3 ms·
Ask HN: Bare metal or embedded OS for IoT security
Good day all,
I'm in the process of scoping out an embedded project, that will at some point be connected to the internet (and then likely in some numbers).
The current complexity of the project makes a microcontroller based system with a realtime OS (FreeRTOS, etc) and an TCP/IP stack (uip, lwip, etc) feasible.
However, there are 2 reasons I might consider a realtime Linux & embedded computer based solution:
* Future increase in complexity beyond what a traditional embedded system can scale to, and
* Quicker development turnaround time (proven stack, APIs, tools, etc)
The big question for me is around IoT security. While not a fan of security through obscurity, a bare metal approach (first one above) means I control exactly what the system can and can't do, and also restricts potential vulnerabilities to something not used as widely (embedded OS, embedded IP stack). There is also no possibility of rooting the device, or running commands or scripts that I don't specifically support. For a Linux based system, my understanding is that the overall complexity of the OS and support tools, and the widely used nature of the stack (bigger attack surface) opens it up to any potential vulnerabilities discovered now and in the future. My biggest concern is inadvertently becoming part of an IoT botnet, knowing that I may not have the resources to fully support and secure any such breaches (or necessarily be able to convince customers to upgrade/update/patch and out of the way system).
Does HN embedded professionals have any input/advice/recommendations/corrections on this topic?