12 ms·
This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufactur
by jjguy 7y ago
This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models.
This applies to every "connected device:" printers, cell phones, home routers, refrigerators, thermostats -- you name it. Michael DeGusta did a great infographic demonstrating this for Android phones in 2011 [1, 2]. Sadly, this hasn't materially changed in the eight years since. Just this year, Google added new terms to the Android license requiring security patches, but even then only for "popular devices." [3] Imagine those dynamics in the secondary and tertiary markets of printers and refrigerators.
As an industry, we've been to this rodeo before. The advancements we've made in operating system and core applications security over the last 20 years have more about patching speed and agility than shipping fewer bugs. However, those areas have backing and control from Apple and Microsoft, managing the end to end ecosystem. There is not a similarly equipped manufacturer of embedded operating systems with the scale to provide post-sale/post-deployment patching infrastructure.
Since this is Hacker News, I'll point out the enormous opportunity to anyone who can address that problem. Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Do you have a better approach to it? There's a burgeoning multi-billion dollar market waiting for a few leaders to take it over.
1 - https://theunderstatement.com/post/11982112928/android-orphans-visualizing-a-sad-history-of https://theunderstatement.com/post/11982112928/android-orpha...
2 -
img link is broken in his post, the graphic itself: http://media.theunderstatement.com/016a_android_orphans.png http://media.theunderstatement.com/016a_android_orphans.png
3 - https://www.theverge.com/2018/10/24/18019356/android-security-update-mandate-google-contract https://www.theverge.com/2018/10/24/18019356/android-securit...
- schainks 7y agoThe Nerves Project is positioning itself to address this well.
- patcheudor 7y agoFor D-Link this is the normal, normal and has been for years. Check out VU#924307 which they never fixed. It could be triggered either by an attacker or just in the normal course of using the router: https://www.kb.cert.org/vuls/id/924307/ https://www.kb.cert.org/vuls/id/924307/
- ghaff 7y agoI daresay people aren't going to like this answer but, you ultimately have to align the interests of the manufacturers and the consumers. Which probably means some sort of subscription model and even a requirement that the subscription be current to function. I know. Yuck. But the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions.
- chooseaname 7y agoOr increase the initial price enough to cover the N years it is expected to be in service. If you make a 5 year router, charge for that. If you make a 10 year router, charge for that. But don't charge for a 5 year router and drop it after 2.
- AnthonyMouse 7y ago> But the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions. What would be better is to require that the firmware be replaceable with something like DD-WRT or OpenWRT. One of the biggest issues with hardware like this is that the original manufacturer goes out of business and yet millions of people still have their devices. You can't require updates from a company that no longer exists, but that's not really a problem if their hardware can run the latest versions of half a dozen different open source router firmwares.
- eropple 7y ago> the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions I am unclear why this is not the preferential solution here. "Don't sell lemons" is a societal good.
- OJFord 7y agoIt drives prices up in equivalence with subscription pricing over the typical lifespan. (i.e. not obviously better or worse)
- jumpingmice 7y agoI'm not really sure there is enough evidence behind your assertion. Google wifi APs have got continuous updates from Sep. 2015 to current day. Sonos players have been continuously supported for 15 years. Apple's just-released OS runs on 7-year-old hardware. There are and have always been fly-by-night organizations that sell junk with bad software and no updates. That's not new, nor is the existence of reputable vendors with long support policies.
- AceJohnny2 7y agoAll the brands you've cited are "luxury" brands whose proposition includes long-term support. It's a different market segment that doesn't refute GP's point.
- nyolfen 7y agoi have a $30 netgear router from walmart that has gotten security updates for at least three years
- mikehollinger 7y agoI’m not going to be hacked because of my Apple TV or my google Wifi router; it’s going to be my light switch that does me in.
- greggman2 7y agoYour Apple TV runs 3rd party apps, any of which could be hacking you.
- riffic 7y ago>anyone who can address that problem If no one addresses this problem, regulations will be imposed.
