1,393 karma · joined December 15, 2022
Just a reminder: As fun as discussing this in here with you is, the best way to influence what the FCC ends up doing is to file an official comment by September 25th at https://www.fcc.gov/ecfs/search/docket-detail/23-239 . Click to file either an ‘express’ comment (type into a textbox) or a ‘standard’ comment (upload a PDF). The FCC is required to address your arguments when it issues its final rules. All options are on the table, so don’t hold back, but do make your arguments as clear as possible so even lawyers can understand them. If you have a qualification (line of work, special degree, years of experience, etc.) that would bolster the credibility of your official comment, be sure to mention that, but the only necessary qualification is being an interested member of the public.
Finally, I'd like to extend a special thanks to dang and the rest of the HN team for their help putting this together. They have been a pleasure to work with.
The FCC hasn't traditionally been a cybersecurity agency and will, most likely, never really be one; however, we can certainly do things through rules to empower experts, the public, and the agencies with cybersecurity expertise. If that one thing is all you ever did at the FCC, sounds like the public owes you a big debt of gratitude.
it would be really useful if there were a TLDR version
I agree; I'm hoping that the tech press takes up this topic, but an "official" one would make engagement much faster.
I think the labeling should be simple - like a small discrete set of classes for compliance that can be extended over time with further rules. So 20 years security updates is “platinum” 10 years is “gold” 5 is “silver” or something. Then the classes of label can accrete meaning over time as you enhance your proposals.
This is how I'm thinking about it too -- not just for support term, but for all kinds of things, FOSS firmware in escrow, bankruptcy transition plan, responsibility to publish and implement fixes from public databases -- there's so much that might go into each tier, and while I have my own ideas, it would be great to see the tech community take up these questions.
in some ways a way to work best is right here in the HN comments and then lifting material up into your direct work via the proposal and statement
Also true, and my team will be doing a detailed after-action on this thread once it winds down.
To that end maybe reaching out earlier in the process to get feedback would work
That's one to grow on for next time. The good news is that the final rule (I'd expect end of Q2 2024) will also be subject to notice-and-comment.
Seriously, a huge thank you for your close engagement. I'm really excited about what the tech world can bring to this high-level proposal.
The FCC conducts notice-and-comment rulemaking and is accountable to a public interest standard. Obviously the public interest can be hard to define, but at minimum, if reasonable comments on the record raise issues that we are clearly ignoring, this is likely to emerge in item debate, dissenting statements, and the press. In fact, the courts can go as far as overturning a rule if the FCC failed to adequately address arguments made on the record during the rulemaking process. A lot of our rulemaking is technical and not of general interest, but the public has the right to comment on all of it.
In this particular case, I think the much of the relevant experience and expertise resides with the public more than the federal government. A lot of tech workers are very upset with the current state of IoT security and with the US Government's actions or lack thereof, so if we get a lot of comments on the records about specifics, those will be hard to brush off.
Link for general reference: https://www.fcc.gov/about-fcc/rulemaking-process
I sort of want both. Official commentary moves the needle, but selfishly, I love the thread comments. People tell you what they really think, and sometimes go into a lot of detail as to why. It's an education for me.
I think IoT security is a huge issue, and I think that the solution could be that there are standard, open-source, open-license, free-to-use packages; maybe written in languages like C, that could be offered to the industry. These could enforce low-level compliance with security standards.
"Universal basic security" would probably be a major field of policy approach if we found ourselves with some huge disaster requiring a regulatory response. It's at least worth thinking about now, even if it goes beyond the scope of what the immediate regs can do.
It depends how much the labels shape behavior. I'm envisioning a "high-tier" label that says that risks X, Y and Z have been addressed by M means and that, e.g., addressing risk Z meant sweeping stated databases for known security holes, committing to security-only patches for N years, and hiring J compan(ies) to sweep your firmware within specified parameters -- or whatever other things from the wish list of infosec pros that people like posters in this thread choose to advocate for. Hopefully that would be better than what we have now, which is mainly price/churn-driven minimum viable product.
Re your exception: I don't think mandatory labels are on the horizon in the USA, but this could indeed be a problem under other regulatory regimes.
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.02042022-2.... https://www.nist.gov/itl/executive-order-14028-improving-nat...
They're in FN 20 of the linked proposal for rulemaking (which is 48 dense pages and which I don't expect anyone here to have had a chance to read yet.)
If you find yourself skeptical about the NIST proposals, please feel free to comment on the record!
I worry about this too, and it's one thing when it's a camera but another when it's a car, or electrical grid equipment, or chemical process controls, etc. You make a great point re clickwrap, and clearly clickwrapping your rights away should be something that we don't readily allow for a manufacturer receiving the federal benefit of a marketing label.
It could be that even a top-tier label will turn out to be meaningless. That would mean that we'd need to have "harder" regulation or that people would start demanding dumb devices. I hope that industry will respond productively to this voluntary effort so that the public doesn't get harmed and we are able to benefit from the real advantages of connectivity that's also secure.
If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it.
So if they don't, they can't put the label. That's all.
The current framework is 100% voluntary for what amounts to a marketing label. There are non-FCC government databases for issue reporting, and a commitment to reporting to such DBs could be part of what earns you a higher label. Would be great to see commentary on this point from the tech public.
It's not inconceivable that this could be a requirement for getting a label (or some tier of label.) It depends how the advocacy comes out on the record.
Great points. From one perspective, we can't afford to do this stuff; from another, we can't afford not to. If connectivity makes your life a little easier for little risk, that's one thing; if your dishwasher steals your identity and sells it online, that's another.
My concern would be low quality, usually cheaper, whack-a-mole mfrs that come and go on Amazon, eBay, etc. Even if they release a product that would fall under these guidelines, how are you going to go after a ghost?
Another great point, but that's a snapshot of the market as it is now. We expect certain standards from some things but not others, depending on how much you depend on them, how much is at risk, and what the costs would be. Right now, under the proposal, a company is 100% free to say "I will support this for 0 days and you expect it to ship broken from the factory" -- it's just that they actually have to say that out loud.
Also, what happens when an IoT mfr is acquired, does the acquirer assume all the IoT risks as well?
I expect this to be a hot topic on the record. We'll see what technologists, manufacturers, consumer advocates, etc. say and try to come up with a proposal addressing stated concerns.
I also worry that check-the-box compliance is one possible outcome. I'd love to see professionals comment on the record about where a checklist would and wouldn't be helpful. I'd also love commentary on if and where liability for failure to meet stated commitments would be helpful.