Re: Access control for IoT
William ML Leslie <[email protected]> Tue, 19 Jan 2016 17:16:42 +1100
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAHgd1hEpKyb7fvwTGdhbozyLx4Ute=3g+r9tnRxEwbxyBvQDQg@mail.gmail.com> |
--===============5796568229942998057== Content-Type: multipart/alternative; boundary=001a1143901a3618700529a9d0d5 --001a1143901a3618700529a9d0d5 Content-Type: text/plain; charset=UTF-8 On 19/01/2016 5:07 pm, "Valerio Bellizzomi" <[email protected]> wrote: > > well, it is secure as it is, because no one can reflash your device > remotely, you have to do it by hand. There are three vectors that need to be considered here, and for different products they each carry different risks. For example, security cameras that are outside your house should not be reflashable with physical access. The other two vectors are the automatic update delivery mechanism, which is the most scary IMO, and the API the device exposes. --001a1143901a3618700529a9d0d5 Content-Type: text/html; charset=UTF-8 <p dir="ltr"><br> On 19/01/2016 5:07 pm, "Valerio Bellizzomi" <<a href="mailto:[email protected]">[email protected]</a>> wrote:<br> ><br> > well, it is secure as it is, because no one can reflash your device<br> > remotely, you have to do it by hand.</p> <p dir="ltr">There are three vectors that need to be considered here, and for different products they each carry different risks. For example, security cameras that are outside your house should not be reflashable with physical access.</p> <p dir="ltr">The other two vectors are the automatic update delivery mechanism, which is the most scary IMO, and the API the device exposes.<br> </p> --001a1143901a3618700529a9d0d5-- --===============5796568229942998057== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk --===============5796568229942998057==--