- nomel 7y agoDo you think it’s possible to regulate all of the internet connected consumer devices coming from China? Routers, WiFi lightbulbs, toasters, etc?
- otterley 7y agoOf course it is. Nations regulate lots of imported goods, from foodstuffs to cars. Nations also have the power to impound cargo deliveries if the importer is notorious for not validating that their cargo is compliant with local regulations.
- TaylorAlexander 7y agoI think consciousness raising is important to. Many have made efforts to explain these downsides, but it is a never ending challenge to keep the public aware of why closed source technology harms them compared to potential open options. Consumer opinion is one of the tools we can use to change this situation, and an important one IMO.
- wil421 7y ago> This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. Ubiquiti has a number of CVEs and has addressed them in a timely manner, IMHO. If you’re buying the cheapest product then expect the cheapest support. My UniFi stuff is easy to manage and upgrade. I can set a number of auto updates I can’t do with other vendors.
- onaraft 7y agoUbiquiti isn't really consumer, though. They want to target enterprises and businesses. Sure, their hardware ends up in residential deployments more often than perhaps any other kind of enterprise computer stuff, but if you're not willing to call them "enterprise", I'm going to insist they be practically alone in their own category of "pro-sumer but actually professional-consumer, and not the yuppie garbage that you usually call pro-sumer that's just the normal consumer crap but priced at 4x with a slick black plastic case." I agree with GP in that the spectrum you are suggesting ("you get what you pay for" actually looks more like this: <cheap garbage> ----------- <expensive garbage> ----[huge $$$ gap]----- <enterprise stuff for price-insensitive corporations who value brand and risk-aversion more than actual specs> Which I would reify into the realm of, for example, computer hardware, as follows: <a $100 best buy laptop with Windows> --------- <a $4000 alienware desktop with windows> --------------- <a $40000 Dell server with out-of-band management and ECC ram and HSM's and dual power supplies and actual RAID controllers and so on> The best buy laptop and the alienware desktop are going to have the same issues with regards to control and privacy, and you need to make a huge jump to get to anything remotely respecting you.
- wmf 7y agoUbiquiti is targeting small business (not enterprise) but their prices are firmly within consumer range. (For actual enterprise look at Meraki prices.) Likewise Apple Airport (RIP), Google Wifi, Eero, etc. have long-term support for a modest premium. There's no huge gap.
- 7y ago
- dangus 7y agoUntil consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send traffic to your router's login page from the Internet. So they'd have to physically drive around looking for these three specific D-Link routers. And then what would they get out of a successful exploit? Access to your network's traffic and unprotected file shares (most people don't even have any file shares), and even that level of access will be rather useless for getting important information like bank credentials (protected by HTTPS). Am I wrong about any of this? A lot of non-technical people use old Android phones, old printers, etc, and never experience any serious security breach. Some of them do experience a security breach, but it's far more likely to happen in a social exploit (phishing, whaling, etc) or institutional breach (your reused password being breached from a database hack of a popular website). In a lot of ways, ignorance is bliss.
- dredmorbius 7y agoUntil consumers are willing to spend on subscription services... You cannot shift a Gresham's Law race-to-the-bottom dynamic by insisting on consumer (or producer) willpower. You've got to enforce a floor. In other consumer (and industrial) products, this has tended to happen through the combined mechanisms of strict liability, certification, and independent inspection (in specific cases). Where manufacturers, or as seems more likely given the industry concentration around sales points, retailers, are liable for the consequences of unfit-for-purpose devices and services, a reasonable set of minimum requirements (including life-of-product and update requirements) can be specified, then you might see a shift to some mix of time-of-sale plus subscription service pricing and payment models. More likely you'll see devices bundled with services (which sometimes happens), though preferably in a far more user-friendly basis than is presently the case (e.g., cable service set-top boxes). There's actually a long history of leased-equipment business in the IT sector, most notably as pioneered by IBM in the 1950s and 1960s.
