Protecting update systems from nation-state attackers
Protecting update systems from nation-state attackers
[Security] Posted Jul 24, 2019 14:56 UTC (Wed) by corbet
Frequent updates are a key part of keeping systems secure, but that goal will not be met if the update mechanism itself is compromised by an attacker. At a talk during the 2019 Open Source Summit Japan, Justin Cappos described Uptane, an update delivery mechanism for automotive applications that, he said, can prevent such problems, even when the attacker has the resources of a nation state. It would seem that some automobile manufacturers agree.