3 ms·
If there's a ROM with non-editable software it will just get instantly compromised as soon as it comes back up. For your standard "internet of things" device th
by psybin 10y ago
If there's a ROM with non-editable software it will just get instantly compromised as soon as it comes back up. For your standard "internet of things" device there is no room, physically or in the bill of materials, for things like connectors for people to physically deliver updates.
- WalterBright 10y agoThis is not a difficult problem to solve. The ROM cannot be overwritten - hence it can be designed so that malware cannot run. Also, jumpers are cheap. Just set the jumper to enable writes, and download the update. Are you happy with it being unknowable which of your appliances are compromised or not? Would you pay $1 more for a disk drive with firmware in ROM? I would. If you were running a banking system, would you pay extra for code in ROM that cannot be compromised?
- TeMPOraL 10y agoYou would. But you're not the market - 99.99% of other people, who don't even know what a "jumper" is, are the market. So your preferences don't matter. Yes, even in most technology products. As for IoT devices, I can't imagine average Joe or Jane prying off their smart whatever, destroying the pretty plastic casing it's hidden in, and manually setting jumpers to flash firmware.
- WalterBright 10y agoIsn't it ironic that the means of updating firmware to prevent installation of malware is the vector for installing malware? I don't think the current scheme is working very well. Even worse, there is no way to tell if your appliance has been compromised or not. There are a lot of companies that care whether their machines are infected or not.