Of course. Doesn’t mean we should leave the root password written down on a post-it next to the hardware. It sounds strange that such a privileged port has no authentication.
Getting security to work reliably in such scenarios can be hard. And your customer really don't want their up to hundred million in cost pieces of equipment sit there doing nothing because maintenance is unable to do something with it.
Much simpler just to instruct to physically secure the conduit around... Even better if that is already approved and demanded process.
At certain price point customers tend to make it also your problem. And expensive jets are certainly beyond that point. They might sue you. Or simply not buy or lease new ones.
Very true. I was actually thinking that telling the customer to secure the physical location where the insecure port is located is making it the customer’s problem while solving the authentication problem is making it the manufacturer’s problem. I guess you may have read it the other way?
Fair to say that everything has tradeoffs, even expensive hardware.
Comments
Of course. Doesn’t mean we should leave the root password written down on a post-it next to the hardware. It sounds strange that such a privileged port has no authentication.
Getting security to work reliably in such scenarios can be hard. And your customer really don't want their up to hundred million in cost pieces of equipment sit there doing nothing because maintenance is unable to do something with it.
Much simpler just to instruct to physically secure the conduit around... Even better if that is already approved and demanded process.
“Make it the customers problem” always works. These days it feels like LLMs are trained to do the same.
At certain price point customers tend to make it also your problem. And expensive jets are certainly beyond that point. They might sue you. Or simply not buy or lease new ones.
Very true. I was actually thinking that telling the customer to secure the physical location where the insecure port is located is making it the customer’s problem while solving the authentication problem is making it the manufacturer’s problem. I guess you may have read it the other way?
Fair to say that everything has tradeoffs, even expensive hardware.