IoT Security Updates
The cluster centers on the lack of firmware security updates for IoT and embedded devices, with debates on manufacturer responsibilities, vulnerabilities from unpatched devices, and risks of internet connectivity.
Activity Over Time
Top Contributors
Keywords
Sample Comments
The lack of ongoing support from device manufacturers is really awful. There were some major UPnP vulnerabilities (last year, as well as some previous ones iirc) and a parade of attacks against WPA of various levels and very few devices ever get patched for them - including high-spec devices.Running open-source firmware is basically necessary to have any chance against all these attacks, because manufacturers simply won't do the work.There really really needs to be some regulation on
These things really shouldn't be internet connected, and the firmware should be controlled by the owner.
That's a very idealistic but unrealistic perspective. Often times the source code can't or won't be released - it could put further customers at risk if a vulnerability is found and the update servers have gone away.Some devices might not be possible to update due to hardware/software configuration (perhaps certain variables are hard coded?).Whilst what you're saying is right it just doesn't work that way. I'd love for all the Android devices to get years
Security updates need to be supplied for anything that can connect to a network. Vulnerabilities are anything that allows remote read or write access to the device without the user's explicit consent. Companies need to open source everything needed for supplying security updates before going bankrupt (perhaps setting up a suitable insurance to make sure there is money for work needed to do so). You can't import products that don't meet these requirements, just like you can't
No. As long as their iot device is still working consumers could care less about security updates.
Just requiring security updates doesn't guarantee much; they have to actually stop the threats. I'd like some opt-in qualification guaranteeing support similar to what autos have. There are recalls for safety issues, refunds for negligence, etc for a reasonable amount of time. Behind the scenes, this requires some kind of fund or insurance to back up the liability, which does have a cost. It's fine if not all products meet this high bar, but it'd be good for highly-committed
Frighteningly possible counter-alternative: continue to ship bad software on embedded devices and just toss network connectivity in there in the event the device becomes popular / customers demand an update.
Well how else would you get security updates for your insecure devices if not by connecting them to the internet. /s
I wouldn't call it FUD. Embedded devices tend to get updated less frequently than PCs. Connecting them all to the internet is not helping.
Something so critical shouldn't be build with needing to have security updates. It's a design flaw. Make the device physically secure instead.