As usual for these posts. No certifications. No proper markings. Probably non compliant. Will probably go unpunished.
HN user
negative_zero
Modular Approval is an FCC thing only. CE doesn't have it.
It always seems wild to me how, in the US, something like the grid is just a wild west.
"ERCOT said it is reviewing the test failures and drawing up plans to protect the grid from disruptions."
Why are they even allowed to connect? / Why are they not kicked off? / Why aren't they being forced to add their own grid inertia?
Any chance of having a finger print scanner on the back of the phone?
I personally really dislike the screen ones. They're slower, less reliable and the location is unnatural.
So if I am a small open source developer or run small website, this could be added to my AI scraping defences?
If something like Nepenthes added poisoned pages to it's tarpit then a small number of users can just poison all LLMs?
Network people: Do we even need MAC addresses anymore? Can we not just have a UUID that the device generates?
They seem to get more abuse over time i.e. MACs are how a car is uniquely identified and authenticated with fast charging CCS networks for Autocharge.
I've also had APN issues with physical SIMs, they are definitely not perfect. But I have never had an unusable "bricked" physical SIM. My eSIMs gripes are from being unable to use the eSIM at all. It's essentially a brick at that point.
I did not know that. It's amazing how the usability and utility has taken such a big hit.
Calling it "eSIM" is BS marketing. Every time I've used them it's been painful. I don't know the details but it absolutely is not "SIM technology". "eSIM" is something completely different.
A regular SIM: you just pop a SIM card into your phone and it just God damn works.
But eSIMs? I've used eSIMs from five carriers in three different countries and every time there is some issue:
* "Oh you need our god awful app to install an eSIM" (of course I couldn't easily download it because Google play geo hides apps).
* "If your phone is stolen overseas you can simply use this QR barcode again to register an eSIM to a new phone" (I couldn't).
* "Works with all phones". (It didn't because phone manufacturers have to bake Telco specific data into your phones firmware. Not supported? You're shit out of luck).
I could go on..
The fact that there are now privacy and security issues is not surprisingly at all. This isn't teetching issues. The drafters of the eSIM standard should be publicly flogged.
Well I can say that the update is not going 100% smoothly. I have a pending KEK update in Fedora but it's a test key (bug filed but no progress as of yet).
Why would I use this over PlugShare?
The limitation is both ISS scheduling (it's very busy now and has been for a while) and number of available docking ports.
It's part of why the next crew dragon mission is being delayed, it needs to use the docking port currently occupied by Starliner (and Starliner can't leave until Boeing updates and uploads software for full autonomous operations).
I would add PFASs to the suspect list.
100% agree. IMO, these days it seems like FPTP is more actually a source of instability (than stability it is often claimed is one of it's benefits).
Just want to add some nuance:
STV is used for the Australian Federal Senate.
The federal lower chamber (House of Representatives) uses optional preferential voting for candidates in a federal electorate.
I'm not sure if NZ is a fair comparison as it uses MMP, which is deliberately designed to favour multiple parties forming coalitions, not independents.
Excellent additions. Sadly for Canada, some companies I worked with didn't bother because of these differences. "US market is big enough for launching. Maybe we'll come back to Canada later." They rarely did.
One company I have worked with had an internal rule for "radiated emissions": You had to be 10dB (1 order of magnitude) underneath the limits before going for a formal cert. Non-negotiable.
Part of the reason for this rule was that they:
1) OEMed their products.
2) Sold products that could be used in complex and bespoke CAN networks with goodness knows what else.
3) There was a chance of interfering with Marine VHF radio which is used for emergencies. The EU rules were (still are) not actually strict enough for preventing interference with that band.
There used to be. But they've been almost completely stripped away because of rampant abuse.
Hard agree that pricing for standards is generally insane. IMO if the law requires it, it should be free + maybe a $10 admin. Anything else is BS. Standards bodies already make a killing off their membership fees. There are alternatives and workarounds though, here is one: https://news.ycombinator.com/item?id=36452660
If you don't want to hire a consultant then don't. You can do it yourself. Go get a EEE degree and then spend 5-15 years working as a EEE in product development and certification. Then you'll be good to go :)
Or just blind self certify and pay the lawyers, Friendly Spectrum Agency and other spectrum users (like cell phone companies) when they come knocking and asking for damages from you.
Here is a free primer I replied with earlier today: https://news.ycombinator.com/item?id=40926870
As someone who has built relationships with labs to the point where I had "special privileges" the most important thing you can do is:
Make your test setup as easy as possible.
