3 ms·
I don't think this is a fair assessment. When I got to make a website, I don't say I can't make it secure because I can't afford to be an expert in security at
by pythonaut_16 9y ago
I don't think this is a fair assessment.
When I got to make a website, I don't say I can't make it secure because I can't afford to be an expert in security at every level of the OSI. I say I'm not an expert in every level of the OSI so I rely on accepted best practices and community standards to make my site secure.
I don't replace HTTPS with my own standard because I can't afford to make an adequate and secure replacement. If IoT makers can't make their own custom solutions secure then they need to build their devices out of standardized pieces that are secure.
- kbart 9y ago"they need to build their devices out of standardized pieces that are secure." That's exactly the problem with IoT-- there's no standard, out-of-box solutions right now. Try to google for "IoT security": you will find a bunch of (mostly proprietary) competing solutions with no clear leaders among them. See my other comment on this thread, were I've provided HTTPS as an example for IoT ecosystem. I'm an experienced embedded developer and most often, when it comes to security, I still have resort back to "invent my own" security solution, because I can't find anything that fits project needs.
- greggman 9y agoafaict you can't use HTTPS in any reasonable way with IoT. There are no solutions that don't cost $$$$$$$+ note: I know you were not suggesting HTTPS as a solution only as an example of a standard used other places. I'm only pointing it out as another example of an issue IoT has which is lack of solutions .
- cybergibbons 9y agoWhy do you need to spend money to use HTTPS with IoT?
- greggman 9y agohow do you get a cert for each device? let's encrypt limits the number of certs per domain (that includes sub domains). so unless you expect users to get their own domains for their IoT devices they can't get a free cert based on user unique subdomains you provide. The only solution I know of is Plex's solution which was to partner with a CA for $$$$$$ https://blog.filippo.io/how-plex-is-doing-https-for-all-its-users/ https://blog.filippo.io/how-plex-is-doing-https-for-all-its-...
- petra 9y ago>> when it comes to security, I still have resort back to "invent my own" security solution What's wrong with using the mbed security stack as a standard for mcu's ?