Embedded Security Print

  • specialisedtechnology, specialised, security, hacked, woocommerce, guide, howto, solution
  • 0

Protecting devices in the field.

WHAT TO ASSUME

The device is physically accessible to an attacker Firmware can be extracted and analysed Communications can be intercepted

WHAT THAT RULES OUT

Secrets shared across every device Security depending on obscurity Trusting anything the device reports without verification

WHAT PER-DEVICE IDENTITY PROVIDES

Compromise of one device not compromising all.

WHAT TO PROVISION

Unique keys per device, at manufacture.

WHERE TO STORE THEM

A secure element or hardware-protected storage.

WHAT TO DISABLE BEFORE SHIPPING

Debug interfaces Development credentials Verbose logging Unused services

WHY DEBUG INTERFACES SPECIFICALLY

They frequently provide complete access, and are routinely left enabled.

WHAT TO ENCRYPT

Stored data, and all communications.

WHAT TO VALIDATE

Every input, including from sensors and peripherals.

WHY

Malformed input has been used to compromise devices.

WHAT TO PLAN FOR

Vulnerability disclosure, and how you would respond.

WHAT OBLIGATIONS MAY APPLY

Regulations increasingly require update capability and disclosure processes.

Take advice on your position.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot