Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SimingtonFCC
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
SimingtonFCC
3y ago
I would love to see frank discussion on the record of consumer-grade vs infrastructure-grade practices and what label(s) would be appropriate for each! It’s not lost on me either that the roots of much high-ticket critical infrastructure is
2.
▲
by
SimingtonFCC
3y ago
Hi and thanks for commenting. My concern with this topic is motivated in part by the AcidRain family of energy infrastructure attacks and the larger questions they raise about infrastructure security. Teardowns on Chinese-sourced equipment
3.
▲
by
SimingtonFCC
3y ago
Thank you so much everyone for the interesting, high-quality discussion so far. My team and I are looking forward to continuing to engage with you for at least a few more hours. Just a reminder: As fun as discussing this in here with you is
4.
▲
by
SimingtonFCC
3y ago
Thanks again -- will review both links (especially the latter!) The FCC hasn't traditionally been a cybersecurity agency and will, most likely, never really be one; however, we can certainly do things through rules to empower experts,
5.
▲
by
SimingtonFCC
3y ago
Thanks! Sorry for any lack of clarity. My initial draft was way over the character limit and I had to cut a lot prior to posting. Thanks for highlighting the relevant language and clearing things up.
6.
▲
by
SimingtonFCC
3y ago
Flash ROM comment noted. It would be bad if getting a label required a manufacturer to do something objectively anti-user.
7.
▲
by
SimingtonFCC
3y ago
Comments against push updates and highlighting industrial applications would be a very important part of record development. I would expect industrial buyers to have very different needs from commodity consumer hardware buyers and it would
8.
▲
by
SimingtonFCC
3y ago
Really appreciate your kind words and the effort required in getting your arms around so much material so quickly. it would be really useful if there were a TLDR version I agree; I'm hoping that the tech press takes up this topic, bu
9.
▲
by
SimingtonFCC
3y ago
Thanks for raising this. I support the law addressing this issue and would also support Commission action on this.
10.
▲
by
SimingtonFCC
3y ago
Thanks for your response! This would be an excellent comment on the record, and implanted devices are a particularly compelling example considering cases such as Second Sight.
11.
▲
by
SimingtonFCC
3y ago
It might help to explain how that works - how do public comments influence things? The FCC conducts notice-and-comment rulemaking and is accountable to a public interest standard. Obviously the public interest can be hard to define, but a
12.
▲
by
SimingtonFCC
3y ago
I would suggest to my peers, that the links you gave are "official channels," and are probably what you really want, as opposed to a rather rambling thread of comments. I sort of want both. Official commentary moves the needle,
13.
▲
by
SimingtonFCC
3y ago
High-quality comment. Thanks very much! I'll read your filing and think about it. But also, it's a great example of impactful public FCC commentary. I hope your work inspires others to make their mark in the record.
14.
▲
by
SimingtonFCC
3y ago
This would make for a fine comment on the record. It would be great to have suggestions about pros and cons of government, court, third-party and other audit means.
15.
▲
by
SimingtonFCC
3y ago
I don't know about a mandatory update regulation -- one way or the other, that isn't on the table right now. I would love extensive discussion on the record, however, of the costs and benefits of requiring updates to get the label
16.
▲
by
SimingtonFCC
3y ago
Completely agree! The public record in this case is going to be what agencies and industry looks to, far more than whatever I might happen to personally believe. I'm going to get as much information from this discussion as I can, but e
17.
▲
by
SimingtonFCC
3y ago
Thanks for yours! It depends how much the labels shape behavior. I'm envisioning a "high-tier" label that says that risks X, Y and Z have been addressed by M means and that, e.g., addressing risk Z meant sweeping stated datab
18.
▲
by
SimingtonFCC
3y ago
I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glass, and get a sticker from the US Government saying so,
19.
▲
by
SimingtonFCC
3y ago
There are a couple of NIST papers on specifics for labels: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.02042022-2.... https://www.nist.gov/itl/executive-order-14028-improving-nat... They
20.
▲
by
SimingtonFCC
3y ago
Right now, the actual requirements for a label are totally up for grabs. This would make for a good public comment, in my opinion.
21.
▲
by
SimingtonFCC
3y ago
manufacturers are simply never going to be incentivized to take security seriously I worry about this too, and it's one thing when it's a camera but another when it's a car, or electrical grid equipment, or chemical process
22.
▲
by
SimingtonFCC
3y ago
My two cents is that this would be an excellent comment on the record -- I'd love a discussion at the level of defining security risks to be part of the official federal commentary, because this is going to be a thorny implementation p
23.
▲
by
SimingtonFCC
3y ago
Sorry for any confusion. The relevant language: If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it. So if they don't, they can't put the label. That's all
24.
▲
by
SimingtonFCC
3y ago
Re your point 4 in particular, I feel your pain -- I said "exposed public keys, expired certs" in the OP for a reason. The current item doesn't contemplate a requirement to tie these off as such, but I'd be interested to
25.
▲
by
SimingtonFCC
3y ago
None taken, of course. Several people in this thread have made this point, and it's a very reasonable one. The current framework is 100% voluntary for what amounts to a marketing label. There are non-FCC government databases for issue
26.
▲
by
SimingtonFCC
3y ago
Another great step would be a guarantee of making the firmware Open Source after no more than a certain amount of time, and having that guarantee known at compile time. Effectively, that means the device will always be supportable. It
27.
▲
by
SimingtonFCC
3y ago
Planned or unplanned obsolescence is good for business. You are proposing regulations counter to that, so should expect counter-pressure, even for IoT makers that want to do the right thing. Great points. From one perspective, we can'
28.
▲
by
SimingtonFCC
3y ago
100% agree! This is a totally voluntary program that is explicitly based on EnergyStar. I also worry that check-the-box compliance is one possible outcome. I'd love to see professionals comment on the record about where a checklist wou
29.
▲
by
SimingtonFCC
3y ago
From the Cyber Trust Mark perspective, there's no inherent difference between a connected disposable gizmo and your example of the water heater. Personally, I would love to see a minimum cybersecurity commitment made by anyone who make
30.
▲
by
SimingtonFCC
3y ago
Thanks for participating! After this thread winds down, I and my team are going to comb through it for suggestions and take as many as we can. We're also looking into other venues to engage directly with cybersecurity professionals. Bu
More ›