4 ms·
Perhaps the ban / tariff / regulation should be applied to companies making networking hardware that's riddled with flaws and exploitable vulnerabilities, rathe
by moduspol 2y ago
Perhaps the ban / tariff / regulation should be applied to companies making networking hardware that's riddled with flaws and exploitable vulnerabilities, rather than by naming specific companies or countries of origin.
- rekabis 2y agoI would be fully open to the FTC/CRTC or whatever network/ISP regulator that exists in your country be the determiner of what should be exposed to world+dog. Let them do remote vulnerability scans once a day on all IP addresses assigned to domestic ISPs or locations physically in-country, then flag the IPs that have vulnerable routers. From there, they can force ISPs to contact their clients to demand the issue be resolved. If the client does not respond to the ISP, the ISP is forced to suspend the connection until the client can demonstrate a fix has been implemented. In all cases, that vulnerability vanishing has the ISP updated so the client is no longer in danger of being pestered. If the product is still being sold in stores, or is not very far past EoL, and there is no manufacturer patch available, those manufacturers must take their hardware back for a 100% MSRP refund, or provide an equivalent router without those exploits. It’s only if the product has been no longer manufactured for a minimum set period of time - say, 7 years - that it is deemed “too far past EoL” for the responsibility for patching/replacing to fall on manufacturers, and responsibility finally falls to the consumer to replace/upgrade. In all cases, a customer can “fix” their router with third-party firmware such as OpenWRT or DD-WRT, but this also requires laws to be written that forces manufacturers to not hardware-lock their routers, and force them to meet the minimum storage/driver-availability specs these third-party firmwares need.