Re: IPP Firmware Update Extensions v1.0 - recommendations for "Security and Privacy" and "Implementation Considerations" sections
Ira McDonald via ipp <[email protected]> Sun, 24 May 2026 15:12:07 -0400
| Newsgroups | gmane.ietf.ipp |
|---|---|
| Message-ID | <CAN40gSsVwgNJPmAYwb3PE+LEm55kHWD5CspVjAJJ-Kb3J=bwCQ@mail.gmail.com> |
--===============1490639214746796610== Content-Type: multipart/alternative; boundary="0000000000007bac4a0652950a05" --0000000000007bac4a0652950a05 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Smith, I'd also suggest adding as Informative references to Security Considerations: NIST SP800-193 Platform Firmware Resiliency Guidelines (May 2018) https://csrc.nist.gov/pubs/sp/800/193/final ITU-T X.1373 Secure Software Update Capability for ITS (March 2024) https://www.itu.int/ITU-T/recommendations/rec.aspx?rec=3D15664 ISO 24089:2023 Road vehicles =E2=80=94 Software Update Engineering (Februar= y 2023) https://www.iso.org/standard/77796.html All three are worth a look for security requirements - first two are FREE - third is behind a paywall (135 Swiss Francs), but it's a concise spec (I was co-editor) Cheers, - Ira *Ira McDonald (Musician / Software Architect)* *Co-Chair - TCG Mobile Platform WG* *Co-Chair - TCG Metadata Access Protocol SG* *Chair - Linux Foundation Open Printing WGSecretary - ISTO Printer Working GroupCo-Chair - ISTO PWG Internet Printing Protocol WGIETF Designated Expert - IPP & Printer MIBBlue Roof Music / High North Inchttp://sites.google.com/site/blueroofmusic <http://sites.google.com/site/blueroofmusic>http://sites.google.com/site/hi= ghnorthinc <http://sites.google.com/site/highnorthinc>mailto: [email protected] <[email protected]>(permanent) PO Box 221 Grand Marais, MI 49839 906-494-2434* On Fri, May 22, 2026 at 12:53=E2=80=AFPM Michael Sweet via ipp <[email protected]= > wrote: > Smith, > > Some thoughts on security/privacy: > > 1. Firmware should be cryptographically signed > 2. Firmware downloads should be protected in transit (i.e. HTTPS/TLS) > 3. Any identifiers used to authorize access to and/or track downloads and > installations of new firmware should be limited to the Printer and not th= e > Printer's owner, organization, etc. IOW, "this is a valid Example Corp > Laser Printer 2000 with SN 12345 that is entitled to receive firmware v2.= 0" > - this allows the vendor to broadly know what version(s) of firmware are = in > use, whether there have been issues installing new firmware, etc. but not > to know that Alice hasn't updated the firmware in her Printer for the las= t > 18 months. > 4. Firmware Repositories can potentially combine Printer identity > information with IP addresses, routing info, etc. to determine the identi= ty > of owners (privacy consideration for using OTA updates...) > > I know we don't want to dig too deep with this, and I certainly don't wan= t > to provide a roadmap for abusing OTA updates, but it seems appropriate to > outline some of the risks and highlight best practices... > > > > On May 21, 2026, at 4:32=E2=80=AFPM, Kennedy, Smith (Wireless & IPP Sta= ndards) > via ipp <[email protected]> wrote: > > > > Hi there, > > > > For IPP Firmware Update Extensions v1.0, does anybody have any > recommendations for items to list in the "Security and Privacy" and > "Implementation Considerations" sections? I'd like to get that before I > produce my next draft, which will be ready for our IPP WG meeting June 18= . > > > > Cheers, > > > > Smith > > > > /** > > Smith Kennedy > > HP Inc. > > */ > > > > _______________________________________________ > > ipp mailing list > > [email protected] > > https://www.pwg.org/mailman/listinfo/ipp > > ________________________ > Michael Sweet > > _______________________________________________ > ipp mailing list > [email protected] > https://www.pwg.org/mailman/listinfo/ipp > --0000000000007bac4a0652950a05 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hi Smith,</div><div><br></div><div>I'd also sugge= st adding as Informative references to Security Considerations:</div><div><= br></div><div>NIST SP800-193=C2=A0Platform Firmware Resiliency Guidelines (= May 2018)</div><div><a href=3D"https://csrc.nist.gov/pubs/sp/800/193/final"= >https://csrc.nist.gov/pubs/sp/800/193/final</a></div><div><br></div><div> <div>ITU-T X.1373=C2=A0Secure Software Update Capability for ITS (March 202= 4)</div><div><a href=3D"https://www.itu.int/ITU-T/recommendations/rec.aspx?