16 ms·
FCC Bans Authorizations for Devices That Pose National Security Threat
- myself248 4y agoAbout time. We need open and verifiable firmware, at the very least, to be able to trust anything. Now if only they'd turn this lens on American-made devices which are likewise opaque, insecure, and likely to be weaponized against us as soon as security updates stop....
- TEP_Kim_Il_Sung 4y agoThat's not how this will be applied. Instead, I think, they will go after devices that don't contain government backdoors.
- 2OEH8eoCRo0 4y agoWhich devices have government backdoors?
- jbverschoor 4y agoCisco iirc
- 2OEH8eoCRo0 4y agoSource?
- sschueller 4y agoSee CVE: https://www.cvedetails.com/vulnerability-list.php?vendor_id=16&product_id=&version_id=&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=0&month=0&cweid=0&order=3&trc=4362&sha=b6b9f0966b7dbca88b729e5b85a1f8fffc37d986 https://www.cvedetails.com/vulnerability-list.php?vendor_id=... At some point you have to think these are deliberate.
- TedDoesntTalk 4y agoLike the deliberate ones from TP-Link?
- 2OEH8eoCRo0 4y agoExtraordinary claims require extraordinary evidence. All I see are a lot of CVEs.
- fbdab103 4y agoIf not intentional, it at least points to a culture that cannot be trusted with producing secure devices.
- freshpots 4y agoDoes it though? Are you a SWE?
- fbdab103 4y agoGiven the number of times that a hard-coded password has been distributed on Cisco gear, yeah, I think it points to a cultural failure.
- Spooky23 4y agoThat happened 15 years ago dude, on Linksys gear. The first CVE on that list is probably older than a few of the commenters on this thread.
- fbdab103 4y agoA cursory internet search reveals several that popped up within the past decade on Cisco's gear. Hard-coded passwords are table stakes, if that slips through, what else is lurking beneath the surface? Network hardware is to operate in the adversarial landscape which is the open internet. It requires an extreme, exhaustive workflow to ensure bugs do not slip through. That we repeatedly see these failures does not raise confidence. - 2016-01 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-air https://tools.cisco.com/security/center/content/CiscoSecurit... - 2018-03 https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180307-cpcp.html https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-2018... - 2018-10 https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20181003-cpcp-password.html https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-2018... - 2019-07 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190717-cfnm-statcred https://tools.cisco.com/security/center/content/CiscoSecurit... Edit: formatting
- croes 4y agohttps://www.tomshardware.com/news/cisco-backdoor-hardcoded-accounts-software,37480.html https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...
- notrealyme123 4y agoSounds like it: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey https://tools.cisco.com/security/center/content/CiscoSecurit...
- _jal 4y agoAside from Cisco, Juniper has not exactly been forthcoming about backdoors: https://www.wired.com/2016/01/new-discovery-around-juniper-backdoor-raises-more-questions-about-the-company/ https://www.wired.com/2016/01/new-discovery-around-juniper-b... If my job were to ensure backdoor access to everything I could, at least to get started I'd sort a list of hardware vendors by marketshare.
- glitchc 4y agoAlmost all of them?
- TEP_Kim_Il_Sung 4y agoCell phones are required to have them by law. https://www.youtube.com/watch?v=D5cAfEGhH5o https://www.youtube.com/watch?v=D5cAfEGhH5o
- ouEight12 4y ago> don't contain <the correct> government backdoors. Fixed that for you. :/
- TEP_Kim_Il_Sung 4y agoAny backdoor can be used by any government. It may take time, but it will be found and exploited. All they're doing is passing the buck... your buck, that is.
- comboy 4y ago> We need open and verifiable firmware, at the very least, to be able to trust anything. How? Even ignoring ASICs, I just don't see how it's possible. Even if you had no binary blobs anywhere (we are already in the wonderland), with process for turning source to binary, you need to trust compiler, cpu, flashing hardware and software and the whole lot of other things. And that's all ignoring the fact that hiding bad stuff in open source is many orders of magnitude cheaper than finding it. I don't think we have even a theoretical plan for fixing computer security, it just becomes ML bots arena.
