Re: Access control for IoT
Valerio Bellizzomi <[email protected]> Tue, 19 Jan 2016 07:07:05 +0100
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Organization | SEL |
| Message-ID | <[email protected]> |
On Tue, 2016-01-19 at 12:11 +1100, Ben Kloosterman wrote: > On Tue, Jan 19, 2016 at 8:07 AM, Tony Arcieri <[email protected]> wrote: > > > On Mon, Jan 18, 2016 at 11:59 AM, Valerio Bellizzomi <[email protected]> > > wrote: > > > >> I've seen software update is a process that needs the device powered off > >> and on some devices the reflashing is via usb cable. > >> > > > > I consider automatic software updates a baseline requirement for a secure > > system. If the device needs to be connected to some sort of tether cable > > and flashed by some 3rd party software utility the user needs to install, > > those upgrades aren't going to happen. > > > > > > Not practical / wise for HW / small ioc . Yet to see a single mother > board auto update - with good reason . HW normally works on no changes and > if there are any changes there is normally a very length cycle before its > released. This includes Flash /EEproms , not to mention that it some cases > you can brick the device with some Eeproms if you do it to often. > > Ben well, it is secure as it is, because no one can reflash your device remotely, you have to do it by hand.