| ▲ | pimterry 2 hours ago | |
> no Gov agency would ever mandate secure firmware Interestingly, Europe is about to try this: the Cyber Resilience Act is going to become obligatory for all sold digital products (hardware & software) by the end of 2027, with a bunch of strict minimum requirements: no hardcoded default passwords, must check for known vulnerabilities in components/dependencies, encryption for data at rest, automatic security updates by default (which must be separate from functionality updates), etc. Remains to be seen whether this'll help, but good to see somebody have a go at fixing this. | ||