3 ms·
Once again embedded device security is a joke. Firmware updates are provided for 2 years or less on devices that end up lingering, acting as the core of network
by StudentStuff 7y ago
Once again embedded device security is a joke. Firmware updates are provided for 2 years or less on devices that end up lingering, acting as the core of networks for 5 to 15 years.
Repeat offenders should be held accountable, standards should be enforced (like running point releases of OpenWRT, providing vendor skins as a package, thus the vendor doesn't have to deal with software updates).
- ChuckNorris89 7y ago> Once again embedded device security is a joke. Have you seen the state of salaries in the firmware dev industry? That pretty much explains why firmware security is such a mess. You pay peanuts you get peanuts.
- StudentStuff 7y agoThe state of salaries in hardware/embedded roles is quite poor, along with the decision making process of most companies that create embedded hardware. Only TI ever really went all in with a fully open stack that had support mainlined, problem being by the time their chips had full support upstream they'd be lagging 1 to 2 years behind Qualcomm, Nvidia, Mediatek, Allwinner, Spreadtrum, etc while having a much higher cost per chip, most of said cost being the decently written and upstreamed drivers. For longer lived architectures (eg: AMD/Intel CPUs) totally new device drivers aren't needed on launch day, in part due to older upstreamed drivers still mostly working with newer hardware. None of the aforementioned vendors besides TI ever got into this virtuous cycle of having upstreamed drivers, thus they've trapped their devices on sketchy, unstable & insecure BSPs that hurt the reliability, performance and sometimes the market image of the final product (eg: when the device randomly crashes or gets exploited due to latent bugs).