Re: Access control for IoT

Ben Kloosterman <[email protected]> Tue, 19 Jan 2016 12:11:57 +1100
Newsgroups gmane.comp.capabilities.general
Message-ID <CAJT18ibHt6sRxdUi7pJyHwcER89k1FHeD_eWJ5kK6KODok0Vkw@mail.gmail.com>
--===============8526166439970180174==
Content-Type: multipart/alternative; boundary=047d7b2e4b4ea802080529a5908b

--047d7b2e4b4ea802080529a5908b
Content-Type: text/plain; charset=UTF-8

On Tue, Jan 19, 2016 at 8:07 AM, Tony Arcieri <[email protected]> wrote:

> On Mon, Jan 18, 2016 at 11:59 AM, Valerio Bellizzomi <[email protected]>
> wrote:
>
>> I've seen software update is a process that needs the device powered off
>> and on some devices the reflashing is via usb cable.
>>
>
> I consider automatic software updates a baseline requirement for a secure
> system. If the device needs to be connected to some sort of tether cable
> and flashed by some 3rd party software utility the user needs to install,
> those upgrades aren't going to happen.
>
>

Not practical / wise for HW / small  ioc .  Yet to see a single mother
board auto update - with good reason . HW normally works on no changes  and
if there are any changes there is normally a very length cycle before its
released. This includes Flash /EEproms  , not to mention that it some cases
you can brick the device with some Eeproms if you do  it to often.

Ben

--047d7b2e4b4ea802080529a5908b
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Tue, Jan 19, 2016 at 8:07 AM, Tony Arcieri <span dir=3D"ltr">&lt;<a =
href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&g=
t;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0=
 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div cl=
ass=3D"gmail_extra"><div class=3D"gmail_quote"><span class=3D"">On Mon, Jan=
 18, 2016 at 11:59 AM, Valerio Bellizzomi <span dir=3D"ltr">&lt;<a href=3D"=
mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt;</sp=
an> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px=
 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left=
-style:solid;padding-left:1ex"><div><div><span style=3D"color:rgb(34,34,34)=
">I&#39;ve seen software update is a process that needs the device powered =
off</span><br></div></div>
and on some devices the reflashing is via usb cable.<br></blockquote><div><=
br></div></span><div class=3D"gmail_quote">I consider automatic software up=
dates a baseline requirement for a secure system. If the device needs to be=
 connected to some sort of tether cable and flashed by some 3rd party softw=
are utility the user needs to install, those upgrades aren&#39;t going to h=
appen.</div><span class=3D""><div>=C2=A0</div></span></div></div></div></bl=
ockquote><div><br></div><div>Not practical / wise for HW / small =C2=A0ioc =
.=C2=A0 Yet to see a single mother board auto update - with good reason . H=
W normally works on no changes =C2=A0and if there are any changes there is =
normally a very length cycle before its released. This includes Flash /EEpr=
oms =C2=A0, not to mention that it some cases you can brick the device with=
 some Eeproms if you do =C2=A0it to often.=C2=A0</div><div><br></div><div>B=
en</div><div>=C2=A0</div></div></div></div>

--047d7b2e4b4ea802080529a5908b--

--===============8526166439970180174==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk

--===============8526166439970180174==--