- AnthonyMouse 4y ago> with process for turning source to binary, you need to trust compiler, cpu, flashing hardware and software and the whole lot of other things. "We should not solve this solvable problem because other problems exist" is false. Meanwhile the other problems have solutions, like reproducible builds, so that the attacker not only has to compromise your compiler/CPU/hardware, they also have to compromise any others the output result gets compared by, or one of them will differ and the attack will be detected.
- shukantpal 4y ago> "We should not solve this solvable problem because other problems exist" is false. Without commenting on the truthiness of the comment you are replying to, you have constructed a strawman argument here. They weren't saying that the problem shouldn't be solved because other problems exist, rather that it might not be solvable b/c of so and so obstacles that don't seem to have a solution.
- ClumsyPilot 4y agoThe more accurate statement would be "we should not apply this silution because it only solves 60% of the problem. Instead we should despair abd do nothing at all"
- lrvick 4y agoYou need deterministic builds of firmware artifacts proven to correspond to source code by multiple parties. You also need hardware purpose made to be user auditable. See: https://media.ccc.de/v/36c3-10690-open_source_is_insufficient_to_solve_trust_problems_in_hardware https://media.ccc.de/v/36c3-10690-open_source_is_insufficien...
- deleted 4y ago[deleted]
- reversethread 4y agoIn reality, Chinese manufactures will just ignore FCC licensing requirements. A good amount of cheap Chinese electronics on Amazon are already unlicensed, so I doubt any new changes will affect them. Online marketplaces like Amazon really need to crack down on products and make sure they are properly licensed.
- phpisthebest 4y agoI would rather Amazon focus on elimination of Counterfeits and Fraud, not enforcement of FCC protectionism
- dylan604 4y agowell, yes and no. Amazon most definitely has a counterfeit/stolen goods problem that they are deliberately (from outside perspectives) not doing anything about. however, if a "legit" vendor is selling devices that does not meet local regulations and it is known by the seller this is true, then the seller has blame as well.
- deepsun 4y agoAnd also the seller cannot just say "oopsie I didn't know". Well, they must make an effort to "know your customer", instead of "better not ask".
- dylan604 4y agoI think there is/should be a grace period though. If a retailer is provided goods by a vendor where the vendor knows their products are illegitimate, it is possible for the retailer to be unaware. However, once it becomes known that the vendor is selling illegitimate products, it is up to the retailer to then remove those items. Most major retailers have agreements/contracts with these vendors that say they must buy back any merchandise unable to be sold. This would be a normal way of handling things. Once this avenue is not pursued and the retailer continues to sell the product, then the retailer is no longer innocent.
- woodruffw 4y agoBased on the actual news release[1], this is the FCC's formal statement of rules for compliance with the Secure Equipment Act of 2021[2]. [1]: https://docs.fcc.gov/public/attachments/DOC-389524A1.pdf https://docs.fcc.gov/public/attachments/DOC-389524A1.pdf [2]: https://www.congress.gov/bill/117th-congress/house-bill/3919 https://www.congress.gov/bill/117th-congress/house-bill/3919
- kryogen1c 4y agoThanks for connecting the dots, I was doing this research before I found your comment. I knew I had searched for covered telecom equipment last year. Also, I didn't know the covered list was being updated. Does anyone know what AO Kaspersky is? Is that the official corporate name for the anti-virus Kaspersky?
- woodruffw 4y agoYeah, I believe it's their corporate name. Their website lists their copyright as "AO Kaspersky Lab."
- wsh 4y agoThe prefix “AO” in the name of a Russian business entity is like the suffix “Co.” in English; it’s an abbreviation for aktsionernoye obshchestvo (акционерное общество), joint-stock company.
- deleted 4y ago[deleted]
- threatofrain 4y agohttps://news.ycombinator.com/item?id=33753442 https://news.ycombinator.com/item?id=33753442
- jasonhansel 4y agoIs it just me, or does the full "report and order" spend way, way too much time responding to the comments of various telecom companies and trade groups? The tone seems far too deferential, as if they're apologizing to the industry they're trying to regulate.
- deleted 4y ago[deleted]
- readme 4y agoin most cases, regulation in the US is basically a mouse trying to "regulate" the dinner of a lion by sneaking away a morsel or two
- chefandy 4y agoOr, depending on the leadership, a lion overseeing prey protection policy.
