End-of-support is a security event
The day support ends, nothing changes about the device and everything changes about its risk.
Flaws found afterwards stay unfixed permanently, and the accumulation is one-directional. It deserves treating as a scheduled event with a plan, rather than as a date that passes unremarked and is noticed two years later during an assessment.
More on IoT and embedded
- A default password scales into a fleet vulnerabilityOne word, printed a million times
- Physical access changes the embedded threat modelThe lid was the threat model
- Firmware updates are a long-term security promiseYou sold the box, you signed up for the years
- Secure boot protects the startup chainEach link checks the next
- Device identity should be uniqueAll answering to one name
- Cloud shutdown can strand smart devicesThe strings came from elsewhere