- 7y ago
- bogomipz 7y ago>"Today's manufacturers cannot afford to update software for hardware devices they have already moved on from." What is this statement based on? None of your links show any kind of unit economics that support the assertion that providing critical security patches for a defined support window is infeasible for manufactures and their business models.
- tonyarkles 7y agoI agree wholeheartedly, and outright reject the premise of the original statement. This is a choice that they make. Yes, having a legacy support team is going to cost a bit of money, but not a ridiculous amount. Maybe instead of having a ridiculous number of barely-differentiated SKUs, they could lighten the support burden a bit by making a smaller number of solid well-supported models. Edit: also, basing the models on a common platform would help too. I assume they generally do this already, but if not...
- wmf 7y agobasing the models on a common platform would help too. I assume they generally do this already, but if not... They don't, because they save a few dollars by re-bidding each product. So each company is shipping a random assortment of Broadcom, Marvell, and Qualcomm reference designs, all running incompatible software stacks.
- tonyarkles 7y ago> random assortment of Broadcom, Marvell, and Qualcomm reference designs, all running incompatible software stacks How... what... c'mon! You're totally right [1], and even within similar model numbers (e.g. the DIR-300 B-series uses Ralink chips, but the DIR-330 uses Broadcom). Yeesh. Well... I guess I'll just keep on picking devices supported by OpenWRT and not rely on vendor firmware at all. Yuck. [1] https://openwrt.org/toh/start?dataflt%5BBrand*~%5D=d-link https://openwrt.org/toh/start?dataflt%5BBrand*~%5D=d-link
- sounds 7y agoandroidauthority.com has been pretty good about tracking this more recently: Android Oreo: https://www.androidauthority.com/android-oreo-fastest-manufacturers-update-874788/ https://www.androidauthority.com/android-oreo-fastest-manufa... Android Pie: https://www.androidauthority.com/android-pie-fastest-manufacturers-update-963368/ https://www.androidauthority.com/android-pie-fastest-manufac... Then they put out this weird update: https://www.androidauthority.com/counterpoint-android-updates-1024063/ https://www.androidauthority.com/counterpoint-android-update...
- AceJohnny2 7y ago> Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Partly to your point, Buffalo was using DD-WRT for their wireless routers [1]. I have two of them at home, updated to the latest LEDE/OpenWRT. They're mostly fine [2]. Buffalo's support was not great, lagging far behind the latest DD-WRT when they were still providing those updates. As a power-user, I didn't mind since I could switch, but it was not a great showing for vanilla consumer. Sadly, Buffalo has stopped making them, I suppose the business model didn't survive such a low-margin segment. I definitely appreciate the continued open-source support though! [1] such as https://www.buffalotech.com/products/airstation-highpower-n300-open-source-dd-wrt-wireless-router https://www.buffalotech.com/products/airstation-highpower-n3... [2] I've had to reboot the main one to regain network connectivity a couple times, and it currently loses Wifi settings on power loss. Not great, but not enough to make me switch away yet.
- m463 7y agoI think there are other brands that allow openwrt, such as the linksys wrt ac series: https://openwrt.org/toh/linksys/wrt_ac_series https://openwrt.org/toh/linksys/wrt_ac_series Their support for the first models in the beginning was a little spotty, but I think they are great systems now
- heavenlyblue 7y agoThis all is simply fixed by open-sourcing the outdated software.
- jdnenej 7y agoOpen source the in date software as well. All home router software is absolutely horrendous
- rlpb 7y ago> Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Ubuntu is already doing this: https://ubuntu.com/internet-of-things https://ubuntu.com/internet-of-things For Linux distributions, security updates and maintenance are a solved problem. Ubuntu adds to this a read-only filesystem with atomic updates for embedded devices, vendor-only apps and app stores, and so forth. Disclosure: I work for Canonical, but not in this particular area. Speaking for myself, I find it frustrating that Ubuntu's solutions aren't more widely known and recognised. As far as I know, our community is very aware of the issues involved in this space and there is no other solution that solves the "IoT maintenance" problem properly.
