3 ms·
I think that IOT device manufacturers should be required to support their device for some minimum period of time AND be obligated to release the full source cod
by distract8901 3y ago
I think that IOT device manufacturers should be required to support their device for some minimum period of time AND be obligated to release the full source code for the device once they decide to end support. This also requires releasing the keys to any firmware signing mechanism or publishing a firmware update that removes such checks.
The core problem is that without control of the firmware, consumers don't really own these devices. The company can unilaterally decide one day to brick your device and force you to buy a new one. It should be obvious that this behavior is egregiously anti-consumer and anti-competitive.
- kijin 3y agoThere's also the problem that electronic devices last a long time -- often much longer than any manufacturer wants to admit. Vehicles, PCs, printers, and routers can easily last 10 years. Refrigerators and HVAC units can last 20 years or more. And now we're putting "smart" stuff into electric circuits that should last the lifetime of the house. The manufacturer will probably go out of business long before those devices go out of service, and there's no guarantee that there will be anyone to push one final firmware update or release the source code in the hectic last few days of an imploding business.
- motohagiography 3y agoSeconding this thread. There is no reason why a device shouldn't be servicable in 30 years regardless of whether the vendor is still in business. There might be a way to integrate these IoT regulations with e-waste regulations, where the liability for disposal, recycling, and cleanup is related to servicability.
- creole_wither 3y agoSome sort of escrow with a dead man switch could solve this. They can reset the switch by releasing an update or affirming that they are still providing service. If no communication is received after a certain period of time, then it gets released publicly.
- gsuuon 3y agoThis is great for hackers but doesn't it make IoT devices incredibly insecure for normal users who wouldn't even know their device has reached end of support?
- rfoo 3y ago> doesn't it make IoT devices incredibly insecure for normal users How secure or insecure a device is is unrelated to whether its source code is public. Disclosure: I might be biased on this, as I'm a reverse engineer.
- whats_a_quasar 3y agoI think the parent comment is implying that if the source code is released at the end of the device's supported life, it will be much easier for hackers to find vulnerabilities. Then users who aren't paying attention will continue running that last version, and hackers will attack them using those now-public vulnerabilities. So you'd still need some mechanism to force-update devices in response to vulnerabilities found in open-source end-of-support firmware.
- gsuuon 3y agoReleasing source code could lower the barrier a bit but the main thing I was calling out is releasing the keys - maybe they could be transferred to a trusted custodian instead.
- iforgotpassword 3y agoIn certain cases probably yes, but maybe still worth it? If you have the keys you still need to get your maliciously manipulated build on the customer's device... And this is assuming the manufacturer even bothered signing and verifying in the first place. So this would be bad for manufacturers releasing secure well designed devices without security vulnerabilities.... But if you think about it for a second, isn't this good? As long as there is no known vulnerability, the manufacturer can say the device is still supported, and it costs them nothing, as they have no reason to release an update. And well, if there is a security issue, then it might be better to have the source and keys after all?
- charcircuit 3y ago>AND be obligated to release the full source code for the device once they decide to end support. This is unreasonable. Code is often reused in the next generation of a product. The company may not have the rights to release all of the code.
- summm 3y agoThen they have to acquire the rights to do so for of all components before they use those components.
- jpc0 3y agoA competent technician with access to a workshop can make even 80 year old vehicles work. That is long past the service life of that vehicle but it can still be done, an iteration of the same technology is likely still in use today though in your car. That isn't possible for software simply because reverse engineering is not simple, reverse engineering a small microcontrollers firmware might be possible, reverse engineering even something like old unix wouldn't be and definitely any modern operating system wouldn't be even though there is no legal precedent for that source code to be protected. In 30-40 years time when early windows and early DOS copyright expires do you think Microsoft is going to benevolently make that source code available? It has legally become public domain but the source code will still remain closed. How about firmware for IOT devices being installed in your house, it's likely that that hardware can be made to work for the next 60 years but you are forced to replace it in 3 when the manufacturer decices it's no longer financially viable to support it.
- charcircuit 3y ago>That isn't possible for software simply because reverse engineering is not simple Nor is repairing a car. It is not as hard as you think to RE some random IoT device firmware.
- jpc0 3y agoIs it "Here's a manual and a pile of tools, follow the instructions" hard? Most maintenance on vehicles is exactly that. The smart fridge that has a buffer overflow leading to RCE cannot be fixed quite a easily as as replacing the brakes on my car, neither is easy but one of those a monkey with a spanner could figure out eventually.