To expand on that:
1) Realise that you're mostly working with testing technicians NOT engineers. They see all sorts of weird and wild stuff. They often have to parse poorly written and complicated manuals written by engineers who don't have a clue about writing manuals and make poor implicit assumptions about the "target audience".
2) It's frankly, often soul destroying work (hence the churn, especially at the bigger labs). They use the crappy manuals for crappy products (but everyone thinks their product is the bees knees) try and set it all up. Then it doesn't work. Or it fails because the customer didn't do any pre-compliance work and was "hoping it would just pass". Well time is money, now they have to break the setup down because they've wasted 1 hour on the phone to some engineer who doesn't know what's wrong and is trying to trouble shoot through the phone. Now they get to do ALL that again with one else's crappy product.
So how do you make it as easy as possible for them?
1) Your setup should be plug and play and I mean TRULY plug and play. No manual should be required for putting the device into some hacky test state. Get the software engineers to automate it.
Does a button need pushing? Automate it or just remove the requirement somehow.
Does it need wiring up? Nail it all down on a giant piece of ply wood. Zip tie down all the cables. All the dummy loads. Any other devices. The only thing they should need to connect is the power cable.
Does a laptop need to drive it? Automate everything on there. ONE SCRIPT, maybe a menu in there depending on what test they are running. Make the laptop bullet proof. Get a nice laptop that boots and runs fast (not the one at the bottom of the IT donor pile). Give them a mouse to use.
Remove ALL of these barriers. AUTOMATE it ALL. Don't require them to baby sit it. That's a waste of their time.
PLUG AND PLAY.
2) Make it easy for a technician to see if and when the device is working VS it's not working. Don't give them instructions on "open this menu, do this, do that ..." no.
Put a red LED on it and a green one. Don't have one in your product? Be creative, Retrofit something. Have a special test UX on the device. Hell you should have special test firmware as a reference point.
They should be able to, at a single glance, look at the product and know: "Is it still working/running?"
So now imagine you have done all of that effort. Now put yourself in the shoes of that technician. One of the test stands is available early because a crappy product failed. They gaze towards the giant pile of crap they have to get through. Many are a a giant plastic box with tangles of cable, hand written crappy instructions, an IBM thinkpad from 1995 to drive it, no labels on any of the cables ....
... but amongst it they see your PLUG AND PLAY testable product. It's all mounted on a plywood stand, ready to go. There is almost a light from heaven illuminating it, it's so beautiful, it's so easy throw on a test stand and GO (and then do something else).
Guess which one is jumping the queue and going on that test stand? (And time is money remember. A test stand not testing is loosing money).
Ethics approval for a medical device is a completely different thing from EMC regulations (which is what normally people mean when talking about FCC and CE for a device).
"I can't imagine having to have each hardware iteration certified by the FCC."
Depending on your device and the magnitude of the changes, this might simply be the reality for you. This is why I always try to tell people that you need compliance at the table from the start or you really risk making life very difficult for yourself. Find yourself a compliance specialist or at least a hardware engineer who is familiar with the regulations.
EDIT: You CAN'T just iterate ad-infinitum for free without consequence like you do for software. This thinking and approach, only works in software land. No where else.
It would be ridiculous to build a house and having the builder iterate on your house over 2-3 years to finish it, no?
See my response to a similar question here: https://news.ycombinator.com/item?id=40926103
EMC compliance rules are needed so that all our electronic devices (running software mind you) can continue to function. Part of the rules are about squeezing as much "performance" as possible out of the "thing" that is the electromagnetic spectrum. It's simple physics.
The other part of the rules are for human safety. Devices can directly hurt people (like a microwave) or indirectly (like a crappy device that prevented ambulance phone calls going through).
It's as simple as that (and not perfectionism or being mean to the poor software people).
""we're going to teach you how to cheaply get your product to market in a way that respects the spectrum" I'm available to do exactly that for you at my hourly rate :D
You are correct on the spread spectrum clocks. Outside of military, they really soley exist for compliance (specifically unintended electromagnetic emissions) and are increasingly everywhere out of necessity. If an integrator needs spread spectrum locked on, there is no doubt a BIOS available that does just that.
"Now that I'm in position to ask ;)"
Ask away :) This is boring for 99.99999% of the population so I don't get to talk about it often :)
"I've wondered about the glass/plastic window PC cases.. Surely a PC case itself would not be required to have any emission tests done on it, or would it?"
