Re: IPP Firmware Update Extensions v1.0 - recommendations for "Security and Privacy" and "Implementation Considerations" sections

Ira McDonald via ipp <[email protected]> Sun, 24 May 2026 15:12:07 -0400
Newsgroups gmane.ietf.ipp
Message-ID <CAN40gSsVwgNJPmAYwb3PE+LEm55kHWD5CspVjAJJ-Kb3J=bwCQ@mail.gmail.com>
--===============1490639214746796610==
Content-Type: multipart/alternative; boundary="0000000000007bac4a0652950a05"

--0000000000007bac4a0652950a05
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Smith,

I'd also suggest adding as Informative references to Security
Considerations:

NIST SP800-193 Platform Firmware Resiliency Guidelines (May 2018)
https://csrc.nist.gov/pubs/sp/800/193/final

ITU-T X.1373 Secure Software Update Capability for ITS (March 2024)
https://www.itu.int/ITU-T/recommendations/rec.aspx?rec=3D15664

ISO 24089:2023 Road vehicles =E2=80=94 Software Update Engineering (Februar=
y 2023)
https://www.iso.org/standard/77796.html


All three are worth a look for security requirements
- first two are FREE
- third is behind a paywall (135 Swiss Francs), but it's a concise spec (I
was co-editor)

Cheers,
- Ira


*Ira McDonald (Musician / Software Architect)*
*Co-Chair - TCG Mobile Platform WG*

*Co-Chair - TCG Metadata Access Protocol SG*








*Chair - Linux Foundation Open Printing WGSecretary - ISTO Printer Working
GroupCo-Chair - ISTO PWG Internet Printing Protocol WGIETF Designated
Expert - IPP & Printer MIBBlue Roof Music / High North
Inchttp://sites.google.com/site/blueroofmusic
<http://sites.google.com/site/blueroofmusic>http://sites.google.com/site/hi=
ghnorthinc
<http://sites.google.com/site/highnorthinc>mailto: [email protected]
<[email protected]>(permanent) PO Box 221  Grand Marais, MI 49839
906-494-2434*


On Fri, May 22, 2026 at 12:53=E2=80=AFPM Michael Sweet via ipp <[email protected]=
> wrote:

> Smith,
>
> Some thoughts on security/privacy:
>
> 1. Firmware should be cryptographically signed
> 2. Firmware downloads should be protected in transit (i.e. HTTPS/TLS)
> 3. Any identifiers used to authorize access to and/or track downloads and
> installations of new firmware should be limited to the Printer and not th=
e
> Printer's owner, organization, etc. IOW, "this is a valid Example Corp
> Laser Printer 2000 with SN 12345 that is entitled to receive firmware v2.=
0"
> - this allows the vendor to broadly know what version(s) of firmware are =
in
> use, whether there have been issues installing new firmware, etc. but not
> to know that Alice hasn't updated the firmware in her Printer for the las=
t
> 18 months.
> 4. Firmware Repositories can potentially combine Printer identity
> information with IP addresses, routing info, etc. to determine the identi=
ty
> of owners (privacy consideration for using OTA updates...)
>
> I know we don't want to dig too deep with this, and I certainly don't wan=
t
> to provide a roadmap for abusing OTA updates, but it seems appropriate to
> outline some of the risks and highlight best practices...
>
>
> > On May 21, 2026, at 4:32=E2=80=AFPM, Kennedy, Smith (Wireless & IPP Sta=
ndards)
> via ipp <[email protected]> wrote:
> >
> > Hi there,
> >
> > For IPP Firmware Update Extensions v1.0, does anybody have any
> recommendations for items to list in the "Security and Privacy" and
> "Implementation Considerations" sections? I'd like to get that before I
> produce my next draft, which will be ready for our IPP WG meeting June 18=
.
> >
> > Cheers,
> >
> > Smith
> >
> > /**
> >     Smith Kennedy
> >     HP Inc.
> > */
> >
> > _______________________________________________
> > ipp mailing list
> > [email protected]
> > https://www.pwg.org/mailman/listinfo/ipp
>
> ________________________
> Michael Sweet
>
> _______________________________________________
> ipp mailing list
> [email protected]
> https://www.pwg.org/mailman/listinfo/ipp
>

