3 ms·
Commissioner, thank you for raising this important issue and bringing more attention to IoT security. More transparency around support lifetimes is a step in th
by gzer0 3y ago
Commissioner, thank you for raising this important issue and bringing more attention to IoT security. More transparency around support lifetimes is a step in the right direction, but I worry it doesn't go far enough.
The problem is that consumers simply aren't equipped to make security-informed decisions even with perfect information. How many years of updates matters little if the software has vulnerabilities to begin with. And there's no guarantee manufacturers will fully honor the length they claim.
Rather than disclosure rules, I believe we need minimum security standards that all IoT devices must meet before sale, eg:
No hard-coded credentials/keys
Encryption of sensitive data
Ability to patch known vulnerabilities
Use of secure boot to prevent unauthorized firmware
Standards could be tiered by device type and risk level. Compliance could be self-certified with spot audits, like PCI DSS.
This puts the burden on manufacturers to build more secure devices upfront, not just promise to patch them later. Consumers benefit from safer defaults without needing to become security experts themselves.
Standards also allow security to improve over time as threats evolve. Disclosure rules would quickly become static and outdated.
I'm sympathetic to manufacturer concerns about costs, but I think basic security is a reasonable consumer expectation by now. If we act soon, we can prevent IoT disasters before the market grows even further. I hope you'll consider proposing minimum standards within the FCC or partnering with other agencies like NIST who could.