Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

671–680 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#671

Earlier quoted context omitted.

> An informed market avoids lemons. Has that been true in practice? I can think of plenty of horrible products, in IT, on the market. In terms of security (including privacy), the market has done nothing for IT consumers. And what about the people who already bought the lemons, before the market learned of it? Also, what if the lemon doesn't affect me but affects others (such as through DDoS)? I prefer to keep it as…

Nothing? Hasn't Apple built a part of their brand upon security and privacy?

You're right, that was hyperbole and I make a point of not using it. It's BS.

Security is awful, however, and I don't think that's hyperbole. Almost every consumer I know, including people in IT, have given up on privacy and security (i.e., confidentiality and integrity).

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#672

I see the strong encouragement to post to the FCC's public comments, and you say it is highly influential - more influential than what you can do as a Commissioner. I'm a well-informed, active citizen, and I didn't realize that. It might help to explain how that works - how do public comments influence things? My concern would have been that it depends on the FCC, and that comments could be included or ignored as des…

It might help to explain how that works - how do public comments influence things? The FCC conducts notice-and-comment rulemaking and is accountable to a public interest standard. Obviously the public interest can be hard to define, but at minimum, if reasonable comments on the record raise issues that we are clearly ignoring, this is likely to emerge in item debate, dissenting statements, and the press. In fact, the…

Thanks.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#673
it would be better if the FCC demanded open source and/or open hardware. For example, make GPIO pins required, no undocumented black blobs. Service manuals available.

A manufacturer shouldn't be stuck supporting hardware they don't want to, but they absolutely should give us the ability to repair and manage our own devices.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#674
post #669

Earlier quoted context omitted.

These seem like very rare scenarios. If we're concerned about dire threats like this, the manufacturer needs a way to remotely send devices into an internet-disconnected "safe mode" before anyone's even talking about updates.

How do you, as a user, determine whether your oven is in "safe mode" that the manufacturer has toggled, or in "safe mode" that makes the UI look the same as the real one, but is actually a malicious code that waits until 3AM to start the cleaning mode? I agree that these scenarios are (relatively) far fetched _now_; but if we expect the future to include connecting appliances like that to the internet, then solving p…

If the attacker has total control, then all bets are off no matter what mechanisms you put in first. Adding a safe mode would at least allow manufacturer to stop any non-total exploit without relying on the more complicated update mechanism. Also, the appliance would more likely work in a kinda normal way in the meantime.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#675
post #669

Earlier quoted context omitted.

How do you, as a user, determine whether your oven is in "safe mode" that the manufacturer has toggled, or in "safe mode" that makes the UI look the same as the real one, but is actually a malicious code that waits until 3AM to start the cleaning mode? I agree that these scenarios are (relatively) far fetched _now_; but if we expect the future to include connecting appliances like that to the internet, then solving p…

If the attacker has total control, then all bets are off no matter what mechanisms you put in first. Adding a safe mode would at least allow manufacturer to stop any non-total exploit without relying on the more complicated update mechanism. Also, the appliance would more likely work in a kinda normal way in the meantime.

>If the attacker has total control, then all bets are off no matter what mechanisms you put in first.

Great, so we now agree that it's important to keep the system patched and up to date.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#676

As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here. How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing? Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the…

> Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs. +1 for this at the consumer level. My oven may have a critical update, but - for right now - *nothing* is more critical than finishing dinner. I'll let the update apply the day after thanksgiving when I'm doing the dishes. There are a few connected appliances brands that do this well: updates…

The more critical thing than finishing Thanksgiving dinner for your oven is not burning your house down.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#677

Earlier quoted context omitted.

> Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs. +1 for this at the consumer level. My oven may have a critical update, but - for right now - *nothing* is more critical than finishing dinner. I'll let the update apply the day after thanksgiving when I'm doing the dishes. There are a few connected appliances brands that do this well: updates…

I'm wondering why you'd have a smart oven in the first place. Seems like all risk and no reward.

Lucky guy, it sounds like you've never experienced overwhelming anxiety over having possibly left the oven on while out of the house.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#678

Earlier quoted context omitted.

I'm wondering why you'd have a smart oven in the first place. Seems like all risk and no reward.

The ability to pre-heat my oven without standing in front of it. That's really the big win. But also to be able to tell if spouse or children left it on.

But I can walk to my oven and turn it on, which wasn't a real problem even when I lived in a huge house. What am I missing?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#679
post #675

Earlier quoted context omitted.

If the attacker has total control, then all bets are off no matter what mechanisms you put in first. Adding a safe mode would at least allow manufacturer to stop any non-total exploit without relying on the more complicated update mechanism. Also, the appliance would more likely work in a kinda normal way in the meantime.

>If the attacker has total control, then all bets are off no matter what mechanisms you put in first. Great, so we now agree that it's important to keep the system patched and up to date.

That depends on updates never introducing new vulnerabilities.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#680

Earlier quoted context omitted.

Many flash chips have write enable pins at the hardware level. So this support really does still exist in theory! However, these pins mostly aren't used for any kind of switch in basically every PCB design I've seen. Either it's "always enabled" so the storage can always be written, or it's a chip that's programmed from the factory and always disabled to prevent any kind of user update.

I'd sure hate to have my system ransomware compromised, and when I try to restore from a backup drive, the ransomware encrypts it, too, as soon as I plug it in. I also have, on occasion, flipped the from and to parts of the command to restore from a backup. I'd really like to have a hardware switch to make the drive read-only.

They exist, but only as very expensive specialty gear for digital forensic investigators.

https://digitalintelligence.com/store

Post reply on HN