Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

271–280 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#271

This part of the press release seems pretty crucial: > Producers of consumer-grade routers that receive Conditional Approval from DoW or DHS can continue to receive FCC equipment authorizations. In other words, foreign-made consumer routers are banned by default. But if you are a manufacturer, you can apply to get unbanned ("Conditional Approval"). In the FAQ ( https://www.fcc.gov/faqs-recent-updates-fcc-covered-list…

> but they are going to look at them with a fine-tooth comb

This comb likely is designed to extract loose $1M checks from the foreign manufacturers.

Re: FCC updates covered list to include foreign-made consumer routers

#272

What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers! Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?

Lmao you're an IT guy, right? Get yourself a Raspberry Pi 5, PCIe adapter and a second hand gigabit Intel NIC. Slap a case on that, put OpenWRT on it and bam! High performance, high quality router built from trustworthy parts running open source operating system. Not the prettiest and simplest solution but at least that way you don't have to depend on Realtek chips and Chinese firmware.

There is an entire WORLD that lives in your computer below the operating system (eg, OpenWRT). For example, in your Raspberry Pi 5, there is a chip called the VideoCore GPU and it contains a big blob of code known only to Raspberry Pi Foundation and, perhaps, Five Eyes. The Chinese processors are like that too!

Even if you have the source and build system to recreate the exact binary blob and can reload it with Jedec or whatever, there is another world below the firmware...called microcode. Some of the microcode comes from the FAB preloaded! Even if you can get the source code for the microcode and somehow read it out and verify it is the same, you guessed it...there is another world below that [1 https://www.researchgate.net/publication/380555600_Trustwort... ] [2 https://dl.acm.org/doi/fullHtml/10.1145/3579856.3582837 ] [3 https://ieeexplore.ieee.org/document/7546493 also https://www.semanticscholar.org/paper/A2%3A-Analog-Malicious... ]

Re: FCC updates covered list to include foreign-made consumer routers

#273
post #215

Earlier quoted context omitted.

I'm no fan of imaginary property, but you're going to have to lay out your reasoning here. Firmware security is such crap precisely because most hardware manufacturers see it as nothing but a cost center they wish they could avoid. The difficulty of installing OpenWRT or Linux in general on hardware comes from that hardware not being documented, or not having straightforward APIs like BIOS/EFI. Or for some devices, c…

> not having straightforward APIs like BIOS/EFI. Oh, no, not this again! > But we generally see that as soon as the manufacturer stops their updates, the community versions start lagging behind as well. Care to demonstrate that? The reason OpenWrt abandoned most routers was 1) insufficient flash space in the kernel partition, or insufficient total flash space in no-USB, no-SPI routers, 2) unwillingness to repartition…

> Oh, no, not this again!

What are you referring to? Would you not say there is a difference between OpenWRT having to make a list of supported whole systems, whereas an amd64 Linux distribution making a list of chipsets? I can go buy an off the shelf laptop, stick a generic "Linux install" USB in it, and be reasonably certain most things are going to work. Whereas OpenWrt I have to look at their list of supported machines, and buy exactly that one, even down to the hardware rev. Some of this is due to embedded constraints, but a good chunk is also due to the lack of hardware discoverability.

>> community distributions that dubiously remix manufacturer-supplied binaries are available

> The reason OpenWrt abandoned most routers was

I didn't mean things like OpenWrt, which I'd say is a general Linux distribution that does contortions to fit on specific devices. Rather I was talking about things like Valetudo which are closer to rooting the stock distribution with some tweaks, or the countless "custom ROMs" you see (saw?) in the phone world which are effectively remixing the manufacturer images. I thought DD-WRT was in that camp, especially for many devices (eg where do these "older kernels" come from?), but I'm hazy on that.

(personally I gave on up OpenWrt some 10 years back, and just use generic Linux (NixOS) on amd64. A VM on my server for the router, and lower-power amd64 boards for the additional APs (most of which double as Kodi terminals))

Re: FCC updates covered list to include foreign-made consumer routers

#274
post #225
post #176

Earlier quoted context omitted.

The Snowden leak showed that Cisco routers had been altered to enable surveillance [1]. Whether or not the manufacturer is complicit, or how the alteration is performed is ultimately irrelevant to the end user. Ultimately, the only people that got in legal trouble for this were Snowden and people who provided service to him. [1]: https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...

Actually it's entirely relevant how, in the context of this conversation. Here, we're discussing product as shipped, not product intercepted and modified. We're discussing if products are shipped secure or not. The Snowden disclosures are important, but not relevant in this case.

