Re: Access control for IoT

Valerio Bellizzomi <[email protected]> Tue, 19 Jan 2016 07:07:05 +0100
Newsgroups gmane.comp.capabilities.general
Organization SEL
Message-ID <[email protected]>
On Tue, 2016-01-19 at 12:11 +1100, Ben Kloosterman wrote:
> On Tue, Jan 19, 2016 at 8:07 AM, Tony Arcieri <[email protected]> wrote:
> 
> > On Mon, Jan 18, 2016 at 11:59 AM, Valerio Bellizzomi <[email protected]>
> > wrote:
> >
> >> I've seen software update is a process that needs the device powered off
> >> and on some devices the reflashing is via usb cable.
> >>
> >
> > I consider automatic software updates a baseline requirement for a secure
> > system. If the device needs to be connected to some sort of tether cable
> > and flashed by some 3rd party software utility the user needs to install,
> > those upgrades aren't going to happen.
> >
> >
> 
> Not practical / wise for HW / small  ioc .  Yet to see a single mother
> board auto update - with good reason . HW normally works on no changes  and
> if there are any changes there is normally a very length cycle before its
> released. This includes Flash /EEproms  , not to mention that it some cases
> you can brick the device with some Eeproms if you do  it to often.
> 
> Ben

well, it is secure as it is, because no one can reflash your device
remotely, you have to do it by hand.