Re: Access control for IoT
Matt Rice <[email protected]> Mon, 18 Jan 2016 22:47:24 -0800
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CACTLOFrnGssrb-pf4ab04ds7kdSAXPTfCuxSCWkYr4uAZK1_xQ@mail.gmail.com> |
--===============6699140921842293247== Content-Type: multipart/alternative; boundary=001a113eb70ef70e6e0529aa3d1b --001a113eb70ef70e6e0529aa3d1b Content-Type: text/plain; charset=UTF-8 On Mon, Jan 18, 2016 at 10:16 PM, William ML Leslie < [email protected]> wrote: > > On 19/01/2016 5:07 pm, "Valerio Bellizzomi" <[email protected]> wrote: > > > > well, it is secure as it is, because no one can reflash your device > > remotely, you have to do it by hand. > > There are three vectors that need to be considered here, and for different > products they each carry different risks. For example, security cameras > that are outside your house should not be reflashable with physical access. > > The other two vectors are the automatic update delivery mechanism, which > is the most scary IMO, and the API the device exposes. > FWIW security of remote updates is not exactly a new problem, space craft has long had the same issue, I'm not sure if the computer history museum where the last friam was held still has any association with moffet field, But I recall from a conversation with someone from there that they essentially used a jump table I'm not sure how close of an analogy can be made to the keykos primordial system image though. Anyhow it is a well researched field for mission critical applications... the primary difference is that the remoteness of space makes physical attacks difficult.. --001a113eb70ef70e6e0529aa3d1b Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo= te">On Mon, Jan 18, 2016 at 10:16 PM, William ML Leslie <span dir=3D"ltr">&= lt;<a href=3D"mailto:[email protected]" target=3D"_blank">willia= [email protected]</a>></span> wrote:<br><blockquote class=3D"gmail_= quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1= ex"><span class=3D""><p dir=3D"ltr"><br> On 19/01/2016 5:07 pm, "Valerio Bellizzomi" <<a href=3D"mailto= :[email protected]" target=3D"_blank">[email protected]</a>> wrote:<br= > ><br> > well, it is secure as it is, because no one can reflash your device<br= > > remotely, you have to do it by hand.</p> </span><p dir=3D"ltr">There are three vectors that need to be considered he= re, and for different products they each carry different risks. For example= , security cameras that are outside your house should not be reflashable wi= th physical access.</p> <p dir=3D"ltr">The other two vectors are the automatic update delivery mech= anism, which is the most scary IMO, and the API the device exposes.<br> </p></blockquote></div>FWIW security of remote updates is not exactly a new= problem, space craft has long had the same issue, I'm not sure if the = computer history museum where the last friam was held still has any associa= tion with moffet field,<br><br></div><div class=3D"gmail_extra">But I recal= l from a conversation with someone from there that they essentially used a = jump table I'm not sure how close of an analogy can be made to the keyk= os primordial system image though.<br><br></div><div class=3D"gmail_extra">= Anyhow it is a well researched field for mission critical applications...<b= r></div><div class=3D"gmail_extra">the primary difference is that the remot= eness of space makes physical attacks difficult..<br></div></div> --001a113eb70ef70e6e0529aa3d1b-- --===============6699140921842293247== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk --===============6699140921842293247==--