It is absolutely relevant. It is completely within the realm of feasibility that a foreign nation state would pressure a manufacturer in their jurisdiction to include a backdoor, or simply insert it themselves. Routers are in every home and office in the country, and can be leveraged for immense attacks. It’s a hugely attractive target, and it’s a reasonable security policy to try to limit our exposure to this threat. And it would absolutely make sense for adversaries to avoid buying U.S. made routers for exactly the same reason. Unfortunately this administration is generating more adversaries by the day.

Re: FCC updates covered list to include foreign-made consumer routers

#275

Earlier quoted context omitted.

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

>The problem is that "secure firmware" is a relativistic statement. No it isn't, software formally verified to EAL7 is guaranteed to be secure.

It's guaranteed to have more paperwork. Actually secure, maybe.

Re: FCC updates covered list to include foreign-made consumer routers

#276
post #213

Earlier quoted context omitted.

I think we all know that's never going to happen.

I don't understand why people with this opinion think it's worth the effort to post it.

There's a whole interesting physiology behind learned helplessness (of which this is a minor variation).

In its defense, there's some practicality to it; we wouldn't say that a "get out of debt" plan that involved spending all available money on lottery tickets is worthwhile because "its not gonna happen". But defeatism is just a shortcut to say "I don't want to talk/think about it" in many cases.

And in this one, if the US Gov't required that all routers purchased by any agency they could influence had the ability to run open source code it would certainly shake up the market.

Re: FCC updates covered list to include foreign-made consumer routers

#277

Earlier quoted context omitted.

> foreign-made consumer routers can still be sold, but they are going to look at them with a fine-tooth comb, and they are going to use FCC approval as leverage to try to increase domestic manufacturing That is not what's going to happen. What's going to happen is that anyone coughing up payola to the current executive in chief's people will get approved, and anyone that doesn't will remain blocked. This practice is…

That descriptions already fits the payola model. It's almost never about directly handing money to a politician. That's illegal, so it's not worth doing when there's legal ways to do it. Instead, payola usually involves regulations requiring using some kind of product or certification, then the organizations that sell the product or perform the certification contribute to the politicians. Also, the biggest benefactor…

> It's almost never about directly handing money to a politician. That's illegal

According to SCOTUS in Snyder v. United States, if the payment occurs after the official act, it's a perfectly legal "gratuity."

Re: FCC updates covered list to include foreign-made consumer routers

#279

Earlier quoted context omitted.

Who creates and regularly keeps the firmware for the dozens and dozens of router models secure and up-to-date? Who ensures the maintainers for these routers are incentivized to do this competently and in a timely fashion? You haven’t answered these key questions, which are equally or more important than whether a community firmware can be applied.

It would be ideal if we could come up with a way to get people paid to maintain a community firmware. However, that's a considerably harder problem than "you absolutely must allow community firmware to be flashed".

I agree. It's a harder problem and it's the more critical problem.

Businesses aren't incentivized to maintain it and hoping that the community can support it by opening it is perhaps necessary, but it's far from sufficient.

Either the business or maintainers need to be sufficiently incentivized--whether it's through funding, reputation, or something else (graduate-student torture).

Re: FCC updates covered list to include foreign-made consumer routers

#280

Earlier quoted context omitted.

Modern coreboot depends on opaque blobs on CPU (FSP/ACM on Intel) and auxiliary processors (ME/PSP), but AMD is moving in the right direction with OpenSIL host firmware. Arm devices have their own share of firmware blobs. A decade of security updates for routers would require stable isolation between low-level device security and IoT vendor userspace. In Sphere, the business model for 10 years of paid updates was bac…

>Anyone know why it didn't get market traction? Oh gee. Maybe because no one sane looks at an industrial product adversarially built to confine and prevent the end user from doing anything to it and wants anything to do with it? It isn't rocket science. If I can't buy it and get a damn manual and programming tools to twiddle all the bits, I'm not adopting. Not even at gunpoint, or if you're the last supplier on Earth…

> If I can't buy it and get a damn manual and programming tools to twiddle all the bits, I'm not adopting.

Hence the isolated device security hardware should be an open standard with FRAND licensing. If devices ship with a prepaid commercial license for 10 years of device security updates from BIG_CO, the default commercial baseline would be raised independent of IoT vendors. Tech-savvy users could then have the option to replace the device security layer with the OSS _or_ competing commercial stack of their choice.

Post reply on HN