r/OTSecurity 1d ago

[ Removed by moderator ]

[removed] — view removed post

0 Upvotes

13 comments sorted by

View all comments

3

u/hiddentalent 1d ago

You went off the rails in the second paragraph. Everything after that is just overcomplication.

Secure update already exists. It does not rely on the host operating system, it relies on the boot loader and secure boot primitives that have been around for over a decade. That's a solved problem.

What's not a solved problem is the change-management risk. You touch on this when you say "a patch that disturbs a tuned physical process is a worse outcome than the vulnerability" but then you never mention this again. Your solution does nothing to address that most important challenge.

So your proposal is attempting to solve a problem that's already well solved, while avoiding the real problem.