<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>embedded security &#8211; TELEGRID</title>
	<atom:link href="https://telegrid.com/tag/embedded-security/feed" rel="self" type="application/rss+xml" />
	<link>https://telegrid.com</link>
	<description></description>
	<lastBuildDate>Mon, 05 Feb 2018 21:59:52 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.6.13</generator>

<image>
	<url>https://telegrid.com/wp-content/uploads/2022/09/cropped-Screen-Shot-2022-08-29-at-9.50.37-AM-32x32.png</url>
	<title>embedded security &#8211; TELEGRID</title>
	<link>https://telegrid.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Does President Trump Want an Offline LINUX Repository?</title>
		<link>https://telegrid.com/offline-linux-repository?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=offline-linux-repository</link>
		
		<dc:creator><![CDATA[Beth Flippo]]></dc:creator>
		<pubDate>Mon, 15 May 2017 12:11:37 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Embedded Software]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[embedded security]]></category>
		<category><![CDATA[LINUX repository]]></category>
		<guid isPermaLink="false">http://telegrid.com/?p=1096</guid>

					<description><![CDATA[<p>On May 11th President Trump signed a Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure.  In that Executive Order the President stated that, “Known but unmitigated vulnerabilities are among the &#8230;</p>
<p>The post <a rel="nofollow" href="https://telegrid.com/offline-linux-repository">Does President Trump Want an Offline LINUX Repository?</a> appeared first on <a rel="nofollow" href="https://telegrid.com">TELEGRID</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On May 11<sup>th</sup> President Trump signed a <a href="https://www.whitehouse.gov/the-press-office/2017/05/11/presidential-executive-order-strengthening-cybersecurity-federal">Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure</a>.  In that Executive Order the President stated that, “Known but unmitigated vulnerabilities are among the highest cybersecurity risks faced by executive departments and agencies.  Known vulnerabilities include using operating systems or hardware beyond the vendor&#8217;s support lifecycle, <strong>declining to implement a vendor&#8217;s security patch, or failing to execute security-specific configuration guidance</strong>.”  It seems the President agrees with something <a href="http://www.telegrid.com">TELEGRID</a> has been recommending for years, an offline LINUX repository for secure networks.</p>
<p>As an embedded software developer I can go on and on about the many benefits of LINUX.  I can easily list hundreds of benefits.  What I believe is the greatest though is the LINUX repository.</p>
<p>The LINUX repository is an online archive of open source and proprietary software packages that programmers use for development or maintenance.  There is a repository for every LINUX distribution with compiled packages for a multitude of hardware configurations.  Software developers can create upgrades or security patches and upload them to the LINUX repository where they can be easily downloaded by users.</p>
<h4 style="text-align: center;"><a class="fancybox" href="#contact_form_pop"><span style="color: #ff6600;">Click to Subscribe</span></a></h4>
<div class="fancybox-hidden" style="display: none;">
<div id="contact_form_pop" style="text-align: center;">[contact-form-7 id=&#8221;1478&#8243; title=&#8221;Subscribe&#8221;]</div>
</div>
<p>Unfortunately, new security risks are forcing system administrators to limit connectivity between secure networks and the internet.   You can’t be hacked if a hacker can’t get in. While a closed network is ideal for security, it is a big problem for software maintenance.</p>
<p>Since the LINUX repository is online, the software upgrades are inaccessible on a secure network.  For years defense contractors, like <a href="http://www.telegrid.com">TELEGRID</a>, have had to go to great lengths to deploy software upgrades on secure networks.  This leads to delays in the deployment of security patches and seemingly endless upgrade cycles.</p>
<p>To resolve these issues we recommend replicating the LINUX repository inside secure networks with an offline LINUX repository.  But how do we update the LINUX repository if it is offline? One solution is to deploy a cross domain solution that straddles the secure and unsecure networks.  Another solution is compressing repository updates and sending them to a system administrator who can upload them into the offline LINUX repository.</p>
<p>While secure networks are important we must not forget that the main goal is functional, bug-free and secure code.  An offline LINUX repository will make it easier to maintain code on secure networks and apply needed security patches.  It seems the President agrees.</p>
<p>&nbsp;</p>
<p>Beth Flippo is Vice President of Embedded Software at <a href="http://www.telegrid.com">TELEGRID</a>.  TELEGRID has unique expertise in secure embedded systems, secure authentication, PKI, and Multi-Factor Authentication (MFA).</p>
<p>&nbsp;</p>
<h4 style="text-align: center;"><a class="fancybox" href="#contact_form_pop"><span style="color: #ff6600;">Click to Subscribe</span></a></h4>
<div class="fancybox-hidden" style="display: none;">
<div id="contact_form_pop" style="text-align: center;">[contact-form-7 id=&#8221;1478&#8243; title=&#8221;Subscribe&#8221;]</div>
</div>
<p>Disclaimer: The opinions expressed here do not represent those of TELEGRID Technologies, Inc.  The Company will not be held liable for any errors, omissions, or delays in this information or any losses, injuries, or damages arising from its display or use.  All information is provided on an as-is basis.</p>
<p>The post <a rel="nofollow" href="https://telegrid.com/offline-linux-repository">Does President Trump Want an Offline LINUX Repository?</a> appeared first on <a rel="nofollow" href="https://telegrid.com">TELEGRID</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Government Activism and IoT</title>
		<link>https://telegrid.com/government-activism-and-iot?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=government-activism-and-iot</link>
		
