HNHacker News
TopNewBestAskShowJobs

SimingtonFCC

1,393 karma · joined December 15, 2022

submissionscomments
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
I would love to see frank discussion on the record of consumer-grade vs infrastructure-grade practices and what label(s) would be appropriate for each! It’s not lost on me either that the roots of much high-ticket critical infrastructure is about to rest on web tech and highly evolved descendants of 8-bit micros.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Hi and thanks for commenting. My concern with this topic is motivated in part by the AcidRain family of energy infrastructure attacks and the larger questions they raise about infrastructure security. Teardowns on Chinese-sourced equipment have been somewhat worrying as well -- one report I've read highlighted about two dozen versions of SSH in a single base station. Best wishes and good luck.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Thank you so much everyone for the interesting, high-quality discussion so far. My team and I are looking forward to continuing to engage with you for at least a few more hours.

Just a reminder: As fun as discussing this in here with you is, the best way to influence what the FCC ends up doing is to file an official comment by September 25th at https://www.fcc.gov/ecfs/search/docket-detail/23-239 . Click to file either an ‘express’ comment (type into a textbox) or a ‘standard’ comment (upload a PDF). The FCC is required to address your arguments when it issues its final rules. All options are on the table, so don’t hold back, but do make your arguments as clear as possible so even lawyers can understand them. If you have a qualification (line of work, special degree, years of experience, etc.) that would bolster the credibility of your official comment, be sure to mention that, but the only necessary qualification is being an interested member of the public.

Finally, I'd like to extend a special thanks to dang and the rest of the HN team for their help putting this together. They have been a pleasure to work with.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Thanks again -- will review both links (especially the latter!)

The FCC hasn't traditionally been a cybersecurity agency and will, most likely, never really be one; however, we can certainly do things through rules to empower experts, the public, and the agencies with cybersecurity expertise. If that one thing is all you ever did at the FCC, sounds like the public owes you a big debt of gratitude.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Thanks! Sorry for any lack of clarity. My initial draft was way over the character limit and I had to cut a lot prior to posting. Thanks for highlighting the relevant language and clearing things up.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Flash ROM comment noted. It would be bad if getting a label required a manufacturer to do something objectively anti-user.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Comments against push updates and highlighting industrial applications would be a very important part of record development. I would expect industrial buyers to have very different needs from commodity consumer hardware buyers and it would be great if they (and their vendors) were represented on the record!
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Really appreciate your kind words and the effort required in getting your arms around so much material so quickly.

it would be really useful if there were a TLDR version

I agree; I'm hoping that the tech press takes up this topic, but an "official" one would make engagement much faster.

I think the labeling should be simple - like a small discrete set of classes for compliance that can be extended over time with further rules. So 20 years security updates is “platinum” 10 years is “gold” 5 is “silver” or something. Then the classes of label can accrete meaning over time as you enhance your proposals.

This is how I'm thinking about it too -- not just for support term, but for all kinds of things, FOSS firmware in escrow, bankruptcy transition plan, responsibility to publish and implement fixes from public databases -- there's so much that might go into each tier, and while I have my own ideas, it would be great to see the tech community take up these questions.

in some ways a way to work best is right here in the HN comments and then lifting material up into your direct work via the proposal and statement

Also true, and my team will be doing a detailed after-action on this thread once it winds down.

To that end maybe reaching out earlier in the process to get feedback would work

That's one to grow on for next time. The good news is that the final rule (I'd expect end of Q2 2024) will also be subject to notice-and-comment.

Seriously, a huge thank you for your close engagement. I'm really excited about what the tech world can bring to this high-level proposal.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Thanks for raising this. I support the law addressing this issue and would also support Commission action on this.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Thanks for your response! This would be an excellent comment on the record, and implanted devices are a particularly compelling example considering cases such as Second Sight.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
It might help to explain how that works - how do public comments influence things?

The FCC conducts notice-and-comment rulemaking and is accountable to a public interest standard. Obviously the public interest can be hard to define, but at minimum, if reasonable comments on the record raise issues that we are clearly ignoring, this is likely to emerge in item debate, dissenting statements, and the press. In fact, the courts can go as far as overturning a rule if the FCC failed to adequately address arguments made on the record during the rulemaking process. A lot of our rulemaking is technical and not of general interest, but the public has the right to comment on all of it.

In this particular case, I think the much of the relevant experience and expertise resides with the public more than the federal government. A lot of tech workers are very upset with the current state of IoT security and with the US Government's actions or lack thereof, so if we get a lot of comments on the records about specifics, those will be hard to brush off.

Link for general reference: https://www.fcc.gov/about-fcc/rulemaking-process

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
I would suggest to my peers, that the links you gave are "official channels," and are probably what you really want, as opposed to a rather rambling thread of comments.

I sort of want both. Official commentary moves the needle, but selfishly, I love the thread comments. People tell you what they really think, and sometimes go into a lot of detail as to why. It's an education for me.

I think IoT security is a huge issue, and I think that the solution could be that there are standard, open-source, open-license, free-to-use packages; maybe written in languages like C, that could be offered to the industry. These could enforce low-level compliance with security standards.

