4 ms·
That's a very idealistic but unrealistic perspective. Often times the source code can't or won't be released - it could put further customers at risk if a vulne
by tcd 7y ago
That's a very idealistic but unrealistic perspective. Often times the source code can't or won't be released - it could put further customers at risk if a vulnerability is found and the update servers have gone away.
Some devices might not be possible to update due to hardware/software configuration (perhaps certain variables are hard coded?).
Whilst what you're saying is right it just doesn't work that way. I'd love for all the Android devices to get years of OS and security patches, but it simply doesn't happen.
Any IoT device is pretty much the same. It's not going to change any time soon.
Only invest in products you can be sure of (which is hard these days). Expect them to break, expect nobody to care, and be prepared to lose money or get a terrible ROI - it's why phones don't get updates, the OEM doesn't make money from providing updates which are a direct cost VS selling a new phone.
This is capitalism, produce crap, sell many units, offer no support, rinse and repeat.
- Silhouette 7y agoMarket forces have clearly failed to address this issue for an extended period, so this seems to be a situation where statutory regulation is indicated.
- vbezhenar 7y agoSecurity by obscurity does not work. For experienced reverse engineers reading assembly code is as easy as reading C code for someone else.