Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

431–440 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#431
post #207

Earlier quoted context omitted.

> So, we don't need an electrical code to enforce correct wiring. For an analogy to work, its underlying elements should have a relation to the target. Your analogy is not in the same universe. For electrical work, there is a baseline of materials and practices which is known to produce acceptable results if adhered to. For software, there isn't. (Don't tell me about the Space Shuttle. Consumer software doesn't cost…

The analogy does work. The house is any software provided by any vendor. The kind strangers are white hat security researchers. The people living in the house are the users. Software absolutely has baseline materials, have you never written software before? Never used a library? Programming language? API? Protocol? Data format or specification? CPU instruction? Sorting algorithm? A standard material is just a materia…

> The analogy does work. The house is any software provided by any vendor.

Even before we start, you immediately have a problem. When a house is built, the thing to be inspected is built in the jurisdiction requiring the inspection.

If you have some code being written in China or India and some US jurisdiction wants to require the sort of programming practices you're suggesting, is the US going to send inspectors to other countries? How do they even validate that the processes are being followed either way? And what are you proposing to do with all the existing code that was written in the past? Requiring the company to have a checklist included in their book of procedures that nobody is actually following doesn't solve anything.

The way this nominally works for building inspections is that the inspector waits until after the work is done and then inspects the work, but that's a validation of the result rather than the procedures. The equivalent for code is an audit, which is dramatically more labor intensive for the government than sending someone to have a quick look to see if the wires appear to be hooked up right, if you expect it to actually do anything.

> I think the problem here is there's too many armchair experts saying "Can't be done" when they don't know what they're talking about

There are too many armchair experts saying "if they can land a man on the moon then surely they can land a man on the sun."

> That's not the way it is in the trades, in medicine, in law, and those folks actually have more to think about than software engineers, and more restrictions

First notice that you're listing all the professions where costs are out of control and the incumbents have captured the regulators to limit supply.

On top of that, those regulations are not even effective in solving the analogous problem. For example, the ethical requirements for lawyers nominally require them to do the thing public defenders aren't provided with the ability to do, i.e. spend enough time on the case to give the client adequate representation. Public defenders are given more clients by the state than they have the resources to actually represent. Quite unsurprisingly, this utterly fails to solve the problem of indigent defendants not having adequate representation.

But that's the thing most analogous to what you're proposing. If you nominally require companies to do something they otherwise have no real incentive to do, which you have no efficient way of verifying that they've done, and provide them no additional resources to do it, you can't expect "they will now do it well" to be the result.

> I think SWEs are just trying to get out of doing work and claiming it's too difficult, and the industry doesn't want to stop the free ride of lack of accountability it's had for decades.

What makes you think the software developers are the ones objecting to it? They, and the incumbent companies trying to raise costs on smaller upstarts, are the ones trying to establish a new racket and exclude newcomers from the industry. The ones objecting are the customers, and anyone who values efficiency and efficacy.

> We need to stop screwing around and create the software building code, before the government does it for us.

"We need to stop screwing around and create the Torment Nexus, before the government does it for us."

Re: FCC updates covered list to include foreign-made consumer routers

#432
post #423

Earlier quoted context omitted.

> Which is not a real issue in practice. Are you serious? The number of IoT companies that make a product for a couple years and then go bust is enormous . > It's like arguing that warranty doesn't matter because the vendor might go out of business. How are you going to use a warranty from a company that no longer exists to get a security update for a product a million consumers still have?

The typical IoT company not surviving the typical lifecycle of their products shows that IoT is a seriously dorked up idea. Anybody deploying them who values security should choose products that can be updated even after the vendor is gone. > How are you going to use a warranty from a company that no longer exists to get a security update for a product a million consumers still have? I was not talking about using war…

> The typical IoT company not surviving the typical lifecycle of their products shows that IoT is a seriously dorked up idea. Anybody deploying them who values security should choose products that can be updated even after the vendor is gone.

But then many consumers value cost or other things over security, which is why you need all the devices to be able to be updated even after the vendor is gone.

> I was not talking about using warranty for this.

Then why are you talking about a warranty to begin with?

Re: FCC updates covered list to include foreign-made consumer routers

#433

Earlier quoted context omitted.

Why is there no path? Surely it’s possible to do?

It would take years, maybe decades. We saw the same thing with drones. It's impossible to overstate how much the supply chain for modern electronics depends on China. Everything in a router, from the chips to the resistors to the antennae to the coating on the PCBs, comes from there.If you wanted to build it all in America, even if you had unlimited funding it would take forever. There's no router industry here becau…

You’re just saying it’s painful and don’t want to do it which is the purpose of the law.

Re: FCC updates covered list to include foreign-made consumer routers

#434

Earlier quoted context omitted.

It would take years, maybe decades. We saw the same thing with drones. It's impossible to overstate how much the supply chain for modern electronics depends on China. Everything in a router, from the chips to the resistors to the antennae to the coating on the PCBs, comes from there.If you wanted to build it all in America, even if you had unlimited funding it would take forever. There's no router industry here becau…

You’re just saying it’s painful and don’t want to do it which is the purpose of the law.

I'm saying that if you wanted a fully made-in-America WiFi 8 router, it is impossible, it physically can't happen. The timescale required to spin all of this up is too long, even with perfect funding and organization.

I'm also saying that because in reality there is no funding for it, American routers will end up like the US shipbuilding industry, using protectionist policies as an excuse to stay decades behind the times and produce nothing.

Re: FCC updates covered list to include foreign-made consumer routers

#435
post #422

Earlier quoted context omitted.

