Hacker News new | ask | show | jobs
by jasode 2559 days ago
>served from an auto updated base, there's no reason why it couldn't be pretty much as secure as a platform. [...] Docker image that gets updated upstream for security issues [...] Why couldn't that work?

The update process itself acts as an attack vector. Even the techies like programmers can get pwned with trusted repositories that suddenly became untrusted.[0][1][2]

A decentralized server appliance of powerful sophistication that requires updates will require a baseline level of technical expertise. So far, even the less sophisticated hardware like wifi cameras and Nest devices are leaving unwitting homeowners exposed to criminals and unwanted spying.[3][4]

[0] https://www.theregister.co.uk/2018/07/12/npm_eslint/

[1] https://www.infoworld.com/article/3184399/malware-finds-unwi...

[2] https://nakedsecurity.sophos.com/2016/02/22/worlds-biggest-l...

[3] https://www.google.com/search?q=home+wifi+cameras+hacked

[4] https://www.vice.com/en_us/article/8qbq5x/the-cia-spied-on-p...