Hacker News new | ask | show | jobs
by ses1984 1860 days ago
Devices that can’t be updated all face an early ewaste destiny, don’t blame expiring certs.
3 comments

This is kinda silly. These are problems that, as an industry, we make for ourselves. The fact that you can't make a network connected device that continues to function for decades without a constant maintenance is a problem not a feature.
Sure you can. Make an application that is frozen from future features but can still communicate with the platform at a basic level. Text Messages have been with us for centuries and still compatible with nearly 99% of devices.

Feature updates normally consist of "your device isn't supported and lock the user out without saying Good Bye.

If you create a platform that holds the basic for all versions and don't introduce new features to that; you won't have so much e-waste nor much maintenance upkeep.

well maybe a trust system that forces devices that can't be updated into obsolescence is not a good system.
Maybe having devices that can't be updated is not a good system.
Having perfectly functional devices that become obsolete because the world moves around them is also not a good system. We don't have to design our support targets to be a moving window of >= $current_version - 2.
Arguing with time's arrow is fruitless. The world will change, it isn't going to wait around for your OK.

For the most part we aren't talking about needless turnover here. The trust store represents an institutional claim, between now and whenever you stop using this device, all the people who have these private keys will take proper care of them. I actually think that claim is extremely dubious for these Android devices today, it relies on people we meanwhile judged as incompetent to have nevertheless correctly destroyed key materials in their possession when they ceased to do business. I would not be astonished to discover that this already did not happen at least once since the devices ceased to get updates.

For example I imagine all the Symantec roots are included, and likewise StartCom/ WoSign.

My dad had to replace his working but older Motorola phone because MMS stopped working because of outdated certs and he couldn't update anything to get them working again.