[193679] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: IoT security

daemon@ATHENA.MIT.EDU (Rich Kulawiec)
Sat Feb 11 04:34:20 2017

X-Original-To: nanog@nanog.org
Date: Fri, 10 Feb 2017 17:55:01 -0500
From: Rich Kulawiec <rsk@gsp.org>
To: nanog@nanog.org
In-Reply-To: <CALFTrnP-Qq8RPXKfgTLiLwRCtT6qfvozFrp+GKQZa4h3gFEH3g@mail.gmail.com>
Errors-To: nanog-bounces@nanog.org

On Tue, Feb 07, 2017 at 08:58:46AM -0500, Ray Soucy wrote:
> Ideally a cloud-managed device so that the config wouldn't need
> to be rebuilt in the event of a hardware swap.

That opens them to a class breach: instead of one getting compromised
they *all* get compromised.  Better to save the configuration to cheap
local media like a USB stick.  Yes, it could get lost, but that doesn't
break or compromise the device, and it only affects one device.

---rsk

home help back first fref pref prev next nref lref last post