Why? What security benefit do you gain by using HTTPS when you already check the signature/hash of the firmware file?
Why? What security benefit do you gain by using HTTPS when you already check the signature/hash of the firmware file?
If you assume there IS further version validation, then the question is how do you know what version you should be expecting without HTTPS?
Downside: Reverting is not possible if you make a serious mistake in an upgrade. If you can't initiate another upgrade process, bricking is possible...
I don't know much about the world of really small devices aka IoT, but from my laymen perspective: Is a full TLS stack still a huge obstacle there? Sane signature checks are at least a step in the right direction.
Synchronize time using one of the time signals available in the area or use signed channel for time sync. Using radio time signal it can be easy to spoof it if your location is known by the intruder, but makes it practically impossible for remote exploits. But radio signals may have bad reception inside a house.
Maybe people hand-roll their own signature validation code badly, but those same people will just as much screw up or plain disable the CA verification.
If you have the knowledge to use the primitives from something like NaCl, you have nothing to gain from using a full TLS stack but pain building, upgrading, programming your firmware and massive middleware problems in the field. And when they inevitably find issues in the TLS stack you used, your device is now fucked since there is no virtual address space, W^X, even stack cookies..
[citation needed]
B/c without HTTPS you can't verify you're actually talking to IKEA's update servers. Even if there's firmware signature implemented an attacker could still MITM you over HTTP and simply not serve you a file with updates. Which means that they can prevent your devices from upgrading, i.e to receive an update that closes a known flaw they might be exploiting.
They probably should have signed the json listing of firmware images though, in addition to just the firmware images.