Physical access changes the embedded threat model

Once somebody can hold the device, most software protections stop being the relevant question.

Chips can be read, firmware extracted, debug ports found, memory dumped. For equipment deployed in public or on customer premises, physical access is a realistic assumption rather than an edge case, and the design has to assume the attacker owns one and has taken it apart.

More on IoT and embedded