Re: Access control for IoT

Valerio Bellizzomi <[email protected]> Tue, 19 Jan 2016 07:49:56 +0100
Newsgroups gmane.comp.capabilities.general
Organization SEL
Message-ID <[email protected]>
On Tue, 2016-01-19 at 17:16 +1100, William ML Leslie wrote:
> On 19/01/2016 5:07 pm, "Valerio Bellizzomi" <[email protected]> wrote:
> >
> > well, it is secure as it is, because no one can reflash your device
> > remotely, you have to do it by hand.
> 
> There are three vectors that need to be considered here, and for different
> products they each carry different risks. For example, security cameras
> that are outside your house should not be reflashable with physical access.
> The other two vectors are the automatic update delivery mechanism, which is
> the most scary IMO, and the API the device exposes.


IP cameras *are* reflashable via a web app, they run a minimal linux.
The update is in two steps, download a file to the cam and then flash
it.