Physical and local protection.
WHAT TO DISABLE BEFORE SHIPPING
Debug and programming interfaces Development credentials and services Verbose logging Unused network services
WHY DEBUG INTERFACES SPECIFICALLY
They frequently give complete access and are routinely left enabled.
WHAT SECURE BOOT PROVIDES
The device refusing to run unsigned software.
WHAT IT REQUIRES
Keys in hardware, and careful key management.
WHAT ENCRYPTED STORAGE PROTECTS
Credentials and data, if the device is obtained.
WHAT TO STORE IN SECURE ELEMENTS
Keys, above all.
WHAT TAMPER DETECTION PROVIDES
Knowledge that a device was opened.
WHAT TO DO ON DETECTION
Erase credentials, and report.
WHAT PHYSICAL SECURITY TO ASSUME
Very little, for devices in public or customer premises.
WHAT THAT MEANS
A compromised device must not compromise others.
WHAT ENFORCES THAT
Per-device credentials, and authorisation limited to its own scope.
WHAT TO VALIDATE ON THE DEVICE
Every input, including sensor values and received messages.
WHY SENSOR VALUES
Malformed input from a peripheral has been used to compromise devices.
WHAT TO MINIMISE
Software present, and services running.
WHY
Every component is a potential vulnerability requiring maintenance.