Hacker News new | past | comments | ask | show | jobs | submit login

So allow the device vendor a way to push a configuration change?



Then the attacker would push that configuration change before DDoSing someone.


Well, I would hope that any IoT device that accepts remote configuration or software updates also checks digital signatures before applying changes. If it doesn't, then I would want the automatic firewall on the router to block all updates.


Your router would notify you of the change and ask if it was intended before applying it, maybe?

I realize how close to Vista's UAC this is getting.


Make the configuration change come from the approved endpoints.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: