Otherwise we're just manufacturing e-waste.
Otherwise we're just manufacturing e-waste.
The industry should be made to move to security models that don't revolve around baking in manufacturer-privileged keys (verification or attestation). Internal groups developing any default user-environment software should have to stay at an arms length from the hardware team, and only be using published documentation.
Have proper standards how music is transmitted. Have devices support those standards. Have those standards be long-running.
When trillion-dollar companies consider a serial connector to be a proprietary and DRM-enabled apparatus I think the "real solution" is precluded by entirely unnecessary corporate greed.
Regular major and minor chords were unaffected though :)
(I actually started reading this comment as a pun, as in "The EU can regulate music streaming - they already regulated power chords", and that made me smile)
This is particularly true of internet connected devices, but is also true for IOT devices that only connect to the internet indirectly. Security holes get found, if you can't patch and update devices in the field then you are leaving your customers unprotected.
And I feel that updates are being abused too much by device makers now:
-allows making devices worse, say "optimizing" the UI e.g. to make you spend more time in the parts they (not necessarily the user) want you to see
-allows releasing half-finished games since they can just be updated later anyway
-allows breaking old functionality for whatever reason
-allows the device makers to choose when to do the update rather than the user, say just when you want to start playing a game
It's a shame there's no less invasive way to ensure devices are secure. It sure is convenient for the device makers that the solution to security also gives them continuous control over your device's features and when you can actually use it
If the device is using a read-only firmware, has a secure boot chain of trust, lives behind a firewall and only makes outgoing connections, the risk is very limited. You can't directly connect to it, so your only option is to tamper with traffic in transit and exploit some buffer overflow in how it parses replies to its requests - that's already a very targeted attack that's really hard to scale, and with an intact secure/trusted boot chain it still means you can't persist so you'd need to redo this every time the device is rebooted.
And finally, assuming you manage to do all the above, what't the payoff? For a "Car Thing", the payoff is quite limited. I guess you can blast obnoxious music at full volume against the user's wishes?
And if they're your services then you can maintain their stability.
Well no, because not all e-waste are devices that you can conceivably reflash. For instance a monitor equals at least 10 phones in terms of e-waste volume, but I doubt legislation like this is going to make a dent in monitor e-waste. The proposal only realistically makes a difference for computing devices with short EOL periods and locked bootloaders, so basically phones and tablets.
I believe if given the tools, people would gladly donate their time to make something fun with it. Heck, that's what I do in my spare time. But it's impossible if everything is completely locked down, as if a music streaming box contains nuclear launch codes that must be protected at all costs.
If installing alternative/third-party firmware becomes easy and normalized, there will also be more options to choose from, because it will actually become worthwhile for people/companies to develop said firmware.
If you have an easy way to flash any phone and plenty of firmware available, it makes sense to turn flashing into a business. Buy used phones off people who don't need them any more, reflash them with a newer and debloated Android, and then sell them off for more than you got them for.
This would very quickly lead to abuses though. If PC OEMs are bad, imagine what a small mom-and-pop shop, subject to a lot less scrutiny and having much less respect for the law could do.