4 ms·
Let's assume product uses domain.com to get updates. domain.com one day might be owned by $badDude - that's a huge risk domain.com might return 404's - that's
by tcd 7y ago
Let's assume product uses domain.com to get updates.
domain.com one day might be owned by $badDude - that's a huge risk
domain.com might return 404's - that's pretty terrible.
What happens to domain.com once $business is now $noLongerBusiness?
You can provide a method of flashing firmware onto the device itself (possible security risk?), but where do you get the files from? How do you verify they're safe?
Then, you need to host the server software itself (depending on how it's coded, that ranges from quite simple to your worst nightmare), and you expect someone to keep that secure? The EU dictates GDPR compliance, which adds additional cost to maintenance.
It's just easier and cheaper to just not bother with servers if the company can't keep them online.
- vbezhenar 7y agoLet user change server domain. Firmware must be signed by certificate with that domain. So now user can change server domain to his own server (or someone he trusts) and sign firmware with that key. It poses no security risk.