FCC Proposes Voluntary Security Labels For ‘Internet Of Things’ Devices Most Companies Will Probably Ignore

from the regulatory-theater dept

While government leaders spent the last three years hyperventilating about TikTok, less talked about has been the dodgy “internet of things” (IOT) space; a broad assortment of mostly overseas-made techno doodads with paper-grade security and privacy standards that Americans connect to home and business networks with reckless abandon.

“Smart” TVs, fridges, and other internet-connected devices that experts have been warning us about for more than a decade often lack even fundamental security and privacy protections.

Enter the government, which is contemplating a new voluntary privacy and security label for IOT devices that manufacturers may or may not ever actually adhere to. According to separate FCC and White House announcements, the idea came from FCC boss Jessica Rosenworcel, and involves putting a “U.S. Cyber Trust Mark (aka a sticker) on products that adhere to certain privacy and security standards:

“As proposed, the program would leverage stakeholder-led efforts to certify and label products, based on specific cybersecurity criteria published by the National Institute of Standards and Technology (NIST) that, for example, requires unique and strong default passwords, data protection, software updates, and incident detection capabilities.”

FCC Commissioner Nathan Simington this week spent some time over at Hacker News discussing the new proposal, which is only in its early stages. He requested that folks who’ve had problematic privacy or security issues with IOT devices file their thoughts with the FCC during the public comment process:

“If you want to influence the process, you have until September 25th, 2023 (midnight ET) to file comments in the rulemaking proceeding.[4] Filing is easy: go to https://www.fcc.gov/ecfs/search/docket-detail/23-239 and click to file either an ‘express’ comment (type into a textbox) or a ‘standard’ comment (upload a PDF). Either way, the FCC is required to consider your arguments. All options are on the table, so don’t hold back, but do make your arguments as clear as possible, so even lawyers can understand them.”

The program will initially take aim at stuff like smart refrigerators, TVs and fitness trackers. Eventually it will shift to routers, where lax security has also long been a problem. It’s certainly not the first time government or other organizations have advocated for more robust IOT standards. Consumer Reports in 2017 proposed an open source IOT standards system that (IIRC) never really went anywhere.

I don’t think this is a terrible idea, I just have my doubts that this FCC can actually implement and enforce it at any scale. This is an FCC that’s effectively given up on consumer protection or seriously regulating broadband industry giants under its direct authority, so the idea that it’s going to consistently play hardball with a universe of dodgy IOT device makers seems somewhat laughable.

This kind of voluntary stuff is fairly standard for the FCC’s Rosenworcel, who is also proposing an entirely voluntary broadband “nutrition” label consumer groups already say lacks the kind of detail or rigor to be genuinely useful to consumers being ripped off by their local broadband monopoly.

It’s a sort of regulatory theater. Made worse in an environment where Congress is too corrupt to implement meaningful reform. You design programs that look like they’re tackling a major problem, but you make them voluntary — out of fear that being tough with larger companies might upset them. For example, the FCC’s nutrition label voluntarily asks broadband monopolies to be transparent about their high prices, but it never addresses the real cause of high broadband prices (unchecked monopoly power).

Most careerist regulators don’t want to actually regulate. They want to bide their time until their next political promotion or industry or think tank gig, usually through performative solutions that look good but don’t actually fix the underlying problem. Genuine reformers with the kind of fierceness needed to implement real reform genuinely aren’t treated well by entrenched power (see: Gigi Sohn).

Here, we’re asking an underfunded and understaffed agency to create a label system for a massive ocean of interconnected markets and thousands of different companies all over the globe. And we’ve made it voluntary. Many of the worst offenders when it comes to IOT security come from China, where companies could care less what Jessica Rosenworcel or the FCC think about much of anything.

I’d love to be wrong and see this program develop into a useful framework that elevates more trustworthy brands and provides consumers some long-overdue guidance on privacy and security. The underlying aspiration is sound. I’ve just been watching this agency long enough to know that it lacks the backbone or courage required to implement any reform that seriously challenges the interest of big companies (again see the sleazy, bipartisan undermining of Gigi Sohn, or the FCC’s multi-decade failure to hold predatory giants like AT&T, Comcast, Verizon, or Charter accountable for much of anything).

That’s not to say that consumers shouldn’t participate in the FCC rulemaking process, it’s still within the realm of the possible that the agency could be prodded into developing a backbone.

Filed Under: , , , , , , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “FCC Proposes Voluntary Security Labels For ‘Internet Of Things’ Devices Most Companies Will Probably Ignore”

Subscribe: RSS Leave a comment
16 Comments
Anonymous Coward says:

Stickers are nice, I would prefer a standard of opt-in for any and all internet connection requirements. If the device being sold will only operate when connected to the internet, they need to state such very clearly. In addition, they need to identify any and all options and features that will not work unless connected to the internet, or require payment for them to operate.

Anonymous Coward says:

“Voluntary” IOT Security Labels contradicts the whole concept of government Regulation.

That widespread concept demands that government experts determine the best ways to do things in selected private sector areas and require all perspns to obey the government rules developed.

Voluntary-Regulation is an oxymoron.

Anonymous Coward says:

Re:

prefer the idea of a voluntary standard to [a mandatory standard]

Given that a certain sense of latitude and trust comes with the word ‘voluntary’, we know for a fact that any and all industries uniformly subscribe to the Number One tenet in the military – Never Volunteer For Anything!

And thus we have rules and regulations. Q.E.D.

Anonymous Coward says:

Re: Re: Re:

And do you realize how long it took to get those standards in place? Decades. And they aren’t all voluntary, some of the ANSI stuff is mandatory, as for example, motorcycle helmets. Every state requires riders to have (and use!) one that adheres to ANSI Z90.1 (IIRC). Many more examples can be found, I’m sure, but the point is, ‘voluntary’ usually doesn’t become mandatory for some time, unless a veritable rash of deaths occur in a very short time frame – that usually gets the attention of both the public and the legislative bodies.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...