Re: Access control for IoT

Tony Arcieri <[email protected]> Mon, 18 Jan 2016 13:07:42 -0800
Newsgroups gmane.comp.capabilities.general
Message-ID <CAHOTMVJOtOgM1pR_tbVKaJtuERFD0FJ7XgDbcJhjTn_wqg8KmA@mail.gmail.com>
--===============1160737510074221091==
Content-Type: multipart/alternative; boundary=001a113f9b44f1a4a30529a2259e

--001a113f9b44f1a4a30529a2259e
Content-Type: text/plain; charset=UTF-8

On Mon, Jan 18, 2016 at 11:59 AM, Valerio Bellizzomi <[email protected]>
wrote:

> I've seen software update is a process that needs the device powered off
> and on some devices the reflashing is via usb cable.
>

I consider automatic software updates a baseline requirement for a secure
system. If the device needs to be connected to some sort of tether cable
and flashed by some 3rd party software utility the user needs to install,
those upgrades aren't going to happen.


> It depends, if there is a full OS, it can do updates via remote link.


An full OS is not a requirement for remote upgradability. However, the only
systems I know for doing this in a manner I'd consider secure are
proprietary.

-- 
Tony Arcieri

--001a113f9b44f1a4a30529a2259e
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">On M=
on, Jan 18, 2016 at 11:59 AM, Valerio Bellizzomi <span dir=3D"ltr">&lt;<a h=
ref=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&=
gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);bord=
er-left-style:solid;padding-left:1ex"><div class=3D""><div class=3D"h5"><sp=
an style=3D"color:rgb(34,34,34)">I&#39;ve seen software update is a process=
 that needs the device powered off</span><br></div></div>
and on some devices the reflashing is via usb cable.<br></blockquote><div><=
br></div><div class=3D"gmail_quote">I consider automatic software updates a=
 baseline requirement for a secure system. If the device needs to be connec=
ted to some sort of tether cable and flashed by some 3rd party software uti=
lity the user needs to install, those upgrades aren&#39;t going to happen.<=
/div><div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px=
 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);bor=
der-left-style:solid;padding-left:1ex">It depends, if there is a full OS, i=
t can do updates via remote link.</blockquote><div><br></div><div>An full O=
S is not a requirement for remote upgradability. However, the only systems =
I know for doing this in a manner I&#39;d consider secure are proprietary.<=
/div><div><br></div></div>-- <br><div class=3D"gmail_signature">Tony Arcier=
i<br></div>
</div></div>

--001a113f9b44f1a4a30529a2259e--

--===============1160737510074221091==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk

--===============1160737510074221091==--