"Universal basic security" would probably be a major field of policy approach if we found ourselves with some huge disaster requiring a regulatory response. It's at least worth thinking about now, even if it goes beyond the scope of what the immediate regs can do.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
High-quality comment. Thanks very much! I'll read your filing and think about it. But also, it's a great example of impactful public FCC commentary. I hope your work inspires others to make their mark in the record.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
This would make for a fine comment on the record. It would be great to have suggestions about pros and cons of government, court, third-party and other audit means.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
I don't know about a mandatory update regulation -- one way or the other, that isn't on the table right now. I would love extensive discussion on the record, however, of the costs and benefits of requiring updates to get the label.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Completely agree! The public record in this case is going to be what agencies and industry looks to, far more than whatever I might happen to personally believe. I'm going to get as much information from this discussion as I can, but every participant should feel free to comment on the record, or to get their employers, companies, trade associations, ad-hoc working groups, concerned citizens congregating on Discord to complain, etc. to do so as well.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Thanks for yours!

It depends how much the labels shape behavior. I'm envisioning a "high-tier" label that says that risks X, Y and Z have been addressed by M means and that, e.g., addressing risk Z meant sweeping stated databases for known security holes, committing to security-only patches for N years, and hiring J compan(ies) to sweep your firmware within specified parameters -- or whatever other things from the wish list of infosec pros that people like posters in this thread choose to advocate for. Hopefully that would be better than what we have now, which is mainly price/churn-driven minimum viable product.

Re your exception: I don't think mandatory labels are on the horizon in the USA, but this could indeed be a problem under other regulatory regimes.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glass, and get a sticker from the US Government saying so, it better be brick-proof.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
There are a couple of NIST papers on specifics for labels:

https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.02042022-2.... https://www.nist.gov/itl/executive-order-14028-improving-nat...

They're in FN 20 of the linked proposal for rulemaking (which is 48 dense pages and which I don't expect anyone here to have had a chance to read yet.)

If you find yourself skeptical about the NIST proposals, please feel free to comment on the record!

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Right now, the actual requirements for a label are totally up for grabs. This would make for a good public comment, in my opinion.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
manufacturers are simply never going to be incentivized to take security seriously

I worry about this too, and it's one thing when it's a camera but another when it's a car, or electrical grid equipment, or chemical process controls, etc. You make a great point re clickwrap, and clearly clickwrapping your rights away should be something that we don't readily allow for a manufacturer receiving the federal benefit of a marketing label.

It could be that even a top-tier label will turn out to be meaningless. That would mean that we'd need to have "harder" regulation or that people would start demanding dumb devices. I hope that industry will respond productively to this voluntary effort so that the public doesn't get harmed and we are able to benefit from the real advantages of connectivity that's also secure.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
My two cents is that this would be an excellent comment on the record -- I'd love a discussion at the level of defining security risks to be part of the official federal commentary, because this is going to be a thorny implementation problem.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Sorry for any confusion. The relevant language:

If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it.

So if they don't, they can't put the label. That's all.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Re your point 4 in particular, I feel your pain -- I said "exposed public keys, expired certs" in the OP for a reason. The current item doesn't contemplate a requirement to tie these off as such, but I'd be interested to see if commenters ask for this as part of getting a stronger label.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
None taken, of course. Several people in this thread have made this point, and it's a very reasonable one.

The current framework is 100% voluntary for what amounts to a marketing label. There are non-FCC government databases for issue reporting, and a commitment to reporting to such DBs could be part of what earns you a higher label. Would be great to see commentary on this point from the tech public.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Another great step would be a guarantee of making the firmware Open Source after no more than a certain amount of time, and having that guarantee known at compile time. Effectively, that means the device will always be supportable.

It's not inconceivable that this could be a requirement for getting a label (or some tier of label.) It depends how the advocacy comes out on the record.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Planned or unplanned obsolescence is good for business. You are proposing regulations counter to that, so should expect counter-pressure, even for IoT makers that want to do the right thing.

Great points. From one perspective, we can't afford to do this stuff; from another, we can't afford not to. If connectivity makes your life a little easier for little risk, that's one thing; if your dishwasher steals your identity and sells it online, that's another.

My concern would be low quality, usually cheaper, whack-a-mole mfrs that come and go on Amazon, eBay, etc. Even if they release a product that would fall under these guidelines, how are you going to go after a ghost?

Another great point, but that's a snapshot of the market as it is now. We expect certain standards from some things but not others, depending on how much you depend on them, how much is at risk, and what the costs would be. Right now, under the proposal, a company is 100% free to say "I will support this for 0 days and you expect it to ship broken from the factory" -- it's just that they actually have to say that out loud.

Also, what happens when an IoT mfr is acquired, does the acquirer assume all the IoT risks as well?

I expect this to be a hot topic on the record. We'll see what technologists, manufacturers, consumer advocates, etc. say and try to come up with a proposal addressing stated concerns.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
100% agree! This is a totally voluntary program that is explicitly based on EnergyStar.

I also worry that check-the-box compliance is one possible outcome. I'd love to see professionals comment on the record about where a checklist would and wouldn't be helpful. I'd also love commentary on if and where liability for failure to meet stated commitments would be helpful.

SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
From the Cyber Trust Mark perspective, there's no inherent difference between a connected disposable gizmo and your example of the water heater. Personally, I would love to see a minimum cybersecurity commitment made by anyone who makes or sells anything with connectivity.
SimingtonFCC··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Thanks for participating! After this thread winds down, I and my team are going to comb through it for suggestions and take as many as we can. We're also looking into other venues to engage directly with cybersecurity professionals. But please feel free to comment on the record as well -- a robust and detailed record is worth a lot more than whatever I can do individually.
Page 1 of 2Next →