3 ms·
I've found the elephant(s) in the room are key management, certificate revocation, and establishing a chain-of-trust from end to end. These are all problems th
by _caw 7y ago
I've found the elephant(s) in the room are key management, certificate revocation, and establishing a chain-of-trust from end to end.
These are all problems that cannot easily be solved through one library or service because they fundamentally involve the humans at your company taking responsibility.
Additionally, the article hints at Secure Boot, but a device must also be able to reject old patches, invalid combinations of patches, and untrusted patches - failing to boot _after_ an unsigned update is not a good user experience.