Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

71–80 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#71

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

[dead]

Re: FCC updates covered list to include foreign-made consumer routers

#73
post #49
post #40

Earlier quoted context omitted.

> So, foreign-made consumer routers can still be sold, but they are going to look at them with a fine-tooth comb, and they are going to use FCC approval as leverage to try to increase domestic manufacturing. You're assuming a non-partisan technocratic process, which this administration has amply shown is neither capable nor willing to provide. This requirement becomes another opportunity for Pay-to-Play, either in ca…

This is the problem with erosion of norms. We’ve all known for decades that consumer routers have shit security. We’ve all known about the risk of implants or intentional backdoors in the supply chain. And now when the FCC appears to be finally doing something about it, there’s a massive cloud of mistrust hanging over the whole idea.

The mistrust comes from those doing it, and the clearly corrupt ways they are operating. The maggot movement is basically rooted in a lot of very real frustrations from very real longstanding problems, but the only thing it offers as solutions is performative vice signalling.

People who care about the problems of digital security are not going to lean into the idea of simply banning devices based on where they were manufactured. Rather they would work at general standards and solutions to actually solve the problems - things like untying the markets for hardware/firmware/services, requiring firmware source escrow, mandating LAN protocols and controllers so every single IoT device isn't backhauling to its own mothership, and so on.

Likewise people who care about domestic manufacturing first and foremost are not going to champion applying steep blanket tariffs two decades after all of that industry has already left, or using regulatory agencies to shake down manufacturers for unrelated concessions.

Re: FCC updates covered list to include foreign-made consumer routers

#74

Earlier quoted context omitted.

Open firmware would become commercially viable when IP is abolished

How do you see firmware becoming more open without copyright exactly?

Not prosecuting people trying to reverse engineer any kind of software would be a great start...

Re: FCC updates covered list to include foreign-made consumer routers

#75
post #40

This part of the press release seems pretty crucial: > Producers of consumer-grade routers that receive Conditional Approval from DoW or DHS can continue to receive FCC equipment authorizations. In other words, foreign-made consumer routers are banned by default. But if you are a manufacturer, you can apply to get unbanned ("Conditional Approval"). In the FAQ ( https://www.fcc.gov/faqs-recent-updates-fcc-covered-list…

> So, foreign-made consumer routers can still be sold, but they are going to look at them with a fine-tooth comb, and they are going to use FCC approval as leverage to try to increase domestic manufacturing. You're assuming a non-partisan technocratic process, which this administration has amply shown is neither capable nor willing to provide. This requirement becomes another opportunity for Pay-to-Play, either in ca…

> You're assuming a non-partisan technocratic process

No, of course I'm not assuming that. That's not the administration's pattern of behavior, so it would be a crazy assumption.

I agree it'll be abused. I just didn't feel it necessary to state the obvious.

Re: FCC updates covered list to include foreign-made consumer routers

#77
post #46

[flagged]

Please avoid low-substance, self-promotional comments like this on HN. It's OK to mention your own product/service occasionally, but only if it's in context and as a part of a comment that makes a substantive, insightful contribution to the discussion. Also, we recommend using a username that seems human, rather than being based on a company/brand name, otherwise it seems like you are here primarily for promotional p…

Thanks Tom. This whole comment thread is a bit of a dumpster fire of opinions however we have been working on the wifi security problem for a long time and we have a lot to say about it. Router manufacturers competing into involution that ship RCE (much of which is triggerable from a web page) have created a substantial risk to consumers, in this case with a lens on the US market. We tackle hardware & software and prioritized network isolation as the first thing to resolve. We have tons on our blog and page about network security and have open source software.

Re: FCC updates covered list to include foreign-made consumer routers

#78

What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers! Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?

I understand the anger but I wouldn't go as far as that last part... the GFW is the ultimate censorship tool. For the record I run tp-link aps

Re: FCC updates covered list to include foreign-made consumer routers

#79
post #25

Earlier quoted context omitted.

It'd be great if open firmware could be commercially viable. Finding a business model is hard. The OpenWRT One [1] sponsored by the Software Conservancy [2] and manufactured by Banana Pi [3] works lovely. [1] https://openwrt.org/toh/openwrt/one [2] https://sfconservancy.org/activities/openwrt-one.html [3] https://docs.banana-pi.org/en/OpenWRT-One/BananaPi_OpenWRT-O...

Open firmware would become commercially viable when IP is abolished

I'm no fan of imaginary property, but you're going to have to lay out your reasoning here. Firmware security is such crap precisely because most hardware manufacturers see it as nothing but a cost center they wish they could avoid.

The difficulty of installing OpenWRT or Linux in general on hardware comes from that hardware not being documented, or not having straightforward APIs like BIOS/EFI.

Or for some devices, community distributions that dubiously remix manufacturer-supplied binaries are available. But we generally see that as soon as the manufacturer stops their updates, the community versions start lagging behind as well.

Post reply on HN