Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

31–40 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#31
What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers!

Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?

Re: FCC updates covered list to include foreign-made consumer routers

#32
post #30
post #19

If you actually read the notice, it exempts models that have been approved. So this just seems to require approvals by DOH or DHS ,": Routers^ produced in a foreign country, except routers which have been granted a Conditional Approval by DoW or DHS." I take this to mean it is just adding security approvals for this type of thing to DOw and DHS. It is not a ban of all future models. It's just saying explicitly that i…

Why shouldn’t people have a reaction to a policy that mandates a new approval process on a large class of consumer products?

[deleted]

Re: FCC updates covered list to include foreign-made consumer routers

#33

What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers! Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?

Why wasn't anyone notified about this being in the works? What bulletins did I fail to notice. WHAT THE HELL IS GOING ON HERE

Re: FCC updates covered list to include foreign-made consumer routers

#34
post #18
post #17

Earlier quoted context omitted.

Are there any consumer-grade routers that aren't produced in Taiwan?

Even MikroTik routers have a supply chain scattered around the world

But most are still made in Latvia.

Re: FCC updates covered list to include foreign-made consumer routers

#35

This part of the press release seems pretty crucial: > Producers of consumer-grade routers that receive Conditional Approval from DoW or DHS can continue to receive FCC equipment authorizations. In other words, foreign-made consumer routers are banned by default. But if you are a manufacturer, you can apply to get unbanned ("Conditional Approval"). In the FAQ ( https://www.fcc.gov/faqs-recent-updates-fcc-covered-list…

Any router made by a company that "donates" (bribes) to Trump's "ballroom" or other vanity projects will get approved. Irrespective of anything else. This is just another grift.

Re: FCC updates covered list to include foreign-made consumer routers

#36

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices.

Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence.

You're not going to convince me that a foreign state actor pressuring a company to include a backdoor wouldn't disguise it as a "whoopsie, our crap code lol" as opposed to adding in the open with a disclaimer on it.

It's all closed source firmware. Even the GPL packages from most consumer router vendors are loaded with binary blobs. Tell me I should trust it.

Re: FCC updates covered list to include foreign-made consumer routers

#37
post #25

If we wanted secure products, we wouldn't ban devices. We'd mandate they open their firmware to audits.

It'd be great if open firmware could be commercially viable. Finding a business model is hard. The OpenWRT One [1] sponsored by the Software Conservancy [2] and manufactured by Banana Pi [3] works lovely. [1] https://openwrt.org/toh/openwrt/one [2] https://sfconservancy.org/activities/openwrt-one.html [3] https://docs.banana-pi.org/en/OpenWRT-One/BananaPi_OpenWRT-O...

Open firmware would become commercially viable when IP is abolished

Re: FCC updates covered list to include foreign-made consumer routers

#38

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…

Are you saying that other manufacturers don't do this?

Re: FCC updates covered list to include foreign-made consumer routers

#39
post #20

Earlier quoted context omitted.

A trusted website that compiles it from source and a way for you to go to a webpage and flash from there automatically. The FPV community does that all the time with a set of websites for their ESC, flight controllers, radio, all open source. You can add signatures etc but just a trusted website goes a long way vs a random blob preinstalled

That proves that the one they checked, had the correct firmware. It does not prove that the one from the next batch that you bought did. We are all technical people here we and understand that there isn’t really an easy way to do this that a random non-technical person could actually understand and use.

Isn't the person you're replying to suggesting people can update the firmware to the trusted version via a website? So it doesn't matter if you get one from 'the next batch' - provided you're on top of updating the firmware.

Re: FCC updates covered list to include foreign-made consumer routers

#40

This part of the press release seems pretty crucial: > Producers of consumer-grade routers that receive Conditional Approval from DoW or DHS can continue to receive FCC equipment authorizations. In other words, foreign-made consumer routers are banned by default. But if you are a manufacturer, you can apply to get unbanned ("Conditional Approval"). In the FAQ ( https://www.fcc.gov/faqs-recent-updates-fcc-covered-list…

> So, foreign-made consumer routers can still be sold, but they are going to look at them with a fine-tooth comb, and they are going to use FCC approval as leverage to try to increase domestic manufacturing.

You're assuming a non-partisan technocratic process, which this administration has amply shown is neither capable nor willing to provide. This requirement becomes another opportunity for Pay-to-Play, either in cash or quid pro quo, to the government directly (see, e.g., NVidia and AMD export allowances) or to Trump's inner circle (see, e.g., crypto venture regulation, merger approvals).

Post reply on HN