- cplusplusfellow 4y ago
- freshpots 4y agoDon't turn this place into 4chan.
- bilsbie 4y agoMore like protecting the lions dinner from other mice.
- emodendroket 4y agoHey, the national security hawks get another twist of the knife to China and the home telcos get fewer people horning in on their turf... win-win scenario for everyone concerned I guess.
- 4y ago
- TechBro8615 4y agoThis definitely won't be abused. Is Starlink a national security threat? What about a hardware wallet?
- sieabahlpark 4y ago[dead]
- enkid 4y agoDoes a hardware wallet actually need FCC authorization?
- mynameisvlad 4y agoLedger wallets connect to your phone over Bluetooth, so they would ostensibly need the FCC to ok them.
- enkid 4y agoWould the FCC ok the entire wallet or just the Bluetooth chip it's using?
- umbcorp 4y agoEntire wallet, even if you change the plastic cover you need to go through FCC again.
- deleted 4y ago[deleted]
- vorpalhex 4y agoThat's incorrect. You can buy pre-approved modem setups, eg the esp32.
- musingsole 4y ago
- nimbius 4y agothe video surveillance bans all seem to target billion dollar companies, so its safe to say this is just your friendly lobbyists at ring, nest, and amazon getting an early christmas gift. the security argument is pretty flimsy considering how many american companies are just as bad (looking at you nest) the usual suspect, huawei, has been on americas shitlist ever since they beat US telcos to market with 5g. their cellphones all meet or exceed the build quality of a samsung or iphone and to date america has failed to produce any real evidence of a security issue except 'china scary.' toward the end of the presser its refreshing to see an octogrnarian made sure to remind us all these companies are to some extent "government funded" as if americas subsidies to auto and airlines are somehow any different. "government owned" also gets condescendingly asserted as if the reader isnt familiar with how a planned economy under post soviet marxist theory works. ever since the net neutrality fiasco ive lost a lot of faith in the fcc. largely a toothless organization of corporate business interests.
- phpisthebest 4y ago>lobbyists at ring, nest, and amazon getting an early christmas gift This has no impact on sales to the consumer market for Video, the covered list [1] limits the ban to "the extent it is used for the purpose of public safety, security of government facilities" Ring, Nest etc are used for personal home and small business not likely covered under that ban, and the people buying Hikvision as an example most likely are not the target consumer of Ring devices. Hikvision is / was popular is commercial segment of professionally installed products, I know of zero professional installers doing commercial deployments of Ring. Companies like Axis however do get a boost as Axis is often many times more expensive than Hikvision [1]https://www.fcc.gov/supplychain/coveredlist https://www.fcc.gov/supplychain/coveredlist
- scottcodie 4y ago"The action we take today covers base station equipment that goes into our networks. It covers phones, cameras, and WiFi routers that go into our homes. And it covers rebranded or ‘white label’ equipment that is developed for the marketplace. In other words, this approach is comprehensive," said Jessica Rosenworcel, chair of the FCC.
- fnordpiglet 4y ago“”” The Covered List (which lists both equipment and services) currently includes communications equipment produced by Huawei Technologies, ZTE Corporation, Hytera Communications, Hangzhou Hikvision Digital Technology, and Dahua Technology (and their subsidiaries and affiliates). “””
- runlevel1 4y agoLink to the list: https://www.fcc.gov/supplychain/coveredlist https://www.fcc.gov/supplychain/coveredlist
- deleted 4y ago[deleted]
- largehotcoffee 4y agoGood. https://www.wsj.com/articles/huawei-technicians-helped-african-governments-spy-on-political-opponents-11565793017 https://www.wsj.com/articles/huawei-technicians-helped-afric...
- deleted 4y ago[deleted]
- emodendroket 4y agoWhich telco doesn't comply with requests from the government of the country they operate in?
- libpcap 4y agoAbout time!
