Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

51–60 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#51
post #38

Earlier quoted context omitted.

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…

Are you saying that other manufacturers don't do this?

If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable. Not so with China.

(That is not to say that the FCC change will move the needle on the underlying issue of router security; as some of the ancestor comments have said, lax security practices are common industry-wide, irrespective of country of development/manufacture.)

Re: FCC updates covered list to include foreign-made consumer routers

#52

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…

What was the company, and what did they inject?

Re: FCC updates covered list to include foreign-made consumer routers

#53

This part of the press release seems pretty crucial: > Producers of consumer-grade routers that receive Conditional Approval from DoW or DHS can continue to receive FCC equipment authorizations. In other words, foreign-made consumer routers are banned by default. But if you are a manufacturer, you can apply to get unbanned ("Conditional Approval"). In the FAQ ( https://www.fcc.gov/faqs-recent-updates-fcc-covered-list…

> If you (a manufacturer) apply, they want information regarding corporate location, jursidiction, and ownership. They want a bill of materials with country of origin and a justification for why any foreign-sourced components can't be domestic. They want information about who provides software and updates. And they want to hear your plan to increase US domestic manufacturing and progress toward that goal.

Wow NGL this sounds great if you ignore the reality that it'll be used as a partisan backdoor to enriching the administration.

Re: FCC updates covered list to include foreign-made consumer routers

#54

What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers! Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?

I doubt anything will be pulled from the market. This is instead notice to the companies that now is the time for a donation to the administration’s ballroom.

Right now, the way this is currently worded, every single foreign-made consumer router has already been pulled from the market, and has to request permission to be reintroduced. The only consumer routers not currently affected are those that are either already purchased (some good, but won't last forever) or are American-made (overpriced, underpowered dogshit)

Re: FCC updates covered list to include foreign-made consumer routers

#55
post #25

Earlier quoted context omitted.

It'd be great if open firmware could be commercially viable. Finding a business model is hard. The OpenWRT One [1] sponsored by the Software Conservancy [2] and manufactured by Banana Pi [3] works lovely. [1] https://openwrt.org/toh/openwrt/one [2] https://sfconservancy.org/activities/openwrt-one.html [3] https://docs.banana-pi.org/en/OpenWRT-One/BananaPi_OpenWRT-O...

Open firmware would become commercially viable when IP is abolished

How do you see firmware becoming more open without copyright exactly?

Re: FCC updates covered list to include foreign-made consumer routers

#57
post #25

If we wanted secure products, we wouldn't ban devices. We'd mandate they open their firmware to audits.

It'd be great if open firmware could be commercially viable. Finding a business model is hard. The OpenWRT One [1] sponsored by the Software Conservancy [2] and manufactured by Banana Pi [3] works lovely. [1] https://openwrt.org/toh/openwrt/one [2] https://sfconservancy.org/activities/openwrt-one.html [3] https://docs.banana-pi.org/en/OpenWRT-One/BananaPi_OpenWRT-O...

[deleted]

Re: FCC updates covered list to include foreign-made consumer routers

#58

Earlier quoted context omitted.

Someone did go to jail, so there's at least that.

Yes. But a lot of people still got cars that were not as represented. So if we follow the same pattern, somebody will go to jail, but most routers will not be running verified or safe code.

Do you apply the same scrutiny to the food you eat?

Some trust has to be created through testing standards and the law, but generally we do believe what the label says in day to day life.

Re: FCC updates covered list to include foreign-made consumer routers

#59

Earlier quoted context omitted.

Someone did go to jail, so there's at least that.

Yes. But a lot of people still got cars that were not as represented. So if we follow the same pattern, somebody will go to jail, but most routers will not be running verified or safe code.

The routers thing? That's probably just a scam to get donations to the Trump Family Bunker/Ballroom in DC or other pet project.

Re: FCC updates covered list to include foreign-made consumer routers

#60

If we wanted secure products, we wouldn't ban devices. We'd mandate they open their firmware to audits.

You will first probably need Congress to legislate away the long standing prohibitions against offering (easily) user-modifiable RF devices on the market.

Self ownership and full 'right to repair' has carve-outs in the FCC's regulations in the name of limiting unintentional broadcasting/radiation. Maybe a challenge to those would survive in the post-Chevron environment. I wouldn't expect any Congress in the last 25 years to pass a law which would go against the incumbent telecom lobbyist interests though, and I'd expect such a hole if it did hit case law, to get 'patched' fairly quickly.

About the only way to really solve that would be to embarrass vendors enough to open their moats.

Post reply on HN