Physical access changes the embedded threat model
Once somebody can hold the device, most software protections stop being the relevant question.
Chips can be read, firmware extracted, debug ports found, memory dumped. For equipment deployed in public or on customer premises, physical access is a realistic assumption rather than an edge case, and the design has to assume the attacker owns one and has taken it apart.
More on IoT and embedded
- A default password scales into a fleet vulnerabilityOne word, printed a million times
- Firmware updates are a long-term security promiseYou sold the box, you signed up for the years
- Secure boot protects the startup chainEach link checks the next
- Device identity should be uniqueAll answering to one name
- Cloud shutdown can strand smart devicesThe strings came from elsewhere
- Sensors can be fooled without hacking softwareNo code was touched
