[193679] in North American Network Operators' Group
Re: IoT security
daemon@ATHENA.MIT.EDU (Rich Kulawiec)
Sat Feb 11 04:34:20 2017
X-Original-To: nanog@nanog.org
Date: Fri, 10 Feb 2017 17:55:01 -0500
From: Rich Kulawiec <rsk@gsp.org>
To: nanog@nanog.org
In-Reply-To: <CALFTrnP-Qq8RPXKfgTLiLwRCtT6qfvozFrp+GKQZa4h3gFEH3g@mail.gmail.com>
Errors-To: nanog-bounces@nanog.org
On Tue, Feb 07, 2017 at 08:58:46AM -0500, Ray Soucy wrote:
> Ideally a cloud-managed device so that the config wouldn't need
> to be rebuilt in the event of a hardware swap.
That opens them to a class breach: instead of one getting compromised
they *all* get compromised. Better to save the configuration to cheap
local media like a USB stick. Yes, it could get lost, but that doesn't
break or compromise the device, and it only affects one device.
---rsk