- deleted 4y ago[deleted]
- flumpcakes 4y agoWhile I have no doubt than basically anything from China is probably backdoored (and to the fault of western countries outsourcing manufacturing for cheap labour), what exactly has Huawei done? How do we know that the Cisco equipment also isn't backdoored and if I send a few malformed TCP packets it opens up its control plane on the receiving port? Compared to the last few decades, it seems like a strong hand banning these companies. Personally I would like all electronics and products to be made in countries that respect some level of human rights I am comfortable with, but that doesn't really seem like an option currently.
- joemazerino 4y agoLook up Nortel.
- unmole 4y agoThe bloated tech gaint that refused to acknowledge the reality of the dotcom crash and then was brought down by an accounting scandal? That Nortel?
- joemazerino 4y agoYes. The Nortel that gave away proprietary equipment to Huawei for "testing" of which was returned in a tampered and obviously copied state.
- reaperducer 4y agoYour argument sounds like deflection and elementary school logic. If Cisco has problems, that should also be dealt with. But because Cisco has problems doesn't mean that Huawei shouldn't be dealt with. In Western cultures, we have the notion of "Two wrongs don't make a right." This is a classic Chinese government talking point. "Don't look at what we're doing. Look over there, instead!" For decades it's been using the same tactic when anyone criticizes China for trade imbalances and human rights abuses. It's really boring and base at this point.
- 4y ago
- fredgrott 4y agoNote, did anyone see the US Congress tiktok hearing? Clearly even US Congress was not having the TikTok denials of the CCP accessing USA data.
- remarkEon 4y agoLink?
- squarefoot 4y agoThey seem to make a special case of modules by those brands, for example 4G or 5G modems that are contained in other manufacturers appliances, and these days employ self contained operating systems in theory perfectly capable of moving information back and forth without any intervention, or even knowledge, from the device employing them (cellphone, IoT device, industrial appliance, vehicle etc). The problem is: how do they certify them without obtaining the firmware source code along all the original design data?
- erosenbe0 4y agoFCC doesn't necessarily concern itself primarily with device functionality and security, but rather enforcing the rules of the road, so to speak, for the electromagnetic spectrum. For example, if you sell a microwave oven, you need to use the ISM band or whatever they deem appropriate, and they won't mind whatever EMF goo it puts out. If your microwave oven deviates from allowed parameters, it will fail cert. If it interferes with telecommunications or other equipment and you sell it anyway, you can get in big trouble with Uncle Sam. If you sell a widget that is functionally insecure but you don't lie about it in a negligent or fraudulent way, that isn't necessarily a problem. If you have a backdoor for some nefarious purpose, that could run afoul of numerous criminal or civil statutes. Some of these statutes vary by state, too, so best practice is full disclosure, of course.
- throwaway199956 4y agoDoes it apply to consumer equipment like phones, tablets and smart watches?
- gennarro 4y agoIt’s actually very easy to browse fcc activations. It’s a fun thing to browse if you want to stay ahead of the tech news. Ex: https://fccid.report/ https://fccid.report/
- greatjack613 4y agoThis should not come as a surprise to anyone here. The fact that people on HN still defend china when they clearly got their success through espionage and cheating just shows how much influence XI has on american institutions and social media. I hope everyone just wakes up in time so we can stop this nightmare before we lose everything we hold dear.
- colinsane 4y agoi’d like to hear more about how Xi is influencing the HN perception of these things. it seems a leap to go from “American HNers disagree with many actions by their own government” to “they disagree with this primarily because of foreign influence”. i think the simpler explanation is that there’s a lot of idealists here who take more of a moral absolutism view of things than is historically practical for a state to do: “this anti-China policy Y is silly because US also does terrible things relating to Y”, not caring (at least publicly) which of the two parties is a worse offender to Y.
- mordae 4y agoYou should read up on US history. Brits were not very happy about US ignoring their patents. Selfish people just like to kick off the ladder once they've used it to climb up. We should criticize China for human rights violations, not for copying useful ideas and trying to learn to build tech on their own. IP should be abolished universaly.
- didyouknow789 4y ago[dead]
- myself248 4y ago> Map that port to 192.168.1.252 What's that supposed to do?
- poopsmithe 4y agoFrom the link they posted, the guide says to forward the port to any unused IP address, like 192.168.1.252. I think this effectively causes an attacker's traffic to get dropped.