--0000000000007bac4a0652950a05
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi Smith,</div><div><br></div><div>I&#39;d also sugge=
st adding as Informative references to Security Considerations:</div><div><=
br></div><div>NIST SP800-193=C2=A0Platform Firmware Resiliency Guidelines (=
May 2018)</div><div><a href=3D"https://csrc.nist.gov/pubs/sp/800/193/final"=
>https://csrc.nist.gov/pubs/sp/800/193/final</a></div><div><br></div><div>
<div>ITU-T X.1373=C2=A0Secure Software Update Capability for ITS (March 202=
4)</div><div><a href=3D"https://www.itu.int/ITU-T/recommendations/rec.aspx?=
rec=3D15664">https://www.itu.int/ITU-T/recommendations/rec.aspx?rec=3D15664=
</a></div><br></div><div>ISO 24089:2023 Road vehicles =E2=80=94 Software Up=
date Engineering (February 2023)</div><div><a href=3D"https://www.iso.org/s=
tandard/77796.html">https://www.iso.org/standard/77796.html</a></div><div><=
br></div><div><br></div><div>All three are worth a look for security requir=
ements=C2=A0</div><div>- first two are FREE=C2=A0</div><div>- third is behi=
nd a paywall (135 Swiss Francs),=C2=A0but it&#39;s a concise spec (I was co=
-editor)</div><div></div><div><br></div><div>Cheers,</div><div>- Ira</div><=
div><br></div><div><br></div><div><div dir=3D"ltr" class=3D"gmail_signature=
" data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div><div dir=3D"ltr"=
><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><di=
v dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"=
ltr"><i><font size=3D"1">Ira McDonald (Musician / Software Architect)</font=
></i></div><div><i><font size=3D"1"></font></i></div><div dir=3D"ltr"><i><f=
ont size=3D"1">Co-Chair - TCG Mobile Platform WG</font></i></div><div><i><f=
ont size=3D"1">Co-Chair - TCG Metadata Access Protocol SG<br></font></i></d=
iv><div dir=3D"ltr"><i><font size=3D"1">Chair - Linux Foundation Open Print=
ing WG<br>Secretary - ISTO Printer Working Group<br>Co-Chair - ISTO PWG Int=
ernet Printing Protocol WG<br>IETF Designated Expert - IPP &amp; Printer MI=
B<br>Blue Roof Music / High North Inc<br><a style=3D"color:rgb(51,51,255)" =
href=3D"http://sites.google.com/site/blueroofmusic" target=3D"_blank">http:=
//sites.google.com/site/blueroofmusic</a><br><a style=3D"color:rgb(102,0,20=
4)" href=3D"http://sites.google.com/site/highnorthinc" target=3D"_blank">ht=
tp://sites.google.com/site/highnorthinc</a><br>mailto: <a href=3D"mailto:bl=
[email protected]" target=3D"_blank">[email protected]</a><br>(pe=
rmanent) PO Box 221=C2=A0 Grand Marais, MI 49839=C2=A0 906-494-2434</font><=
/i></div></div></div></div></div></div></div></div></div></div></div></div>=
</div></div></div></div></div></div></div><br></div><br><div class=3D"gmail=
_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Fri,=
 May 22, 2026 at 12:53=E2=80=AFPM Michael Sweet via ipp &lt;<a href=3D"mail=
to:[email protected]">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gm=
ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,=
204,204);padding-left:1ex">Smith,<br>
<br>
Some thoughts on security/privacy:<br>
<br>
1. Firmware should be cryptographically signed<br>
2. Firmware downloads should be protected in transit (i.e. HTTPS/TLS)<br>
3. Any identifiers used to authorize access to and/or track downloads and i=
nstallations of new firmware should be limited to the Printer and not the P=
rinter&#39;s owner, organization, etc. IOW, &quot;this is a valid Example C=
orp Laser Printer 2000 with SN 12345 that is entitled to receive firmware v=
2.0&quot; - this allows the vendor to broadly know what version(s) of firmw=
are are in use, whether there have been issues installing new firmware, etc=
. but not to know that Alice hasn&#39;t updated the firmware in her Printer=
 for the last 18 months.<br>
4. Firmware Repositories can potentially combine Printer identity informati=
on with IP addresses, routing info, etc. to determine the identity of owner=
s (privacy consideration for using OTA updates...)<br>
<br>
I know we don&#39;t want to dig too deep with this, and I certainly don&#39=
;t want to provide a roadmap for abusing OTA updates, but it seems appropri=
ate to outline some of the risks and highlight best practices...<br>
<br>
<br>
&gt; On May 21, 2026, at 4:32=E2=80=AFPM, Kennedy, Smith (Wireless &amp; IP=
P Standards) via ipp &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">i=
[email protected]</a>&gt; wrote:<br>
&gt; <br>
&gt; Hi there, <br>
&gt; <br>
&gt; For IPP Firmware Update Extensions v1.0, does anybody have any recomme=
ndations for items to list in the &quot;Security and Privacy&quot; and &quo=
t;Implementation Considerations&quot; sections? I&#39;d like to get that be=
fore I produce my next draft, which will be ready for our IPP WG meeting Ju=
ne 18.<br>
&gt; <br>
&gt; Cheers, <br>
&gt; <br>
&gt; Smith<br>
&gt; <br>
&gt; /**<br>
&gt;=C2=A0 =C2=A0 =C2=A0Smith Kennedy<br>
&gt;=C2=A0 =C2=A0 =C2=A0HP Inc.<br>
&gt; */ <br>
&gt; <br>
&gt; _______________________________________________<br>
&gt; ipp mailing list<br>
&gt; <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br>
&gt; <a href=3D"https://www.pwg.org/mailman/listinfo/ipp" rel=3D"noreferrer=
" target=3D"_blank">https://www.pwg.org/mailman/listinfo/ipp</a><br>
<br>
________________________<br>
Michael Sweet<br>
<br>
_______________________________________________<br>
ipp mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br>
<a href=3D"https://www.pwg.org/mailman/listinfo/ipp" rel=3D"noreferrer" tar=
get=3D"_blank">https://www.pwg.org/mailman/listinfo/ipp</a><br>
</blockquote></div>

--0000000000007bac4a0652950a05--

--===============1490639214746796610==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
ipp mailing list
[email protected]
https://www.pwg.org/mailman/listinfo/ipp

--===============1490639214746796610==--