3 ms·
8 and 9 specify manufacturers -- people selling something that connects to the internet. If you're selling, you should have to certify that you've done due dili
by Sanddancer 10y ago
8 and 9 specify manufacturers -- people selling something that connects to the internet. If you're selling, you should have to certify that you've done due diligence. If this is done through NIST standards being created, one of the side effects of this would mean that everyone would get actual guidelines, and almost certainly tools, which could do checking if a device is configured at least semi-properly. If anything, it would mean that vendors would have more impetus to communicate and send patches, because they would have to actually own their problems.
- protomyth 10y ago8 and 9 deal with manufactures, but could be used to stop non-manufacture open source. Its been a long time since Bell and I worry security will be used as an excuse to remove some competition.
- johncolanduoni 10y agoYes, but even if your standard only states that manufacturers have to provide some sort of resilience to attackers modifying the binaries on the device remotely, I suspect many manufacturers are going to go with the simplest way: preventing any modifications save manufacturer-signed updates, and/or reducing user configurability of the device. My feeling on this are somewhat mixed; on one hand virtually everyone who owns a modifiable device never makes any significant modifications and doesn't know how to properly secure it to boot. On the other hand, that means that even if manufacturers had no selfish reasons to put in such limitations of their own volition, the natural state for most consumer device markets is going to be to have no modifiable devices available for purchase just because making an unlocked version isn't worth it.