|
|
|
|
|
by Aurornis
160 days ago
|
|
Forcing the release of signing keys would be a security disaster. The first person to grab the expired domain for the auto update server for a IoT device now gets a free botnet. The only real way to make devices securely re-usable with custom firmware requires some explicit steps and action to signal that the user wants to run 3rd-party firmware: A specific button press sequence is enough. You need to require the user to do something explicit to acknowledge that 3rd-party software is being installed, though. Forcing vendors to release their security mechanisms to the public and allow anyone to sign firmware as the company is not what you want, though. |
|
I run a bunch of stuff using Home Assistant via the Zigbee integration - the Zigbee host on the local server gets to decide where to install updates from - which was the security mechanism for most most software for most of history.
Get your stuff from a reputable source. Signage keys are nice, but they don't work as the sole security measure in an unsound supply chain.