- LilBytes 7y agoI've been looking forward to seeing Canonical's adoption in IoT getting better and better. Here's to hoping.
- megous 7y ago> This is the new normal, folks. Consumer technology is manufactured for six to twelve months. Not completely true. For example, just something I discovered recently is that some e-book readers have very long lifespan if you look inside and ignore the battery. There's not even an electrolytic or tantalum capacitors there. Really nothing that will expire. If you don't kill it mechanically, these will survive for 10 years+ just fine. Even the internal memory holding the OS and your data is easily replaceable (uSD card, and no other memory that can get corrupted). Indeed you can easily upgrade your $150 2GB e-book reader to 32GiB for $6, with a much faster uSD card. Or even replace the OS completely. ;) The only thing that makes these devices' lives limited is the battery and the cheap noname uSD card. They even make it so that display is easily replaceable, no glue or anything. What I hate is lack of commitment to free software. Manufacturer will just dump incomplete old kernel code on github once, without a source code to also GPLed bootloader, after years of nagging from users, and calls it a compliance with GPL. They don't even bother with mainline Linux support, that would make it so that anyone could use their device for whatever creative prupose and it would get automatic longterm software support for free, even after they would not want to bother anymore to support it. It's not even a cost thing, I just reverse engineered one such device and it now runs Linux 5.4-rc2 and all HW works, including an eink display driver. It took about 2 weeks of occasional work. Instead the manufacturer probably spent huge amount of time hacking together some old kernel and messy SoC vendor drivers, so that the OS at least holds together for their purposes. It's probably just some culture thing of not giving a fuck about anything but themselves. And there's a huge amout of waste as a result. At least some people sell these devices if they are just locking up/hanging (sure sign of uSD card data corruption) on eBay. But many will probably just throw it out. Such shame. So yeah, some tech is indeed solid, but manufacturer will gladly mess all the benefits up on the software side, for no real reason, at least to me.
- namibj 7y agoWhat model is that?
- megous 7y agohttp://linux-sunxi.org/PocketBook_Touch_Lux_3 http://linux-sunxi.org/PocketBook_Touch_Lux_3 But I hope people will buy second-hand or broken + replacement display instead of supporting the company and buying new, if they want to play with it. They don't really deserve any support for abusing the free work of others and violating the GPL license.
- deleted 7y ago[deleted]
- notyourday 7y ago> I'll point out the enormous opportunity to anyone who can address that problem. Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Do you have a better approach to it? There's a burgeoning multi-billion dollar market waiting for a few leaders to take it over. There's no market for this. The market is for $50 device. Android Phones, nearly flagship, that sell for $500-700 get at best two years updates. People want $50 router that they can throw away when it stops working. I have a $350 router. I have had it for 3 years by now. It is a tiny passively cooled industrial PC that fits into a VESA mount with an Intel Celeron, 128Gb SSD and 2x wifi modules. Why two? Because i want a guest network to be separate from the real network and i want crap-wifi speaking devices to be isolated via VLAN etc. It is running Debian and even techies marvel at the speed, functionality and all the goodies. They want to know where they can get it... Until they hear that it was $350 at which point they go "I was thinking i would pay about $80". A dinner for two in a Puero Rican chicken shack with a couple of beers will be $35!
- dehrmann 7y ago> but live in our homes for three to five years I have a wrt54g that's 10+ years old running at my grandma's house...and running dd-wrt because no one making APs 10 years ago, and even now, was that good at security and stability. What's telling is that the hardware is the part that still works, and I bet part of it is that software fixes are easier than hardware, so you can get away with lower quality software.
