Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Embedded market ripe for picking
Daniel Hanson, 2005-09-09

Perhaps an embedded version of windows in every device isn't such a bad thing after all.

Comments Mode:
Embedded market ripe for picking 2005-09-09
Anonymous
Embedded market ripe for picking 2005-09-09
Anonymous
Embedded market ripe for picking 2005-09-11
Paul Kosinski (1 replies)
Embedded market ripe for picking 2005-09-11
Anonymous
Embedded market ripe for picking 2005-09-12
Alexey Vesnin
Silent firmware upgrades considered harmful 2005-09-22
Anonymous
"And, for extra points and an offical badge of honor:

4. I will find a way to update my embedded system silently and flawlessly so no-one has to interact with it at all."

Naw, I consider this harmful. In the UK, we have Digital TV set-top boxes that accept firmware upgrades over-the-air. This results in at least three additional risks, even if the firmware received is as intended by the manufacturer - a) that the firmware is bad, or undetectably corrupt, and leaves the device irrecoverable after the upgrade b) that the flash device has reached its write limit and results in an unusable firmware image c) change in behaviour, either malicious or undesired.

I've personally experienced c) with my parents' box. As purchased, it had a bug that meant I needed to cable it in a specific way to make it work in a consistent manner. After a (silent) firmware upgrade, the bug was fixed, and my elaborate cabling meant that it stopped working entirely (at least, from my parents' point of view).

Futhermore, silently upgradeable firmware is a vulnerability in itself; I've personally lost a DVD-Rom drive - every other byte of the firmware was apparently corrupted by some rogue piece of software. Devices with field-upgradeable firmware should have a *physical* user control to disable firmware upgrades - i.e. a switch or jumper that cuts the write enable line to the flash device(s).

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/353/32425#32425
Embedded market ripe for picking 2005-09-23
Anonymous
Embedded market ripe for picking 2006-03-29
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus