5 ms·
An attacker could just as easily block the SSL connections - unless you're suggesting it fail if it can't check for a firmware update, but that proposal would m
by problems 9y ago
An attacker could just as easily block the SSL connections - unless you're suggesting it fail if it can't check for a firmware update, but that proposal would mean that if your servers are gone the devices are bricked. Many of such devices function fine in a Lan only setting behind a nat where they're virtually untouchable.
Disallowing downgrades via a signed datestamp is about the best you can do. Anything else will either be trivially blocked or result in other user problems.
- viraptor 9y agoThe are less drastic options. You can start warning loudly if the servers haven't responded for weeks.
- lexicality 9y agoVia what? Flashing the apartment lights?
- viraptor 9y agoReporting to the app controlling them.