Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

281–290 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#281

Earlier quoted context omitted.

> What you need is not a government mandate for infallibility, it's updates So, we don't need an electrical code to enforce correct wiring. We just need a kind soul driving by our house to notice the company who built our house wired it up wrong. Then that kind person can inform the company of the bad wiring. And if the company agrees it's their wiring at fault, we can wait 3 months for a fix. Then the next month ano…

I mean, if you could download an update that would fix the wiring in your house, it would be much less critical that the initial installer got it right. (Still much more important than your router, though; it doesn't stop being an electrocution hazard during the un-updated period.) Trying to make analogies from software to hardware will always fall down on that point. If you want to argue that there should be stricte…

> I mean, if you could download an update that would fix the wiring in your house, it would be much less critical that the initial installer got it right

As in my example, some random stranger needs to first find out your "house" (the vendor's software) is wired wrong. And this needs to happen for every "house" (every piece of software). While waiting for this to be discovered, your house burns down (hackers penetrate millions of devices, or perhaps just Microsoft Sharepoint that the govt is uses).

Re: FCC updates covered list to include foreign-made consumer routers

#282

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

So after two decades, the FCC finally does something about insecure routers by banning security updates unless you jump through a bunch of extra hoops. That's definitely going to improve the situation.

Re: FCC updates covered list to include foreign-made consumer routers

#283
post #274
post #225

Earlier quoted context omitted.

Actually it's entirely relevant how, in the context of this conversation. Here, we're discussing product as shipped, not product intercepted and modified. We're discussing if products are shipped secure or not. The Snowden disclosures are important, but not relevant in this case.

It is absolutely relevant. It is completely within the realm of feasibility that a foreign nation state would pressure a manufacturer in their jurisdiction to include a backdoor, or simply insert it themselves. Routers are in every home and office in the country, and can be leveraged for immense attacks. It’s a hugely attractive target, and it’s a reasonable security policy to try to limit our exposure to this threat…

I think you're responding to the wrong comment, or missing the nuance above.

Having state actors redirecting products after shipping, without telling the company or the client it's happening, and installing backdoors, has nothing at all to do with backdoors from manufacturers.

Re: FCC updates covered list to include foreign-made consumer routers

#284

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

>And "require longer support" doesn't fix it because many of the vendors will go out of business.

Do you mean 'out of business so they cannot provide updates'?

Because, if you mean cheap companies won't be able to provide updates and stay in business, surely that's the point. Companies would have to shim to a standardised firmware that was robust, or something, to keep costs down.

Isn't this all to protect USA business interests and ensure the Trump regime can install their own backdoor though?

Re: FCC updates covered list to include foreign-made consumer routers

#285
post #207

Earlier quoted context omitted.

> What you need is not a government mandate for infallibility, it's updates So, we don't need an electrical code to enforce correct wiring. We just need a kind soul driving by our house to notice the company who built our house wired it up wrong. Then that kind person can inform the company of the bad wiring. And if the company agrees it's their wiring at fault, we can wait 3 months for a fix. Then the next month ano…

> So, we don't need an electrical code to enforce correct wiring. For an analogy to work, its underlying elements should have a relation to the target. Your analogy is not in the same universe. For electrical work, there is a baseline of materials and practices which is known to produce acceptable results if adhered to. For software, there isn't. (Don't tell me about the Space Shuttle. Consumer software doesn't cost…

The analogy does work. The house is any software provided by any vendor. The kind strangers are white hat security researchers. The people living in the house are the users.

Software absolutely has baseline materials, have you never written software before? Never used a library? Programming language? API? Protocol? Data format or specification? CPU instruction? Sorting algorithm? A standard material is just a material tested to meet a standard. A 10d nail is a 10d nail if it meets the testing specs for 10d nails (ASTM F1667). Software can be tested against a spec. It's not rocket surgery.

No known practices with acceptable results?? Ever heard of OWASP? SBOMs? Artifact management? OIDC? RBAC? Automated security scanning? Version control? Code signing? Provenance? Profiling? Static code analysis? Strict types? Formal proofs? Automated testing? Fuzzing? Strict programming guidelines (ex. NASA/DOD/MISRA/AUTOSAR)? These are things professionals know about and use when they want standard acceptable results.

