4 ms·
Trying to work out what I'd want in a first pass. At an absolute minimum: * A commitment and ability to update any critical security issues for a specified amo
by sonofgod 7y ago
Trying to work out what I'd want in a first pass. At an absolute minimum:
* A commitment and ability to update any critical security issues for a specified amount of time
* Standardised mechanisms for reporting critical updates to users which are not used for marketing
* A basic checklist of best practice for internal self-audit (SQL injection, plaintext data, enumeration attacks)
A low bar, but still far better than what we've currently got. (External audits are probably silver tier?)
- smhenderson 7y agoGood list. I would add a clear and accessible way to report a perceived problem without fear of some type of reprisal from the company. But I can also see how that could be abused by bad actors so I guess it would be a tricky part of the policy to do correctly.
- mattlondon 7y agoI'd add: - 2-factor auth support - federated login support (i.e. login with Google/Facebook/etc buttons) - some sort of indication of encryption in-flight and at-rest, and who handles the keys (e.g. is there a per-user key that tech support can't even access without user grant, or is there a single hard-codes AES key in the APK etc that everyone knows)
- fmajid 7y agoMost MCUs don't have a persistent real-time clock and thus if power is lost, there is a good chance TOTP based 2FA will no longer work.
- rkangel 7y agoThe 3rd one makes sense, the first two are system questions rather than device questions. In an open system there may be multiple service providers who's security should be judged separately from the security of a device.
- elliekelly 7y ago> A basic checklist of best practice for internal self-audit (SQL injection, plaintext data, enumeration attacks) I think this is a massive ask/knowledge expectation for the average person. A simple warning label about changing the device password from the default would be a major step in the right direction for consumers.
- nitrogen 7y agoThe average consumer probably has no idea what a growth hormone is either, but it's all over food labeling. It might be enough if there is a label that security experts know and understand, that consumers can learn to say yes/no about without having to know what it really means.
- michaelt 7y agoI think sonofgod means "Vendor self-certifies they have tested their device against the checklist" rather than that end users would perform the audit.
- fmajid 7y agoThe label could have a simple grade, along with a QR code leading to the governmental agency approval DB page for the product in question.
- michaelt 7y agoMaybe you'd enjoy reading - and perhaps contributing to - Draft ETSI EN 303 645 https://www.etsi.org/deliver/etsi_en/303600_303699/303645/02.00.00_20/en_303645v020000a.pdf https://www.etsi.org/deliver/etsi_en/303600_303699/303645/02...