Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

421–430 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#421

Earlier quoted context omitted.

It's a whole lot easier to store the keys in a special hardened location than it is to store your whole storage.

Right but access to those keys will be available in an unhardened location then? Otherwise you're serving encrypted data. So if the system accessing the data and using the keys is compromised, which we can assume is the case if the data is compromised, then access to the keys is as well? Maybe I'm being an idiot but it seems like a lot of extra complexity to protect against really only physical attacks where someone…

> to protect against really only physical attacks where someone directly steals the data storage.

Yes, physical access poses a significant risk to data security, it should not be ignored.

Re: FCC updates covered list to include foreign-made consumer routers

#422

Earlier quoted context omitted.

I have a PC hooked up to my TV in my living room that has been running the latest version of Kubuntu for over 18 years now. It has had many upgrades in that time but it's still the same basic hardware: A CPU, some memory, USB ports, a video card, and an ethernet port on the back. That "genericness" is what's missing in the router space. Literally every consumer router that comes out has some super proprietary design…

It's not so simple. Routers, like most tech emitting and modulating an RF signal by design, are certified products. The radio frequency bands, output power, allowed channels are all tightly controlled. Allowing end-users control without restrictions over such equipment would be unsafe.

how is that different from any computer with a network card and wifi support? routers really are not special here.

Re: FCC updates covered list to include foreign-made consumer routers

#423
post #180

Earlier quoted context omitted.

> And "require longer support" doesn't fix it because many of the vendors will go out of business. Which is not a real issue in practice. It's like arguing that warranty doesn't matter because the vendor might go out of business.

> Which is not a real issue in practice. Are you serious? The number of IoT companies that make a product for a couple years and then go bust is enormous . > It's like arguing that warranty doesn't matter because the vendor might go out of business. How are you going to use a warranty from a company that no longer exists to get a security update for a product a million consumers still have?

The typical IoT company not surviving the typical lifecycle of their products shows that IoT is a seriously dorked up idea. Anybody deploying them who values security should choose products that can be updated even after the vendor is gone.

> How are you going to use a warranty from a company that no longer exists to get a security update for a product a million consumers still have?

I was not talking about using warranty for this.

Re: FCC updates covered list to include foreign-made consumer routers

#424
post #207

Earlier quoted context omitted.

> So, we don't need an electrical code to enforce correct wiring. For an analogy to work, its underlying elements should have a relation to the target. Your analogy is not in the same universe. For electrical work, there is a baseline of materials and practices which is known to produce acceptable results if adhered to. For software, there isn't. (Don't tell me about the Space Shuttle. Consumer software doesn't cost…

The analogy does work. The house is any software provided by any vendor. The kind strangers are white hat security researchers. The people living in the house are the users. Software absolutely has baseline materials, have you never written software before? Never used a library? Programming language? API? Protocol? Data format or specification? CPU instruction? Sorting algorithm? A standard material is just a materia…

> What are you talking about re: space shuttle and tens of millions?

GP was almost certainly referring to "They Write the Right Stuff," an old article that is pretty well known in spaces like this. It discusses a process that (a) works extremely well (the engine control software was ~420 kLoC with a total of 17 bugs found in a window of 11 versions) and (b) is extremely expensive (the on-board shuttle software group had a budget of ~35 million per year in mid-90s dollars).

Re: FCC updates covered list to include foreign-made consumer routers

#426

will this be like "product of USA" potatoes?, where a canadian truck full of bags of potatoes backs up to a special border facility, and the bagged potatoes are put on a conveyor, dumped out, conveyed........, and then rebagged,thereby becoming american product!

Live in USA and never heard of that nor USA ban foreign potatoes............?

Re: FCC updates covered list to include foreign-made consumer routers

#427
post #202

Earlier quoted context omitted.

> the device will only boot the vendor's signed firmware That sounds like what Software Freedom Conservancy would call a GPL violation: https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://events19.linuxfoundation.org/wp-content/uploads/2017...

> That sounds like what Software Freedom Conservancy would call a GPL violation Sure, it is. So what? Have you got 200k for lawyers and years of your life to spend in court fighting over it? I have personally contacted the SFC with ample evidence of deliberate and wilful GPL violations, such as providing a written offer for source code and then ignoring or flat out refusing requests for the source code. The SFC has a…

It is definitely true that any license including the GPL requires effort and resources to enforce, and that almost all authors of GPL software don't have enough of those.

If the SFC lawsuit against Vizio succeeds, then there will be another option; since yourself and others are third-party beneficiaries of the contract embodied in the GPL between Linux kernel developers and hardware vendors that ship Linux; start a class action with other users of the hardware where GPL violations are present, and sue for GPL compliance instead of money. The lawyers will get their legal costs presumably and the users should get source code. Probably some law firms would take this on just for the legal costs, especially if the Vizio precedent makes it easy to win future cases.

https://sfconservancy.org/copyleft-compliance/vizio.html

PS: I don't think SFC have an endowment, they are just directly funded by people who support their goals.

Re: FCC updates covered list to include foreign-made consumer routers

#428
post #351

Earlier quoted context omitted.

> That sounds like what Software Freedom Conservancy would call a GPL violation Sure, it is. So what? Have you got 200k for lawyers and years of your life to spend in court fighting over it? I have personally contacted the SFC with ample evidence of deliberate and wilful GPL violations, such as providing a written offer for source code and then ignoring or flat out refusing requests for the source code. The SFC has a…

Nothing happens my as, until your company gets sued by the FSF and your reputation online gets to the dustbin.

The FSF doesn't sue companies generally, they don't have the resources for that.

Re: FCC updates covered list to include foreign-made consumer routers

#429
post #202

Earlier quoted context omitted.

> the device will only boot the vendor's signed firmware That sounds like what Software Freedom Conservancy would call a GPL violation: https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://events19.linuxfoundation.org/wp-content/uploads/2017...

> That sounds like what Software Freedom Conservancy would call a GPL violation Sure, it is. So what? Have you got 200k for lawyers and years of your life to spend in court fighting over it? I have personally contacted the SFC with ample evidence of deliberate and wilful GPL violations, such as providing a written offer for source code and then ignoring or flat out refusing requests for the source code. The SFC has a…

PS: another tactic I have seen applied for GPL enforcement is for the copyright holder to have customs block devices on import since they contain illegally obtained software. This is pretty rare, but can be effective.
Post reply on HN