3 ms·
We sell industrial equipment which will live its entire life (20+ years) off the internet. Browsers and the people who sit on these committees are understandab
by therealjumbo 7y ago
We sell industrial equipment which will live its entire life (20+ years) off the internet.
Browsers and the people who sit on these committees are understandably more focused on their own use cases, but there really does need to be a viable certificate solution for small embedded devices, preferably works with mDNS too. I'm not going to hold my breath, but until this happens any/all IOT devices will remain largely insecure. Big co's (like my employer) can develop and deploy a custom solution, most companies cannot.
- geofft 7y agoThat's a little bit of a different problem, since the client end of the connection isn't the general public. (At least for industrial equipment.) The router problem is that you need a normal, unconfigured web browser to be able to access the router's config page. The immediate solution that occurs to me is installing a private CA, possibly one with name constraints for the vendor, because private CAs aren't held to the same rules about validity. I'm curious why this doesn't work - is it just that the tooling needed to make it happen isn't polished enough for small vendors? I'm guessing that internet of things devices are, by their name, on the internet and can talk to a CA. Yes, this will require some way to give them a real domain name, but you could either give them names on the vendor's site or encourage people to get a domain name for themselves.