Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

311–320 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#311
post #92

Earlier quoted context omitted.

> This includes the FCC which license their devices The FCC licenses devices to the extent that devices can cause spurious transmissions in the radio spectrum. It’s not a general consumer protection agency. Computer security also is outside the mandate of the FTC, which exists to protect consumers from anticompetitive conduct and unfair business practices, not crappy products.

I could see why someone might be confused in the Mayer of what the FCC can regulate, considering that it regulates the content of television and radio broadcasts and somehow regulates cable TV providers, despite the use of wired connections to customers, instead of radio transmissions.

> despite the use of wired connections to customers, instead of radio transmissions.

The FCC also regulates interstate wire transmissions.

But ultimately, you're not quite getting it right. It's all RF, it's just that we sometimes choose a really shitty wire called "the atmosphere".

Re: FCC updates covered list to include foreign-made consumer routers

#313
post #180

Earlier quoted context omitted.

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

> And "require longer support" doesn't fix it because many of the vendors will go out of business. Which is not a real issue in practice. It's like arguing that warranty doesn't matter because the vendor might go out of business.

> Which is not a real issue in practice.

Are you serious? The number of IoT companies that make a product for a couple years and then go bust is enormous.

> It's like arguing that warranty doesn't matter because the vendor might go out of business.

How are you going to use a warranty from a company that no longer exists to get a security update for a product a million consumers still have?

Re: FCC updates covered list to include foreign-made consumer routers

#314
post #210

Earlier quoted context omitted.

It might also be illegal. Don't know about the US but forcing a bankruptcy to avoid regulations is usually frowned upon by the court system here. So putting a product in a child-dummycorp to go poof when you want and let the parent stay afloat usually puts the parent in the line of fire directly and you are screwed either way.

It is possible to require escrow accounts for cover costs of fixing future security issues) - these survive bankruptcy. They need to be big enough to cover the costs though - insurance can calculate this but it isn't cheap.

The obvious problem with that is the detriment to smaller companies, but it makes a good alternative to releasing the code.

Then if you're a five person shop making routers and you publish the firmware source under a license that allows anyone to make and distribute modifications you're all set. And if you're Apple or Microsoft and you want to make a router without publishing the source code, you post the enormous bond which you have no trouble doing because you're an enormous company and you're all set.

Re: FCC updates covered list to include foreign-made consumer routers

#315
post #262

Earlier quoted context omitted.

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

Congratulations, your router now costs $700!

Customers notice higher prices at time of purchase a lot more than they notice a lack of future security updates, so good luck selling them for that price when someone else just puts an existing open source firmware on the existing hardware and sells it for the existing price.

Re: FCC updates covered list to include foreign-made consumer routers

#316
post #209

Earlier quoted context omitted.

But the fact that a company can manufacture consumer(ish) routers in Latvia means it's very practical that another company could manufacture consumer routers in the US. Usually the argument is that X can't be made in the US because China's so good at it that the US could never compete, so we shouldn't even try. But if a company with 367 employees in a country with the population of a medium-size metro area can do it,…

> But the fact that a company can manufacture consumer(ish) routers in Latvia means it's very practical that another company could manufacture consumer routers in the US. Assembling them in Latvia, or the US, from internationally sourced components isn't a solution to anything. > Usually the argument is that X can't be made in the US because China's so good at it that the US could never compete, so we shouldn't even…

> Assembling them in Latvia, or the US, from internationally sourced components isn't a solution to anything.

I disagree. It's the first step. I mean, how did China do it? They started with assembly and low-value manufacturing and worked their way up the value chain. The US still had fabs. Once you get assembly reshored, start pushing to to reshore components (which are mostly chips, and pretty soon the equipment is mostly domestic.

> Unless Latvia is a much better environment for this kind of industry than the US is.

In what way?

Even if the US is utterly terrible for this kind of industry, we're talking about a small-medium sized tech company. It seems extremely doable.

Re: FCC updates covered list to include foreign-made consumer routers

#317

Earlier quoted context omitted.

> What you need is not a government mandate for infallibility, it's updates So, we don't need an electrical code to enforce correct wiring. We just need a kind soul driving by our house to notice the company who built our house wired it up wrong. Then that kind person can inform the company of the bad wiring. And if the company agrees it's their wiring at fault, we can wait 3 months for a fix. Then the next month ano…

I agree, but in addition the electrical code needs to be open to the public, not paywalled as it is in so many places!

I'd start by not using self-immolating wires (hardcoded default passwords).

Jokes aside, there's so much low-hanging fruit in IoT it's utterly ridiculous. Having any standards at all would be an improvement.

Re: FCC updates covered list to include foreign-made consumer routers

#318

If war breaks out you better bet a bunch of equipment will turn off. Numerous papers showing the ability to easily map indoors areas with WiFi (including occupancy) it’s a liability. There will be excuses “tariffs” etc but I heard a few have gotten calls from three letter agencies coyly telling you to improve your systems. It’s a chance to refresh the product line! (of course at the worst time when mem prices are ble…

"Will turn off"... are you claiming that consumer-grade routers have a secret backdoor kill switch that one government or another can use to turn them off? That's a little hard to believe (even when they are security Swiss cheese).

More likely they have RCE vulnerabilities known to various governments than intentionally made secret backdoors... which is worse since a backdoor would probably at least only be usable by the county that manufactured it (for example see Jia Tan's attempted backdoor).

Re: FCC updates covered list to include foreign-made consumer routers

#319

Earlier quoted context omitted.

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…

And who hasn't seen American software companies where crap security practices are later leveraged by the same company to run exploits? It's of course always phrased in Orwellian terms of business practices, terms of service, "security", etc but we can still call a spade a spade.

One dog's exploit is another's Clippy. I've certainly seen companies downgrade security generally when they deploy (and enable by default) new features. Start with web browsers. Ads in software you paid for. Always on app telemetry. Cloud backups. Cloud-compute assisted "desktop" tools. Sorry, out of time.

Re: FCC updates covered list to include foreign-made consumer routers

#320
post #148

Earlier quoted context omitted.

We're going to keep seeing this in all kinds of industries throughout the next three or so years: "Your products are banned or your country is tariffed, but if you pay enough in bribes, er I mean undergo our approval process, then you'll be exempt."

Bonus points if the ‘approval’ process exempts them from liability if misused - and there is no actual checking done as part of approval.

You know that's exactly how it's going to be. There are two attributes of this administration that are just as prominent as corruption -- laziness and incompetence.
Post reply on HN