- almyk 4y ago> If your NAT router/gateway keeps this port open and you are sure you want to filter it (potential interference with ISPs pushing firmware updates), try the following. Navigate to your router's admin interface and disable TR-069. If that does not work, look under "port forwarding", or "virtual servers", and forward the port to an unused local IP address, like (192.168.1.252) From the source that was linked. So the original author doesn't recommend 192.168.1.252 but just uses it as an example
- viraptor 4y agoThis is FUD, not actionable information. Device management services are not backdoors. Forwarding traffic you don't understand and can't verify the fix is just cargo culting random advice. I'm not saying you shouldn't pay attention to this issue, but this comment is extremely low quality.
- deleted 4y ago[deleted]
- fidesomnes 4y ago
- throwawaaay129 4y agoThis whole things looks more and more embarrassing. From the outside it just looks like the US is struggling to compete and so they create extrajudicial barriers based on "secret evidence" to block competitors. The hypocrisy is that this is the exact anti-competitive behavior the US has been criticizing China for years. It's possible these companies are doing nefarious things. In which case create a country-agnostic legal framework and take them to court and prove your case. If it's all super-secret-spy-stuff then just do the damn parallel construction and show all these secret backdoors you claim to have found. If you don't like foreign equipment near military bases or whatever else, then make laws against it After the Bloomberg microchips-embedded-into-motherboards fantasy stories you can't help but think all this is the product of some CIA director's overactive imagination and isn't based on reality. It does feed into the US frothing-at-the-mouth anti-China rhetoric of the past few years so people eat it up - but cutting out the judicial process and singling out companies/countries just looks horrible imho
- ajkjk 4y agoI feel like I don't really have any moral problem with US passing laws to protect US interests, as long as the laws aren't super unreasonable or evil. They're, like, unfair to some people, but not.. really... morally wrong? The moral complaint about China isn't that they have anti-competitive laws, it's the Orwellian thought-suppression psy-ops stuff.
- throwawaaay129 4y ago"it's the Orwellian thought-suppression psy-ops stuff." I mean that's like a "bigger" issue. I think it's a completely fair to decide you should just not conduct business with companies under authoritarian regimes (see N.Korea Iran Myanmar etc.). If you wanna blacklist the whole country then okay.. but here it's some indefensible middle ground where you continue to do business with them, until it's inconvenient and some bureaucrat decided it's making you look bad so lets just ban some of their strongest companies to cripple them. We will do business with you as long as you only make low end widgets thankyouverymuch. That might not be what's actually happening, but that's how it looks
- refurb 4y agoI just live the quote from the movie Heat: ”Assume they got our phones, assume they got our houses, assume they got us, right here, right now as we sit, everything. Assume it all.”
- ChuckMcM 4y agoI wonder if this covers Baofeng radios. (I'm not sure who their parent company is so hard to tie them to the Covered List) Trade barriers cloaked in National Security cloth are nothing new, they were common in the old Soviet Union (a lot of US made computers were forbidden from entering, and of course the US refused to sell more advanced computers based on National Security concerns), they have been active on and off with China as well. But the interesting thing for me is the reversal, which is as good an endorsement that Chinese industry is legitimately reached parity on a development scale with US goods as any press release the PRC would push out to the news wires. What it says is that China can deliver compelling solutions in the communications and surveillance space with entirely organic (and thus not controllable) supply chains resulting in products that US customers want to buy and US security interests can't insure aren't compromising their buyers. Having the shoe on the other foot has got to feel a bit weird right?
- themagician 4y agoJust going to get worse. Banning China from having EUV today will just force them to double down. They’ll eventually get it and then surpass it. It should be obvious at this point that China will dominate the hardware space in the next 10-20 years.
- rjbwork 4y agoMaybe. AFAIU, they've been pretty incapable of getting anywhere near high-end fabs working, and have relied a lot on western consultants to actually get what they do have up and running. I don't think it's a foregone conclusion that they are going to dominate cutting edge computer hardware at all.
- jolux 4y agoI would bet they'll figure it out eventually, but probably not as soon as they would have otherwise.
- ashwagary 4y agoThe US banning higher end devices also possibly means they are harder for the US to surveil. This may make them more valuable to people that are not Chinese and wont ever spend time in China.