you basically have a backdoor to every…

This is why users need to have an american router, chinese router, and russian router, all wired in series. That way no one spy branch has full backdoor access through the chain ;-)

How would that work? Backdoors usually go the other way: malware calls home. How can the first router in the chain differentiate TLS backdoor traffic from the 3rd router (the one with access to your LAN) from legitimate traffic from LAN?

Re: FCC updates covered list to include foreign-made consumer routers

#237

Earlier quoted context omitted.

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

> What you need is not a government mandate for infallibility, it's updates So, we don't need an electrical code to enforce correct wiring. We just need a kind soul driving by our house to notice the company who built our house wired it up wrong. Then that kind person can inform the company of the bad wiring. And if the company agrees it's their wiring at fault, we can wait 3 months for a fix. Then the next month ano…

Routers have to follow the same standards as other electrical appliances.

Those standards aren’t related to the functionality or security of the router.

Re: FCC updates covered list to include foreign-made consumer routers

#238
This is terrible, perhaps the worst thing this administration has done (which is an incredibly high bar.)

Because it provides a pathway to full government control of the internet.

Content that demonizes the current administration's enemies will become easier to find. Evidence of their crimes will vanish.

When they murder someone in the street, fewer people will find out about it, and those that do will be more likely to hear the government's side of the story.

Mobile networks are already owned by the billionaires, and they've shown plenty of willingness to shape traffic for their interests.

Managing this kind of information at scale is an incredible challenge, but one that LLMs are very well suited for.

Even if you are confident the current administration doesn't have the competence or longevity to exploit this (as I mostly am,) we can easily predict future admins of either party will happily make use of these capabilities.

Bad for the US, but also very bad for the world, because it will make it much easier to manufacture consent for or hide future international crimes committed by the government.

We've excused the complete loss of traditional journalism with a reliance on the Internet instead. Not anymore.

Can savvy individuals work around it, of course. But the general public will treat them like conspiracy theorists, because all they will see is content that reinforces the administration.

The technical discussions in here sound like: "silly Caligula, his horse won't be able to sign his name to cast a vote in the Senate."

Re: FCC updates covered list to include foreign-made consumer routers

#239
post #154

Earlier quoted context omitted.

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

> What you need is the ability for consumers to replace the firmware. I don't think that's enough. Most people aren't going to replace the firmware on their device with an open source replacement made by someone else. Now if the firmware was required to be open source, and automatic updates could be seamlessly switched over to a non-profit or government agency in the event of the company going out of business, you mi…

If you make something internet commected you must provide lifetime warranty for security. no import or sales sor even leases) until you have in escrow the money to pay for them.

i will allow sunsetting and removing ipv4 after 2020 (that is more that 5 years ago)

Re: FCC updates covered list to include foreign-made consumer routers

#240
post #210
post #180

Earlier quoted context omitted.

> And "require longer support" doesn't fix it because many of the vendors will go out of business. Which is not a real issue in practice. It's like arguing that warranty doesn't matter because the vendor might go out of business.

It might also be illegal. Don't know about the US but forcing a bankruptcy to avoid regulations is usually frowned upon by the court system here. So putting a product in a child-dummycorp to go poof when you want and let the parent stay afloat usually puts the parent in the line of fire directly and you are screwed either way.

It is possible to require escrow accounts for cover costs of fixing future security issues) - these survive bankruptcy. They need to be big enough to cover the costs though - insurance can calculate this but it isn't cheap.
Post reply on HN