You're right, a PC case itself does not need EMC compliance, but a PC case that's sold with a power supply does. So does one with built in fans and lights or anything electronic. IMO and very much off the cuff, certing the case + lights and fans without a whole computer inside is probably reasonable. But I would personally try cert with a whole PC (defence in depth).
"On the other hand, might the PC motherboard emissions be certified with the assumption that it will be placed inside a case?"
Yes it can be certed that way. Generally if it is, the details have to be in the manual.
But also, legally, you don't really need to cert a motherboard because it will always be integrated into another thing. However the reality of the PC architecture is that it is extremely modular and reach module is extremely complex. It's simply not at all practical for any systems integrator to try to modify those modules to try and make a whole PC compliant so that they can sell it. Even sticking the whole thing in a metal case might not be enough because the case has cables attached to and unwanted emissions and get out via those.
So for practical purposes manufacturers of motherboards, graphics cards, PSUs, hard drives etc vigorously test and cert their products with decent margins so that no matter what cards are used or how a PC is put together, the sum will be compliant. And this rule holds pretty well in general at all scales, from the individual parts and submodules that come together to make a product up to several products wired together in your house with power and network cables.
And system integrators can demand these requirements because it's necessary for the industry to function. I found a few years ago on Dell's website their manual for part suppliers. It listed every standard they required, made stricter and even had additions of their own so that they could sell with your module everywhere in the world, because they sell everywhere. It basically a thick manual on making a computer "world compatible".
"And then finally comes a consumer (or even a small integrator) and sticks in a PC motherboard inside a windowed case—but in this case the case might not be doing much on the RF side. Or maybe the cases provide better RF protection than they look like or the MBs don't need a case for that reason in the first place :)."
And the consumer benefits from everything I explained earlier. They can buy parts and assemble a computer that will be compliant. It's also why computer shops can build you a PC and sell without a cert and it'll be fine. Just the sheer effort of all these manufacturers so that they have a market to sell into means that the problem is solved for small players in the traditional PC world. The traditional PC industry is quite unique in that way actually.
No problems. You are very welcome :)
It sounds like you are actually doing some things right :) FCC, for example, have scope for "modular approval". Order a radio module (with modular approval), do exactly as the datasheet tells you and you can "piggy back" off the radio modules radio certs. But you will still need to test and cert for things like your own "unintentional emissions", maybe ESD and other things (NOT actual compliance advice btw, this is just to give a rough picture).
"That said, while I actually enjoyed the snark in your reply, there are those of us who actually do want to get this right and do the right thing, despite lacking years of experience and an infinite budget."
Oh I absolutely know you people are out there :) (I've consulted for them. I've also consulted for the ones who are learning the hard way...)
I don't intend to be mean with posts like this on HN, but some reality on these posts is just needed IMO. Especially given how much software dominates product development these days and people just don't know.
I think it's difficult for new comers, but I don't know how you fix that other than asking a consultant. The earlier the better. You can certainly make early feature and design choices to make your certs simpler (and cheaper) down the road.
That said, I think a good place to start for anyone is the following:
1) Find a product that is broadly similar to yours. Is it like a small computer? Is it a wired network device like a router? Maybe it's like a bluetooth dongle or smartwatch? Find one from a large reputable company and search said company's website for their "EU Declaration of Conformity". On these docs (even though it is not required) many companies list the standards that the device is compliant with. They have names like: EN 55022, EN 60950, IEC 61000-3-3.
NOTE - This is for EU only, but they have massive regulatory reach. Also many FCC and EU standards are very similar or even the same. Over time they have been converging more and more.
2) Do this for a few different devices of the same or similar category and you will notice many which are always there and some that are sometimes there. Now you have a starting template of standards that you might need.
3) With this starting template, you can now look up the standards names and often download the first few pages free to get an idea for what they are for.
4) Get a quote from a lab. They often do a lot of testing for product importers (as onus is also on said importers), so they can have "non-engineer friendly" forms that you can fill in. This will give you a price but also some information on what they think you need (they have to be careful though because they have to maintain their independence). Tell them you want CE (Europe) and FCC (North America). This covers much of the world for you. Many countries, even those with their own standards, also simply accept CE and FCC (again this is all in very very broad strokes). Many standards are also just copy and pasted between different regulatory domains but they change the name. So the original standards body will have their name for it. When the EU recognises it, it'll get an "EN" number for it's name (for example).
