Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

241–250 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#241

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…

[flagged]

Re: FCC updates covered list to include foreign-made consumer routers

#242

Earlier quoted context omitted.

> foreign-made consumer routers can still be sold, but they are going to look at them with a fine-tooth comb, and they are going to use FCC approval as leverage to try to increase domestic manufacturing That is not what's going to happen. What's going to happen is that anyone coughing up payola to the current executive in chief's people will get approved, and anyone that doesn't will remain blocked. This practice is…

We're going to keep seeing this in all kinds of industries throughout the next three or so years: "Your products are banned or your country is tariffed, but if you pay enough in bribes, er I mean undergo our approval process, then you'll be exempt."

to me the greatest damage the trump admin is doing is bringing out corruption in the open.

if there's really one thing that destroys countries is corruption. being originally from a 3rd world country - I have seen it. now the US is heading towards the same path.

having worked in the IOT industry before - I can tell even domestic manufactures will be forced to pay bribes soon cloaked in 'state secrets' - there's already export laws etc - but now they will be forced to pay for compliance e.g maybe donating the president's vanity project.

Re: FCC updates covered list to include foreign-made consumer routers

#243
post #3

> all consumer-grade routers produced in foreign countries Are there even consumer-grade routers that are produced in the USA...?

> consumer-grade routers that are produced in the USA Starlink?

X-The Everything router, now with 'Mecha Hitler' built in!

Re: FCC updates covered list to include foreign-made consumer routers

#244
post #188

Earlier quoted context omitted.

I could see why someone might be confused in the Mayer of what the FCC can regulate, considering that it regulates the content of television and radio broadcasts and somehow regulates cable TV providers, despite the use of wired connections to customers, instead of radio transmissions.

Where in the Federal Communications Commission's governing legislation does it say that they're only allowed to regulate things sent through the airwaves?

It applies to communications over radio or wire: “The provisions of this act shall apply to all interstate and foreign communication by wire or radio and all interstate and foreign transmission of energy by radio, which originates and/or is received within the United States, and to all persons engaged within the United States in such communication or such transmission of energy by radio, and to the licensing and regulating of all radio stations as hereinafter provided…”

Re: FCC updates covered list to include foreign-made consumer routers

#245
The Spirit of this law __must__ also now apply to SoCs produced by non-allied nations that feature USFCC-approved RF microelectronics, such as __ESP32__ Here's to hoping USFCC gets around to also reflecting this in the Letters of this law sooner, rather than later.

[cue https://youtu.be/EnIm71jRb_o]

Re: FCC updates covered list to include foreign-made consumer routers

#246
post #74

Earlier quoted context omitted.

How do you see firmware becoming more open without copyright exactly?

Not prosecuting people trying to reverse engineer any kind of software would be a great start...

Most of this software is already GPL.

Re: FCC updates covered list to include foreign-made consumer routers

#247

Does it occurs to someone that in this time of encryption backdoor and such, this is also a good starting point to another mass surveillance system ? Mandate US manufacturers to embed remote access for the use of the government, then as you've made those routers the only ones authorized on the us soil (let's not be foolish about that approval process, it will be a smoke screen) you basically have a backdoor to every…

My sister in laws xfinity router / app has a new feature banner for “detecting motion in your house with WiFi for no additional cost”

I took a screenshot to share if anyone is interested

Re: FCC updates covered list to include foreign-made consumer routers

#248

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…

[flagged]

Re: FCC updates covered list to include foreign-made consumer routers

#249

Earlier quoted context omitted.

> Somebody has to pay for the support. There is no free meal. The problem is not that people need a free meal. The problem is that people need the ability to eat some other food when the OEM's restaurant is closed or unsatisfactory.

Who creates and regularly keeps the firmware for the dozens and dozens of router models secure and up-to-date? Who ensures the maintainers for these routers are incentivized to do this competently and in a timely fashion? You haven’t answered these key questions, which are equally or more important than whether a community firmware can be applied.

It would be ideal if we could come up with a way to get people paid to maintain a community firmware. However, that's a considerably harder problem than "you absolutely must allow community firmware to be flashed".

Re: FCC updates covered list to include foreign-made consumer routers

#250
Yeah, it does sound like this should be focused on verifying firmware, including all future updates. If a Chinese company builds the router at a US Foxconn site, it is still the same situation.

If worried about supply chain and inside jobs, I worry more about the IoT widgets I have. They are already inside the LAN, can access the internet, etc.

Anyway, bribes aside, this is probably just a talking point and not much actually changes.

Post reply on HN