[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: simple security



On 3/24/10 9:31 PM, Fred Baker wrote:
On Mar 24, 2010, at 1:21 PM, Mark Smith wrote:

is every light switch
expected to come with it's own host-based firewall solution?
Speaking as the chair of the Security Subcommittee of the SGIP's Smart Grid Architecture Committee, my inclination would be to have the light controller be able to authenticate and authorize messages instructing it to modify the state of its light bulb, and determine whether they are from a switch that is authorized to initiate such messages. Absent that, I submit that the 21st century equivalent to TP'ing the house of the cute person-of-opposite-gender down the street might be to have their lights making statements using Morse Code.
As such, you wouldn't rely on firewall between the two to secure the light controller. The security needs to be between the controller and switch, not policed by a middlebox function dropping packets it thinks might be from a rogue source without *really* knowing.

I agree wholeheartedly with this security model.

- Mark
http://www.ipinc.net/IPv4.GIF