3 ms·
> Yeah, and having an automatic, secure, reliable patching routine for embedded devices is not trivial (and thus really expensive). Roku (and others) seems to
by bcook 10y ago
> Yeah, and having an automatic, secure, reliable patching routine for embedded devices is not trivial (and thus really expensive).
Roku (and others) seems to have figured that out. They cryptographically sign each update.
- jessaustin 10y agoRoku legitimately needs to initiate connections outside the home. Can the same be said for e.g. a light bulb? If switches don't drop these packets, then routers should, and if they don't, then ISPs should. Is there a field in DHCP that could be used to communicate the fact that a particular host should generate no outside traffic?
- tehmaco 10y agoMy first thought would be to set the default gateway to 127.0.0.1. It should mean that they can't route packets to anything outside their LAN?
- jessaustin 10y agoI meant that the light bulb could tell the router "I'm IoT so assume I'm pretty dumb", to which information the router could respond in any number of ways. I don't think your setting would have the effect we want, however. The light bulbs have to talk to whatever is supposed to control them, so they have to be able to see the LAN.
- tehmaco 10y agoThe gateway is needed to route outside of the local subnet, so if the bulb is 192.168.1.17, it can talk to anything in 192.168.1.0/24 (presuming a standard home user setup), but anything else would get 'no route to host' errors on initial connection attempts. You'd need to configure the DHCP to hand out these kinds of leases by MAC address though, as I can't see vendors agreeing on a way to easily restrict the devices net access! :-/
- lowgman 10y agoPerhaps your average router needs a button to 'add device', only allowing new devices access via something like the WPS button with a term second window for new DHCP request incoming? Otherwise the DHCP ignores any incoming request, just sleeps. Adds one step in the quickstart guide.
- jlgaddis 10y agoDon't assign the device a default gateway (or set it to 0.0.0.0 if one is "required"). I have thought for a long time that we'll one day get to the point where the best thing one can do for a host's security is to not allow it to generate traffic that can reach the Internet. Just like we have default deny on incoming traffic, we need to start using a default deny on outgoing traffic as well.