Protecting data in transit.
WHAT TO USE
Encrypted transport, always.
WHAT CONSTRAINED DEVICES MAY NEED
Lighter variants designed for datagrams and limited resources.
WHAT TO VERIFY
The server's certificate, properly.
WHAT TO NEVER DO
Disable verification to make development easier.
WHY
It is routinely left disabled, and removes all protection.
WHAT TO EMBED
The trusted authority certificates the device accepts.
WHAT TO PLAN
Updating those, since authorities change.
WHAT MESSAGE-LEVEL SECURITY ADDS
Protection that survives intermediaries and storage.
WHERE IT MATTERS
When messages pass through gateways or brokers you do not control.
WHAT REPLAY PROTECTION REQUIRES
Sequence numbers or timestamps, checked by the receiver.
WHY
A captured message resent later could repeat an action.
WHAT TO AUTHENTICATE
Commands to devices, at the message level.
WHY NOT ONLY THE TRANSPORT
A compromised broker could otherwise inject commands.
WHAT TO MINIMISE
Data transmitted at all.
WHY
What is not sent cannot be intercepted, and it saves cost.
WHAT TO TEST
Behaviour when interception is attempted.