		<dc:creator><![CDATA[Eric Sharret]]></dc:creator>
		<pubDate>Tue, 17 Jan 2017 16:23:05 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Embedded Software]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[embedded security]]></category>
		<category><![CDATA[IoT]]></category>
		<guid isPermaLink="false">http://telegrid.com/?p=985</guid>

					<description><![CDATA[<p>The Mirai Botnet Distributed Denial of Service (DDoS) attack of September and October 2016 gave a brief glimpse of the effect Internet of Things (IoT) devices can have on the greater Internet.  This event was &#8230;</p>
<p>The post <a rel="nofollow" href="https://telegrid.com/government-activism-and-iot">Government Activism and IoT</a> appeared first on <a rel="nofollow" href="https://telegrid.com">TELEGRID</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The Mirai Botnet Distributed Denial of Service (DDoS) attack of September and October 2016 gave a brief glimpse of the effect Internet of Things (IoT) devices can have on the greater Internet.  This event was especially felt in Washington, D.C. where there seems to be an uptick in the amount of Government activism and IoT and the frequency and scale of intervention with IoT device manufacturers.  The following are just a few examples:</p>
<ul>
<li>On December 30, 2016 the Congressional Internet of Things Working Group released a <a href="http://latta.house.gov/uploadedfiles/iot_working_group_white_paper.pdf">white paper</a> on IoT stating that, “Recent examples of cyberattacks on IoT devices have exposed not just the potential impact on individual consumers, but the possible vulnerability on the broader Internet infrastructure.”</li>
</ul>
<ul>
<li>On January 5, 2017 the Federal Trade Commission issued a <a href="https://www.ftc.gov/system/files/documents/cases/170105_d-link_complaint_and_exhibits.pdf">complaint</a> against D-Link claiming that D-Link’s “routers and cameras have been vulnerable to attacks that subject consumers’ sensitive personal information and local networks to a significant risk of unauthorized access.”</li>
</ul>
<ul>
<li>On January 9, 2017 the Federal Drug Administration released a <a href="http://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm535843.htm">note</a> about St. Jude Medical stating that its devices had vulnerabilities that, “if exploited, could allow an unauthorized user, i.e., someone other than the patient&#8217;s physician, to remotely access a patient&#8217;s RF-enabled implanted cardiac device.”</li>
</ul>
<ul>
<li>On January 12, 2017 the Department of Commerce released a <a href="https://www.ntia.doc.gov/files/ntia/publications/iot_green_paper_01122017.pdf">Green Paper</a> highlighting the security concerns around IoT. It states that the DDoS attack, “was the most visible and far-reaching example of the potential risks that must be mitigated when considering IoT.”</li>
</ul>
<p>It appears that this the beginning of an activist approach taken by the Government to monitor IoT device manufacturers.  Indeed, the Congressional Internet of Things Working Group white paper states that participants, “grappled with whether or not a solution should rely on industry established standards, agency recommendations, legislation, or a combination of all the above.”</p>
<h4 style="text-align: center;"><a class="fancybox" href="#contact_form_pop"><span style="color: #ff6600;">Click to Subscribe</span></a></h4>
<div class="fancybox-hidden" style="display: none;">
<div id="contact_form_pop" style="text-align: center;">[contact-form-7 id=&#8221;1478&#8243; title=&#8221;Subscribe&#8221;]</div>
</div>
<p>TELEGRID is a designer of <a href="http://telegrid.com/embedded-software-security/">secure embedded systems</a> for the US Military and has developed a <a href="http://telegrid.com/embedded-software-security/">framework</a> to design systems in line with DISA’s Security Technical Implementation Guides (DISA STIGs).  While some commercial manufacturers follow NIST guidelines others ignore security completely.  As Senator Mark Warner, co-founder of the Senate Cybersecurity Caucus <a href="http://www.warner.senate.gov/public/index.cfm/pressreleases?ContentRecord_id=CD1BBB25-83E0-494D-B7E1-1C350A7CFCCA">stated</a>, “Manufacturers today are flooding the market with cheap, insecure devices, with few market incentives to design the products with security in mind, or to provide ongoing support.”</p>
<p>Is the Government going to “incentivize” commercial manufacturers to bake in security?  Will the Government shut certain companies out of the market for selling unsecure IoT devices?  What will be the cost impact to consumers?</p>
<p>These are all very tough questions and it seems the Government is moving quickly to try to answer them.  Are IoT manufacturers paying attention?</p>
<p>&nbsp;</p>
<p>Eric Sharret is Vice President of Business Development at <a href="http://www.telegrid.com/">TELEGRID</a>.  TELEGRID has unique expertise in secure embedded systems, secure authentication, PKI, Multi-Factor Authentication (MFA).</p>
<p>&nbsp;</p>
<h4 style="text-align: center;"><a class="fancybox" href="#contact_form_pop"><span style="color: #ff6600;">Click to Subscribe</span></a></h4>
<div class="fancybox-hidden" style="display: none;">
<div id="contact_form_pop" style="text-align: center;">[contact-form-7 id=&#8221;1478&#8243; title=&#8221;Subscribe&#8221;]</div>
</div>
<p>Disclaimer: The opinions expressed here do not represent those of TELEGRID Technologies, Inc.  The Company will not be held liable for any errors, omissions, or delays in this information or any losses, injuries, or damages arising from its display or use.  All information is provided on an as-is basis.</p>
<p>The post <a rel="nofollow" href="https://telegrid.com/government-activism-and-iot">Government Activism and IoT</a> appeared first on <a rel="nofollow" href="https://telegrid.com">TELEGRID</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
