Earlier quoted context omitted.
But its also unacceptable to make an Internet connected device with a static proprietary OS on it. We have a dozen known vulnerabilities in common software packages every year, and these devices are using IP for communicating often confidential information. It can be disastrous for your toaster to be hijacked, especially if it can be remoted no and burn your house down. This whole IoT disaster should have been predic…
I agree completely. But how likely is that to happen? Let's face it, companies that make 'smart' devices will likely want to monetize on customers whose software is outdated (in functionality, not security) and who want to upgrade because of that. I don't think they'd have a motive to do anything other than proprietary, non-maintainable software. The only solution I could think of from a security standpoint would be…
How much vendors are willing to use something like this remains to be seen. Personally I resist buying things that I think will have a poor security update record. I'd like to see more pressure on vendors to do the right thing here, especially because there is at least one reasonable solution available.
Disclosure: I work for Canonical, but am not associated with the IoT work in Ubuntu.