It's not so simple. Routers, like most tech emitting and modulating an RF signal by design, are certified products. The radio frequency bands, output power, allowed channels are all tightly controlled. Allowing end-users control without restrictions over such equipment would be unsafe.

how is that different from any computer with a network card and wifi support? routers really are not special here.

It's quite different. The transceiver in your device is mainly a low-power receiver, transmit power is limited to ~100mW at best. Meanwhile a typical AP can go up to 1W per antenna for transmit. Also, the firmware that operates the wifi stack on your network card is not open source or user-modifiable beyond firmware updates issued by the manufacturer. I suggest reading up on wifi and RF before going further.

Re: FCC updates covered list to include foreign-made consumer routers

#436

Earlier quoted context omitted.

You’re just saying it’s painful and don’t want to do it which is the purpose of the law.

I'm saying that if you wanted a fully made-in-America WiFi 8 router, it is impossible, it physically can't happen. The timescale required to spin all of this up is too long, even with perfect funding and organization. I'm also saying that because in reality there is no funding for it, American routers will end up like the US shipbuilding industry, using protectionist policies as an excuse to stay decades behind the t…

> it is impossible, it physically can't happen.

I don’t think that’s true.

> American routers will end up like the US shipbuilding industry, using protectionist policies as an excuse to stay decades behind the times

I agree.

Re: FCC updates covered list to include foreign-made consumer routers

#437

Earlier quoted context omitted.

I'm saying that if you wanted a fully made-in-America WiFi 8 router, it is impossible, it physically can't happen. The timescale required to spin all of this up is too long, even with perfect funding and organization. I'm also saying that because in reality there is no funding for it, American routers will end up like the US shipbuilding industry, using protectionist policies as an excuse to stay decades behind the t…

> it is impossible, it physically can't happen. I don’t think that’s true. > American routers will end up like the US shipbuilding industry, using protectionist policies as an excuse to stay decades behind the times I agree.

I can't change what you believe, but as far as I understand the American manufacturing industry, there is zero chance they could build a WiFi 8 router in the time period where it's the current standard. Not low, zero.

This article is a good example: https://archive.is/RAZMJ

Apple, with all their resources, couldn’t even get American screws. Now, if they really wanted to, they could have spun up their own screw manufacturing, eventually. But for a router, you need a lot more than screws. Resistors, capacitors, PCBs, plastics, all the secondary and tertiary industries for the materials behind those--it would probably take decades and trillions of dollars.

Re: FCC updates covered list to include foreign-made consumer routers

#438
post #225
post #176

Earlier quoted context omitted.

The Snowden leak showed that Cisco routers had been altered to enable surveillance [1]. Whether or not the manufacturer is complicit, or how the alteration is performed is ultimately irrelevant to the end user. Ultimately, the only people that got in legal trouble for this were Snowden and people who provided service to him. [1]: https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...

Actually it's entirely relevant how, in the context of this conversation. Here, we're discussing product as shipped, not product intercepted and modified. We're discussing if products are shipped secure or not. The Snowden disclosures are important, but not relevant in this case.

My point is that the US did alter homemade products for export, and that the only people litigated against were the whistleblower and/or companies providing service to him.

> If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable.

With that context added, my point is that the US judicial system would never litigate against e.g. Cisco if they were involved. The issue is not the relation between the state and Cisco, it's the relation between the US justice system and the US national security apparatus that prevents any such litigation to happen.

Re: FCC updates covered list to include foreign-made consumer routers

#439
post #423

Earlier quoted context omitted.

The typical IoT company not surviving the typical lifecycle of their products shows that IoT is a seriously dorked up idea. Anybody deploying them who values security should choose products that can be updated even after the vendor is gone. > How are you going to use a warranty from a company that no longer exists to get a security update for a product a million consumers still have? I was not talking about using war…

> The typical IoT company not surviving the typical lifecycle of their products shows that IoT is a seriously dorked up idea. Anybody deploying them who values security should choose products that can be updated even after the vendor is gone. But then many consumers value cost or other things over security, which is why you need all the devices to be able to be updated even after the vendor is gone. > I was not talki…

> But then many consumers value cost or other things over security, which is why you need all the devices to be able to be updated even after the vendor is gone.

This is only possible if the firmware is replaceable. Along with a practical update mechanism it also requires the possibility to create an update package. That can be achieved by using open source components, but there might be other mechanisms. For example making provisions in case of bankruptcy.

> Then why are you talking about a warranty to begin with?

I was making a comparison with warranty law, which exists to ensure a certain minimum bar for quality and longevity of products. Which is usually desired, therefore legal provisions for updateability of hardware should also be required. Note that a firmware update might well become required within the warranty period.

This is by no means a new concern. IP cams, home routers, robot vacuums, and internet-enabled fridges exist for a long time already. The warranty period was never intended to cover "smart" devices. Maybe forcing an extension of the warranty period for such devices is enough to take care of the problem.

Re: FCC updates covered list to include foreign-made consumer routers

#440

Earlier quoted context omitted.

Right but access to those keys will be available in an unhardened location then? Otherwise you're serving encrypted data. So if the system accessing the data and using the keys is compromised, which we can assume is the case if the data is compromised, then access to the keys is as well? Maybe I'm being an idiot but it seems like a lot of extra complexity to protect against really only physical attacks where someone…

> to protect against really only physical attacks where someone directly steals the data storage. Yes, physical access poses a significant risk to data security, it should not be ignored.

Aren't we legislating the wrong problem here then though? I'd argue prioritising the physical security of your drives over encrypting them is a better aim for services. As if someone can physically steal your drives they've still DOSed your system even if they cannot accesd the content.
Post reply on HN