Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

261–270 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#261

If war breaks out you better bet a bunch of equipment will turn off. Numerous papers showing the ability to easily map indoors areas with WiFi (including occupancy) it’s a liability. There will be excuses “tariffs” etc but I heard a few have gotten calls from three letter agencies coyly telling you to improve your systems. It’s a chance to refresh the product line! (of course at the worst time when mem prices are ble…

Occupancy sensing is a FEATURE on comcast home routers. It notifies you if someone is moving in the house and probably sells the occupancy data also. Makes location data from other sources far more valuable and verifiable.

Re: FCC updates covered list to include foreign-made consumer routers

#262

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

Congratulations, your router now costs $700!

Re: FCC updates covered list to include foreign-made consumer routers

#263
will this be like "product of USA" potatoes?, where a canadian truck full of bags of potatoes backs up to a special border facility, and the bagged potatoes are put on a conveyor, dumped out, conveyed........, and then rebagged,thereby becoming american product!

Re: FCC updates covered list to include foreign-made consumer routers

#264

Does it occurs to someone that in this time of encryption backdoor and such, this is also a good starting point to another mass surveillance system ? Mandate US manufacturers to embed remote access for the use of the government, then as you've made those routers the only ones authorized on the us soil (let's not be foolish about that approval process, it will be a smoke screen) you basically have a backdoor to every…

My sister in laws xfinity router / app has a new feature banner for “detecting motion in your house with WiFi for no additional cost” I took a screenshot to share if anyone is interested

Questions of mass surveillance aside, I always wonder how useful these things (motion detection when you're not home) actually are given how many American households have dogs and cats.

Re: FCC updates covered list to include foreign-made consumer routers

#265

Earlier quoted context omitted.

The main thing you need is for the lowest-level code to be open and replaceable/patchable because it's the only part which is actually specific to the device. Windows running on Core Boot is a better place to be than custom Linux running on opaque blob, because in the first case you can pretty easily get to newer Windows, vanilla Linux or anything else you want running on Core Boot after the original version of Windo…

Modern coreboot depends on opaque blobs on CPU (FSP/ACM on Intel) and auxiliary processors (ME/PSP), but AMD is moving in the right direction with OpenSIL host firmware. Arm devices have their own share of firmware blobs. A decade of security updates for routers would require stable isolation between low-level device security and IoT vendor userspace. In Sphere, the business model for 10 years of paid updates was bac…

>Anyone know why it didn't get market traction?

Oh gee. Maybe because no one sane looks at an industrial product adversarially built to confine and prevent the end user from doing anything to it and wants anything to do with it? It isn't rocket science. If I can't buy it and get a damn manual and programming tools to twiddle all the bits, I'm not adopting. Not even at gunpoint, or if you're the last supplier on Earth. I won't be held voluntarily hostage because a bunch of corporate types, and bureaucrats decided to work together to normalize adversarial silicon. Multiply by everyone I know, and anyone with enough braincells to rub together to pattern match "regulatory capture" and "capitalist rent seeking". You can call me a bore if you want. The incentives are completely unaligned, as this place is so fond of saying. End user adoption is built on faith in product. End user capacity to have faith in the product is based on the capability of the technically savvy purchaser to keep the thing running, repair, understand, and explain it to the non-technically savvy. I look at adversarial silicon isolating me from the hardware; I have to sound off-my-rocker to my non tech-savvy friends family to actually explain that yes, there are industrial cabals out to keep you from doing things with the thing you bought.

It doesn't make any business sense, or practical sense whatsoever. Don't bother quoting regulations that demand the isolation (baseband processors and radio emission regulations) at me. Yeah. I know. I've read those too.

Get over business models that require normalized game theory, and we can talk. Until then, enjoy never having nice things catch on. Hint: your definition of "nice" (where I can't control how it works after purchase) is mutually exclusive with things I'm willing to syndicate as "nice". Nice people don't manipulate others.

Re: FCC updates covered list to include foreign-made consumer routers

#266
post #72

Does anyone even have a list of US produced routers? Like does installing OpenWRT or OPNSense or VyOS matter? I can’t think of a complete start to finish, OS to mosfets, computer that is 100% manufactured in the United States.

If their "made in america" goal was anything but a sham, system76 would be getting huge government contracts right now.

Re: FCC updates covered list to include foreign-made consumer routers

#267

Earlier quoted context omitted.

Encrypting data at rest is security theatre right? Unless consumers control the keys (which they generally dont want to), the keys will have to be accessible by the system storing the data. So if the system is compromised so are the keys? Like I cannot see the security benefits from encrypting data at rest in a non E2E system.

It's a whole lot easier to store the keys in a special hardened location than it is to store your whole storage.

Right but access to those keys will be available in an unhardened location then? Otherwise you're serving encrypted data. So if the system accessing the data and using the keys is compromised, which we can assume is the case if the data is compromised, then access to the keys is as well?

Maybe I'm being an idiot but it seems like a lot of extra complexity to protect against really only physical attacks where someone directly steals the data storage.

Re: FCC updates covered list to include foreign-made consumer routers

#268

Earlier quoted context omitted.

Lmao you're an IT guy, right? Get yourself a Raspberry Pi 5, PCIe adapter and a second hand gigabit Intel NIC. Slap a case on that, put OpenWRT on it and bam! High performance, high quality router built from trustworthy parts running open source operating system. Not the prettiest and simplest solution but at least that way you don't have to depend on Realtek chips and Chinese firmware.

Pi 5 can't come close to handling gigabit wireguard tunnels. I can do an x86 build that will, but still, incredibly aggravating.

You'll probably see better performance with a non-wireguard VPN with the RP5 since it has hardware accelerated AES instructions.

Re: FCC updates covered list to include foreign-made consumer routers

#269
post #92

Earlier quoted context omitted.

> This includes the FCC which license their devices The FCC licenses devices to the extent that devices can cause spurious transmissions in the radio spectrum. It’s not a general consumer protection agency. Computer security also is outside the mandate of the FTC, which exists to protect consumers from anticompetitive conduct and unfair business practices, not crappy products.

I could see why someone might be confused in the Mayer of what the FCC can regulate, considering that it regulates the content of television and radio broadcasts and somehow regulates cable TV providers, despite the use of wired connections to customers, instead of radio transmissions.

> somehow regulates cable TV providers, despite the use of wired connections

They regulate broadcast TV. Those rules leak into cable TV because the originators generally want content that can be sold for broadcast in the future and is advertiser friendly. Cable operators are also often beholden to community standards imposed by municipalities they serve. The FCC isn't responsible for content restrictions on cable.

Re: FCC updates covered list to include foreign-made consumer routers

#270

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

If they cared about security they'd mandate time to fix for the found vulnerabilities, or outright requested the source to be available
Post reply on HN