- lstamour 7y ago> Can you provide an “enterprise class embedded OS” to device manufacturers and address post-deployment updates? How about Microsoft’s Azure Sphere Linux/cloud product with “10-year lifetime” support? > Azure Sphere will feature a turnkey cloud security service that guards every Azure Sphere device, including the ability to update and upgrade this security protection for a 10-year lifetime of the device. https://blogs.microsoft.com/blog/2018/04/16/using-intelligence-to-advance-security-from-the-edge-to-the-cloud/ https://blogs.microsoft.com/blog/2018/04/16/using-intelligen... Samples: https://github.com/Azure/azure-sphere-samples https://github.com/Azure/azure-sphere-samples Pricing, with support through July 2031: https://azure.microsoft.com/en-ca/pricing/details/azure-sphere/ https://azure.microsoft.com/en-ca/pricing/details/azure-sphe...
- wmf 7y agoAzure Sphere looks awesome but they need more SoC models for different use cases.
- autoexec 7y ago> Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Well, they could (D-link has millions), but they won't because it would eat into their obscene profits.
- deogeo 7y ago> Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. And yet my over 10 year old PC still gets the latest updates. Manufacturers have brought this on themselves, by locking and closing their devices, and insisting on proprietary solutions when open alternatives exist, or could exist.
- mkhpalm 7y agoIts been the norm for a long time now. I've always wondered why printer manufacturers could get away with universally exempting themselves from security audits. People just admitted they were bad and said: "don't even look at it wrong or it'll dump all its paper and toner on the floor"
- swinglock 7y agoIt really does. I had a network connected Xerox printer that would hang until rebooted, only by port scanning it with nmap.
- sniku 7y agoThis is exactly why I'm done with consumer router devices. Open Source routers are mature and infinitely more secure. https://teklager.se/en/open-source-routers/ https://teklager.se/en/open-source-routers/
- archi42 7y ago> Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? There is already vxWorks, they don't have to start from scratch and they're already widely used in the industry. (There are others as well). Anyway: The devices in question are running some Linux with a custom web interface on top. Patching this specific flaw is just about having one engineer add a few lines to the webif git, trigger a rebuild, flash to a qemu VM (could happen automatically) and test if the interface still works. If that's the case (which is likely), put the firmware as "unsupported"/"alpha" on the company FTP. This assumes they have proper tooling (e.g. tagged git, automatic&deterministic build server, an efficient test environment,...). If they don't have, they probably wouldn't buy it (or, maybe they would?). Automatic post-deployment are only the end of the chain, and for cheap embedded consumer systems there are good reasons against it: "My router didn't react, so I powercycled it" is problematic if it was just applying an update (resilience against this costs money, which is tight). And then your 1st level support has to explain your grandma how to use tftp to flash the firmware via the bootloader (this is bad for 1st level support suicide rates). Did I mention all the crap should be cheap? What good is a well maintained IoShit device if it costs 4$ more than the poorly maintained competition? Chances are high you won't sell enough to sustain your company - unless you go into a premium segment and just charge twice as much as the competition, which might still be problematic (consumer expectations change a lot with price - cheap and vs. expensive and nice). Also, at the other end of the embedded spectrum: Industrial embedded systems should probably only be updated if really necessary, e.g. if something is broken due to bad firmware. Downtime is really expensive for huge manufacturing plants, especially if unscheduled (in addition to the machine[s] not producing value, your 500 workers a fiddling their thumbs), so you want to reduce the number of opportunities for this to happen.
- ncmncm 7y ago> Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Yes. At least for routers, the topic of the article, OpenWRT is that OS. Any manufacturer can make it work on their router very cheaply. Any customer can install and upgrade it indefinitely.
- ijiiijji1 7y agoThe killer app would be a portable, secure (say, seL4), extremely fast-booting OS that handles hardware and tasks asynchronously. Right now, I'm dealing with a Xfinity->Cisco->Pegatron router that reboots spontaneously 15x/day, the web interface takes 2 minutes to load a PHP page and it takes 2-3 minutes to reboot. This is unacceptable since software doesn't have to behave like this... we can and must do better.