Firmware updates are a long-term security promise
When you sell a connected device you are committing to maintain software on it for as long as it is in service.
Many manufacturers do not, and the device keeps working while quietly becoming indefensible. UK rules now require manufacturers to state how long updates will continue, which at least makes the commitment visible at the point of purchase. That published date is the most useful security specification on the box.
More on IoT and embedded
- A default password scales into a fleet vulnerabilityOne word, printed a million times
- Physical access changes the embedded threat modelThe lid was the threat model
- Secure boot protects the startup chainEach link checks the next
- Device identity should be uniqueAll answering to one name
- Cloud shutdown can strand smart devicesThe strings came from elsewhere
- Sensors can be fooled without hacking softwareNo code was touched