4b) Consider a hiring consultant for a short chat to "downsize" the standards you need and maybe they can point out any you might be missing. Good ones can also advise you on things you can do to avoid standards (and this is not in an illegal way). If you understand the rules well, you can sometimes make small changes and avoid whole sets of rules and testing (classic one IMO is a radio device. In VERY GENERAL TERMS, if it's going to be used more than 40cm from a human, then you don't need to test for human absorption of RF energy. My Chromecast, for example, has a disclaimer on it so that they can claim exactly this (IMO of course) ). How to find a good consultant? Well that's hard and I don't have a sure fire way sorry. Some labs have business cards of small local consultants.
5) Source copies of the standards and read them (Yes it'll likely be heavy reading). Most standards sellers (including the national ones) are crooks. Don't use them. Instead go to the Estonian Centre for Standardisation and Accreditation: https://www.evs.ee/en . They are the cheapest source I know of for standards in English (and only English matters). Further details in an old comment of mine here: https://news.ycombinator.com/item?id=36452660
These above steps are the same steps that I myself use.
Sources to read ... sadly I've not found many good ones. I think the best one that I would recommend is https://incompliancemag.com/ It's dry and does what it says on the tin. But their archives have some great articles by experts. They cover new standards, certing particular devices, testing technology etc. Even the ads can be kind of informative I think. It's good for learning the general layout of the field. Not a shallow learning curve but not steep either IMO (It's also free in digital form).
Then it's on you as the importer. This is part of why lots of stuff on AliExpress and dodgy Amazon 3rd party supplies is cheap. It's non compliant stuff that is not even sold in China. It's export only, and for the wrong reasons.
In the purest theoretical sense yes, in practice no. So that you don't have to recert everytime, you
1) test and exercise your product to extremes so that you can say with high certainty that: no matter what the customer loads, it won't breach the rules.
2) As pjc50 mentioned: Lock down the parts which the user could potentially cause the most damage with. i.e lock down that radio firmware (why is why none of it is open source).
If you do (1) and (2) and a few other things, you buy down your risk sufficiently that you can confidently demonstrate that re-certs are not needed.
The Author of the parent article IMO is doing the exact opposite.
There are also half-way houses: Just doing "pre-compliance testing". So not a formal cert, your just doing a quick test in an anaechoic chamber or even on a table top scanner. Of course this only applies to things you can self-certify. Some things, like radios (WiFi, Bluetooth etc.), you cannot self-certify. That's why almost everyone buys the radio as a module (To buy down their risk). By consequence: That's why those radio module manufacturers have the firmware locked down hard and engineer and cert the radios to have big margins.
There are a lot of rules yes, but there is actually a lot of flexibility and common sense in the system too (but it is still imperfect, absolutely). But that flexibility does not allow for horsing around. If you can demonstrate to Friendly Spectrum Agency all this due diligence, you are going to have a MUCH better time.
That was not my read on it. My interpretation was that they wanted to sell a product, but didn't want to pay for an engineer who understands all this, labs for testing and doing all the paper work that it entails. So the plan became: "Customer buy this software, buy that hardware and put it together" => not liable => profit.
"Is this not exactly equivalent how I might buy a Raspberry Pi and install a non-Raspberry-authorized OS on it? Or equivalent on how I might buy a PC and install Linux on it? Or Android and LineageOS? Are those devices certified not only as SOLD but also as modified by the end-user with software, making them somehow different?"
Yes and no :) Very very succinctly: When you test and cert, it is best practice to create the worst case scenario for your product and pass like with healthy margins. Especially for something like a smartphone or PC, when it's in the test chamber (for something like radiated emissions), you run it at "full noise" (even if it's not a realistic use case). So all your clocks: maximum (don't use all of the clocks? Turn them all on anyway); Power draw: Maximum or more; Play seizure inducing video to exercise that screen; Connect peripherals that are likely to be used to make sure those don't screw you etc. PCs and phones, especially, are tested at these extremes so that the manufacturer can be confident that despite what software the end-user loads, the device will remain compliant (this is also why the radio firmware is kept locked down hard).
Now in the case of this article, sure, the dev boards have CE, but what does that mean? How did they test it? Where all the peripherals running? What did the physical test setup look like? Under CE they are required to keep a compliance folder and to provide the information on request.
My experience with, dev boards that are "compliant". They just powered it up and maybe ran a simple program. Low effort, low noise, easy pass, because the reality is that they don't need it and time is money.
So now you a third party integrator takes that dev board, and runs something that wasn't exercised or puts it into a state that is non compliant. That's on you. Just like it's on the Author of this article.
I might be wrong in this case. Maybe the dev boards have excellent test setups. I might look at the test docs and think: "oh we should be fine". And just do a pre-compliance test and self-certify. You have to evaluate the risk each time and make a call.