= rec=3D15664">https://www.itu.int/ITU-T/recommendations/rec.aspx?rec=3D15664= </a></div><br></div><div>ISO 24089:2023 Road vehicles =E2=80=94 Software Up= date Engineering (February 2023)</div><div><a href=3D"https://www.iso.org/s= tandard/77796.html">https://www.iso.org/standard/77796.html</a></div><div><= br></div><div><br></div><div>All three are worth a look for security requir= ements=C2=A0</div><div>- first two are FREE=C2=A0</div><div>- third is behi= nd a paywall (135 Swiss Francs),=C2=A0but it's a concise spec (I was co= -editor)</div><div></div><div><br></div><div>Cheers,</div><div>- Ira</div><= div><br></div><div><br></div><div><div dir=3D"ltr" class=3D"gmail_signature= " data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div><div dir=3D"ltr"= ><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><di= v dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"= ltr"><i><font size=3D"1">Ira McDonald (Musician / Software Architect)</font= ></i></div><div><i><font size=3D"1"></font></i></div><div dir=3D"ltr"><i><f= ont size=3D"1">Co-Chair - TCG Mobile Platform WG</font></i></div><div><i><f= ont size=3D"1">Co-Chair - TCG Metadata Access Protocol SG<br></font></i></d= iv><div dir=3D"ltr"><i><font size=3D"1">Chair - Linux Foundation Open Print= ing WG<br>Secretary - ISTO Printer Working Group<br>Co-Chair - ISTO PWG Int= ernet Printing Protocol WG<br>IETF Designated Expert - IPP & Printer MI= B<br>Blue Roof Music / High North Inc<br><a style=3D"color:rgb(51,51,255)" = href=3D"http://sites.google.com/site/blueroofmusic" target=3D"_blank">http:= //sites.google.com/site/blueroofmusic</a><br><a style=3D"color:rgb(102,0,20= 4)" href=3D"http://sites.google.com/site/highnorthinc" target=3D"_blank">ht= tp://sites.google.com/site/highnorthinc</a><br>mailto: <a href=3D"mailto:bl= [email protected]" target=3D"_blank">[email protected]</a><br>(pe= rmanent) PO Box 221=C2=A0 Grand Marais, MI 49839=C2=A0 906-494-2434</font><= /i></div></div></div></div></div></div></div></div></div></div></div></div>= </div></div></div></div></div></div></div><br></div><br><div class=3D"gmail= _quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Fri,= May 22, 2026 at 12:53=E2=80=AFPM Michael Sweet via ipp <<a href=3D"mail= to:[email protected]">[email protected]</a>> wrote:<br></div><blockquote class=3D"gm= ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,= 204,204);padding-left:1ex">Smith,<br> <br> Some thoughts on security/privacy:<br> <br> 1. Firmware should be cryptographically signed<br> 2. Firmware downloads should be protected in transit (i.e. HTTPS/TLS)<br> 3. Any identifiers used to authorize access to and/or track downloads and i= nstallations of new firmware should be limited to the Printer and not the P= rinter's owner, organization, etc. IOW, "this is a valid Example C= orp Laser Printer 2000 with SN 12345 that is entitled to receive firmware v= 2.0" - this allows the vendor to broadly know what version(s) of firmw= are are in use, whether there have been issues installing new firmware, etc= . but not to know that Alice hasn't updated the firmware in her Printer= for the last 18 months.<br> 4. Firmware Repositories can potentially combine Printer identity informati= on with IP addresses, routing info, etc. to determine the identity of owner= s (privacy consideration for using OTA updates...)<br> <br> I know we don't want to dig too deep with this, and I certainly don'= ;t want to provide a roadmap for abusing OTA updates, but it seems appropri= ate to outline some of the risks and highlight best practices...<br> <br> <br> > On May 21, 2026, at 4:32=E2=80=AFPM, Kennedy, Smith (Wireless & IP= P Standards) via ipp <<a href=3D"mailto:[email protected]" target=3D"_blank">i= [email protected]</a>> wrote:<br> > <br> > Hi there, <br> > <br> > For IPP Firmware Update Extensions v1.0, does anybody have any recomme= ndations for items to list in the "Security and Privacy" and &quo= t;Implementation Considerations" sections? I'd like to get that be= fore I produce my next draft, which will be ready for our IPP WG meeting Ju= ne 18.<br> > <br> > Cheers, <br> > <br> > Smith<br> > <br> > /**<br> >=C2=A0 =C2=A0 =C2=A0Smith Kennedy<br> >=C2=A0 =C2=A0 =C2=A0HP Inc.<br> > */ <br> > <br> > _______________________________________________<br> > ipp mailing list<br> > <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br> > <a href=3D"https://www.pwg.org/mailman/listinfo/ipp" rel=3D"noreferrer= " target=3D"_blank">https://www.pwg.org/mailman/listinfo/ipp</a><br> <br> ________________________<br> Michael Sweet<br> <br> _______________________________________________<br> ipp mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br> <a href=3D"https://www.pwg.org/mailman/listinfo/ipp" rel=3D"noreferrer" tar= get=3D"_blank">https://www.pwg.org/mailman/listinfo/ipp</a><br> </blockquote></div> --0000000000007bac4a0652950a05-- --===============1490639214746796610== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ ipp mailing list [email protected] https://www.pwg.org/mailman/listinfo/ipp --===============1490639214746796610==--