|
|
|
|
|
by horsawlarway
1693 days ago
|
|
Could not agree more. At the bare minimum a vendor should not be allowed to sell a device that has digital locks if the user is not also given a copy of the keys. You can lock the device, but if I don't get a key at time of purchase, then I don't own the damn thing. |
|
One possibility is around DNS. A public/private keypair is basically a lock and a key. If you can't put ANY public keys on my device without giving me the private key, HTTPS is going to be problematic. Software updates become a little scarier as well, since a man-in-the-middle attack becomes MUCH easier to pull off. But perhaps the answer there is, like DNS on a desktop computer, to simply allow the user to edit those local keys. As long as there's a "Yes, I am also cool with installing unsigned software updates," then I don't see a problem.