If Microsoft released a patch tomorrow that somehow caused a sizable percentage of PCs to start stepping on the cell phone bands they would VERY quickly be told (I emphasise told NOT asked) to fix it. Just like any software this Author could load. They have not sidestepped any responsibility.
EEE here with 16 years experience and having to deal with compliance from day 1 of my career. I now consult on product compliance. Author you are welcome to contact me.
Disclaimer: Nothing below is meant as legally relevant compliance advice. This is just my opinion on the matter.
Going to snark:
"The testing and certification industry is odd"
Except, outside the software world, the real world, where there are real consequences, it's not really.
"The line about CES, in particular, made my hair stand up."
Why? Absolutely the unauthorised device at CES is should NOT be allowed. What if said device caused too much interference on cell phone frequencies and suddenly nobody at CES can dial the local emergency number?
If that made "your hair stand up", here's one from personal experience that will freeze your blood:
I worked as a teen for a certain electronics chain. Said chain was selling a wireless weather station imported from China. A government department that monitored the country for Earthquakes noticed that this device impinged on their frequencies. After the spectrum regulator confirmed the finding, a nice gentleman from them visited us a told us the following:
1) As of this moment this device can no longer be sold. Move it off the floor immediately (he stayed and made sure we did exactly that).
2) That we will immediately issue a recall of said device at your own cost and issue full refunds to the customers.
3) He will return when we decide on further enforcement action which may include punitive fines and recommendations for further remedial action you will need to undertake.
"In theory, it exists to serve the public good and uphold consumer protection laws."
Well here's a (very simplistic) tidbit for the author: In the US, part of the gestation and formation of standards bodies and testing was "market forces", not for the public good. It was to help protect companies from litigation. If you followed the standards, tested and certed to them, paid the fees etc you then had the standards entity bat for you in court (UL is short for Underwriters Laboratory. That name was not chosen for funsies).
"However, in reality, the labs are “too busy” to respond or reply very late and generally sound less than eager to work with you."
Well you don't sound like a serious customer. AND the Labs are not there to give you advice. They're there to do INDEPENDENT testing.
"Variations of the FCC exist in pretty much every developed economy. Putting a poorly tested hardware product on the market immediately puts a target on your back. Maybe you’ll get lucky, but chances are that someone somewhere will report you. And, unless you are operating entirely out of China, it will hurt. A lot. Both your company and maybe even you, personally."
As it should. The electromagnetic spectrum is a very precious and very limited commodity and IMO, the best regulated "commons" in human civilisation (though still not perfect). So no, you are not welcome to just urinate in it willy nilly with your hustler start up product.
"I did not want to spend so much money on testing before I validated the market or gathered a community of believers."
And there it is.
"This way, the electronic device liability will fall on the manufacturer, and the magic of friendship EULA should afford me enough protection to make this a pure software play."
No. That's not how this works.
1) I assume the author is from the US (as they speak about the FCC). I had a 30 second look at these dev boards and their instructions. There is no FCC conformity declarations or markings, so US customers can't use it.
2) It has CE and UKCA though, so customers from EU+UK (and some other countries) can buy them but the certs only cover the dev boards AS SOLD. (i.e without the authors software)
3) Author is modifying the product behavior with their software. So yes author. You are still liable. Technically, your customers are first in the line of fire. But the likely sequence of steps is: Friendly Spectrum Representative will visit them first, have a chat, ask them to stop using the device, then leave them a lone and then come for YOU.
4) What the author has actually done is "buy down" their risk. It is simply less likely that the product will become non-compliant when their software is loaded. But it is still possible. At second glance, those dev boards don't come with a power supply. What is your recommended power supply to use Author? Have you tested your setup with said power supply and have test reports at the ready for when Friendly Spectrum Person comes knocking?
5) Sure it seems clever but Friendly Spectrum Agencies actually have quite far reaching and scary powers. Don't think that your little sleight of hand here is clever and protects you. Fundamentally: You are repackaging + modifying an existing product. The steps you are taking in between to "launder" your liability are irrelevant.
Frankly, it's shit like this, that makes it harder for everyone else playing by the rules. It did actually used to be easier. There used to be exemptions for "low volume" products. But all of those were seen as loopholes and HEAVILY abused. Now these toys have been taken away, with more to follow.
I guess I am showing my age maybe, but 10 seconds for a TV to turn on is insanely long for me and seems even more insane when that is perceived as impressive. Companies love their bloatware.