What are you talking about re: space shuttle and tens of millions? Have you actually read the coding standards for Air Force or NASA? They're simple, common-sense guidelines that any seasoned programmer would agree are good to follow if you want reliability.

I think the problem here is there's too many armchair experts saying "Can't be done" when they don't know what they're talking about, or jaded old fogeys who were on some horrible government project and decided anything done with rigor will be terrible. That's not the way it is in the trades, in medicine, in law, and those folks actually have more to think about than software engineers, and more restrictions. I think SWEs are just trying to get out of doing work and claiming it's too difficult, and the industry doesn't want to stop the free ride of lack of accountability it's had for decades.

AI is going to introduce 100x more security holes than before, so something will have to be done to improve security and reliability. We need to stop screwing around and create the software building code, before the government does it for us.

Re: FCC updates covered list to include foreign-made consumer routers

#286

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices.

True, but the country of manufacture is related to the risk of back doors.

There is a huge security problem (everywhere, not just the US) with insecure consumer devices (not just routers, everything from Wi-fi enabled lightbulbs to cars). AT least someone seems to be waking up to the problem even if their solution is half-baked.

Re: FCC updates covered list to include foreign-made consumer routers

#287
post #154

Earlier quoted context omitted.

> What you need is the ability for consumers to replace the firmware. I don't think that's enough. Most people aren't going to replace the firmware on their device with an open source replacement made by someone else. Now if the firmware was required to be open source, and automatic updates could be seamlessly switched over to a non-profit or government agency in the event of the company going out of business, you mi…

I have a PC hooked up to my TV in my living room that has been running the latest version of Kubuntu for over 18 years now. It has had many upgrades in that time but it's still the same basic hardware: A CPU, some memory, USB ports, a video card, and an ethernet port on the back. That "genericness" is what's missing in the router space. Literally every consumer router that comes out has some super proprietary design…

> They key point remains, however: They're not just hardware—even though they should be!

This is the most thoughtful comment I've seen on this topic. I hadn't even considered this approach, but you're right. The hardware needs to be commoditized in a way that makes the software a layer that can be replaced. Someone else said this but in a way that described flashing a third-party package as HN nerds would. That's too much effort and it won't work.

It should be as generic as PC hardware. Every router manufacturer should build devices that can run the OSes of all their competitors' devices and vice versa. Maybe some features won't work with the other company's OS cause it isn't designed for that, but overall it ought to be replaceable. "Normal people" still wouldn't flash a new OS, but making it an option is a step towards making devices more secure.

If every router could get a new OS as easily as your techy friend could install Firefox or an ad-blocker or whatever else, we'd start the long march to a real longterm solution.

Re: FCC updates covered list to include foreign-made consumer routers

#288
post #3

> all consumer-grade routers produced in foreign countries Are there even consumer-grade routers that are produced in the USA...?

The only one I know of: https://www.islandrouter.com/

> In conjunction with original software development, Island is designed and assembled in the USA to improve security and enable tighter quality control throughout the entire production process. The code for Island routers has only been loaded internally at Island HQ in the U.S; customer support is also managed directly in our U.S. Headquarters.

Re: FCC updates covered list to include foreign-made consumer routers

#289

If war breaks out you better bet a bunch of equipment will turn off. Numerous papers showing the ability to easily map indoors areas with WiFi (including occupancy) it’s a liability. There will be excuses “tariffs” etc but I heard a few have gotten calls from three letter agencies coyly telling you to improve your systems. It’s a chance to refresh the product line! (of course at the worst time when mem prices are ble…

"Will turn off"... are you claiming that consumer-grade routers have a secret backdoor kill switch that one government or another can use to turn them off? That's a little hard to believe (even when they are security Swiss cheese).

The DOCSIS (Data Over Cable Service Interface Specification) standard for cable internet end user routers specifies total remote control. Most ISP originated routers are set up this way.

Re: FCC updates covered list to include foreign-made consumer routers

#290

Ask HN: Is there a list of preferred routers for security?

A Palo Alto 440 is what I would consider a baseline for 'real' security. Way too expensive and complicated for most if not all home users.

I keep recommending the free version of Sophos firewall for home users. It's still a bit of a bear to configure.

Post reply on HN