3 ms·
there are many parts of this problem, I have particular thoughts on two. one concrete recommendation I would make is mandatory third party pen tests. software
by kapilvt 3y ago
there are many parts of this problem, I have particular thoughts on two.
one concrete recommendation I would make is mandatory third party pen tests. software companies have to do this for soc2, etc. Companies putting live mics in living rooms across the country should deal with the same. This is all to raising the level of initial security on devices, including the update process.
the other consideration is about updates, and its much more nuanced against what's viable for a business. there is no security without updates, but the ability to produce those on any schedule is unclear. even more so when the originating company goes out of business. Ideally there would be a threat matrix here against a CVE list (remote access to hot mic/camera), would require a manufacturer to issue an update within x days.