Remix.run Logo
dylan604 4 hours ago

I didn't ask what can you have. We could have whatever safety processes we wanted with multiple levels of redundancy. However, that's not what's available on COTS IoT devices though, so speculation does not help.

Flashing the firmware of a cheap IoT device remotely OTA is not without risk.

_flux 3 hours ago | parent [-]

Surely the basic flashing mechanisms used nowadays will first check checksum (and hopefully a device magic), and then you have a relatively short time window when it actually does the flashing after which it reboots? Even small devices nowadays seem to have the memory for it. So there is a window of failure, but it's not a very long one.

Well, in addition to flashing the incorrect or buggy firmware.