Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

241–250 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#241

Earlier quoted context omitted.

Maybe that figure would change if the firmware could indeed be updated.

It would change, but again -- it wouldn't be appreciable. Security policy is needed that accounts for the behaviors of the vast majority of users.

Users update their phones, there's no reason they can't be educated to update their other devices

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#242

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

> If consumers actually cared about their IoT devices receiving security updates, companies would be doing it.

This seems like a crazy response to me.

The _entire_ program is _voluntary_. If a manufacture doesn't want to jump through any hoops the only downside is that they don't get an "FCC cybersecurity" label on it. So if the customers _actually_ don't care, then don't do the program and don't get the sticker on the box.

The _only_ reason for anyone to complain about this program is that customers _DO_ fucking care, and _want_ to be informed. Customers _want_ to purchase more secure products but do not have the option, and do not have the information required to do so.

It's not even a mandate that they have X years of security updates. They just have to _disclose_ how many years of security updates they are providing. They could disclose that they provide 3 months of security updates if they want to. If that hurts sales, it's only because PEOPLE ACTUALLY CARE about this.

If your theory is accurate, then this proposed rulemaking would have 0 effect on industry at all.

> As a consumer, I do not want the FCC mandating what features will be included in my IoT devices.

That's not the proposal. The proposal is the FCC mandates what features are included in your IoT devices that have an "FCC cybersecurity" label on it.

> If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it. I fought hard for one of these criteria to be the disclosure of how long the product will receive security updates

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#243

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

>Please do not propose this regulation. If consumers actually cared about their IoT devices receiving security updates, companies would be doing it. The fact that companies are not already doing this is evidence it's not important to consumers. People may express frustration, but their purchasing behavior speaks louder than their words.

In 1980 11% of American adults used automobile seat belts.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#244
First and foremost I applaud the effort. I think this is a worthwhile concept. However, I think this is something that would be better if the FCC delivered a report asking for specific things to congress. Because while we can look at this just through the IOT lens I think that's very shortsighted. There are CNC shops still running DOS and Windows95. So what happens when the new fancy CNC they are buying today running Windows 11 embedded goes out of support from MS? These are things that are intended to be in use for 30+ years.

So to me there needs to be a formal process in the law for dealing with abandonment, and minimum support duration.

1. Minimum support duration: This needs to be in federal law and enforced by private right of action, and more specifically one that cannot be waived or arbitrated. This cannot be something that the FCC or FTC must enforce. This must also be binding with valid legal remedies if the company fails to comply or no longer exists. Which leads me to my next point.

2. Abandonment: The law must require that if an OEM abandons a device that sufficient information (including PCB schematics and PCB BOMs!) are made public that both individuals and third party commercial operations can supply support. Again, this must have legal remedy to enforce. My preferred remedy if a company completely fails to provide anything is loss of copyrights to that specific software. Thus negating all the digital locks provisions of the DMCA in regards to that specific hardware. If the company provides the necessary information under an appropriate free software and/or documentation license then they maintain all copyrights. They only need submit the information to the library of congress and a third party such as archive.org; they do not need to host it themselves. Nor would they be required to provide any support after that point. Furthermore, any components not currently in production would have to be made available until such stocks are depleted.

Having a formal abandonment process for a device including a formal notice of termination of support, and releasing appropriate documentation and necessary information to the public provides a massive boost to both ongoing security but also to reducing waste.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#245
I see the strong encouragement to post to the FCC's public comments, and you say it is highly influential - more influential than what you can do as a Commissioner.

I'm a well-informed, active citizen, and I didn't realize that. It might help to explain how that works - how do public comments influence things? My concern would have been that it depends on the FCC, and that comments could be included or ignored as desired, and probably the latter. (I want to emphasize: That would have been my concern had I not read this thread - I trust they are influential).

Thank you!

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#246
post #75

What about industrial IoT? Even if a manufacturer publishes updates, the clients would likely not want to change anything, often. If you have a plant with 1,000 units of gizmo-A and update them during a week-end and now 200 of them do not do the thing they used to do anymore... you have a big problem. There is a genuine fear to update anything in many industries and I am not sure how this can be overcome.

I'm not sure it should be overcome.

Updating software is not a panacea and not always the best thing to do. In industrial hardware it's often better to have a known quantity.

Especially with equipment that can cause damage or even kill people.

Even if it isn't quite that high stakes, dealing with constant random updates is a cost factor with no clear commercial gain.

This doesn't mean there can't be updates, but they need to be done on the factory's schedule, not on the schedule of some random supplier.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#247

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

"The fact that companies are not already doing this is evidence it's not important to consumers. People may express frustration, but their purchasing behavior speaks louder than their words."

I would like to see evidence before anyone accepts this premise as true. That's like saying smokers don't care about lung cancer, or parents don't care about lead in baby toys, as shown by their purchase behavior.

Security updates are affected by asymmetric information, widespread consumer ignorance and negative externalities. We need solid regulation.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#248

IoT devices need regulatory standardization w.r.t a few things: 1. software stack – big fat "firmware" should not exist. Entire stack should be upgradable safely, securely and frequently during its official supported lifetime and should be open-sourced for owner's own upgrades past end of life. For this, the hardware stack needs some amount of standards compliance. 2. Vendor should clearly declare/advertise the perio…

These could be great suggestions for the criteria a product must meet to quality for a label. I encourage you to file an official comment with your thoughts.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#249

[Update: I did not read the original proposal carefully. I mistakenly believed this was a mandated regulation and not a voluntary one, so some of the points in my post do not apply. However, I still oppose it for mostly the same reason: if consumers wanted this type of label on their products, then we we would likely already see it. I am also skeptical that this is being initially proposed as a voluntary program, but…

I don't think customers not caring is a valid reason to not do this. Compromised IoT devices don't only cause harm to their owners, but also external networks and the internet as a whole.

A compromised doorbell, or lightbulb etc can be used as part of a botnet to perform DDoS attacks or other nasty activities.

An analogy is like saying we shouldn't work on reducing the pollution emmitted by motor vehicles because the users of these vehicles don't care about how much pollution they cause and would buy them regardless. It's the negative externalities that we need to consider.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#250

Planned or unplanned obsolescence is good for business. You are proposing regulations counter to that, so should expect counter-pressure, even for IoT makers that want to do the right thing. By volume and impact, what devices have IoT vulnerabilities? If from large mfrs, you might expect some measure of support as that would be somewhat in their best interest, if only to preserve their brand image. My concern would b…

Planned or unplanned obsolescence is good for business. You are proposing regulations counter to that, so should expect counter-pressure, even for IoT makers that want to do the right thing. Great points. From one perspective, we can't afford to do this stuff; from another, we can't afford not to. If connectivity makes your life a little easier for little risk, that's one thing; if your dishwasher steals your identit…

> Also, what happens when an IoT mfr is acquired, does the acquirer assume all the IoT risks as well?

Most other liabilities are inherited during an acquisition. I don't see a good reason for this to be an exception.

It would encourage acquirer's to do much more strict due diligence in this regard, which will have a natural pressure to clean up the behavior of manufacturer's that plan to seek a future exit.

Any exception to liability here seems like a get out of jail free card, for all new manufacturers seeking an exit to behave extremely badly. It also opens the door to corporate shell games, where as soon as a liability is discovered it gets acquired by a thin parent entity to dissolve that liability. I'll leave a comment to that effect as well, but it absolutely seems like this liability should survive an acquisition.

Post reply on HN