3 ms·
> end users must be able to patch beyond the support lifetime That's the kind of thing that gives regulation a bad name. One of the worst ways an IoT device c
by zigzigzag 10y ago
> end users must be able to patch beyond the support lifetime
That's the kind of thing that gives regulation a bad name.
One of the worst ways an IoT device can get hacked is if it's reflashed with malicious firmware that then can't be reflashed back. You've got a permanent backdoor that requires trashing the device and a lot of users won't throw away a device that still works (for them) even if they know it's infected with something that causes problems (for someone else). That's real money.
A simple way to fix that is locked bootloaders that only runs signed code. Then even if the running image gets hacked, a reboot fixes it and at least the device can't be irreversibly hacked.
A regulation like the one you propose would presumably make signature-locked firmware illegal, or at best, require the checks to be disabled after a certain date (which then requires secure clocks: more stuff to go wrong). It's the sort of thing that sounds good but can cause more problems than it solves, which is the typical problem of regulation.
- drvdevd 10y agoVery much agreed and good points all around. My proposal wasn't nearly as technically nuanced as such a proposal should be. I suppose I should fall back to my main argument which is that no such proposal can be at this point. Hence regulation will just be a source of burden on everyone involved, except those with deep enough pockets to use those regulations to turn a profit.