At that company, before the acquisition, I took that firmware manager from a prototype to a tool that updated devices en-masse. It was hard, un-glamorous work. Every device had to be managed individually, sometimes forcibly, to get it onto the firmware we chose.
Even then, one thought kept nagging me: the whole business was exposed to anyone with enough funding who decided to standardize the problem away. One open protocol for firmware updates, password rotation and device management, on any device, and years of our custom work becomes a commodity.
I tried to push for that standardization feature at that time to get ahead of that risk. It never caught on within the company, and the resources were never allocated at that time. the idea was shelved indefinitely.
When I first came across AT Protocol, I saw more than social media in it. Frankly, I saw use cases that matter a good deal more. A Personal Data Server can sign and distribute data on public or private networks, and the content is self-validating. That is most of what a firmware update channel needed, and it drastically reduced the problem space for developing this project.
We built a prototype, and we're open sourcing it:
https://github.com/ListeningPost/open-firmware-manager
What it does today:
- Publishes firmware, packages, Docker images, and potentially similar content as content-addressed releases on a PDS you can host yourself, optionally signed with the manufacturer's key. - Verifies every byte on the device or host before anything is applied, so you don't have to trust whoever serves the download. - Runs a full walk-through with a sidecar agent that updates Docker images, and declines to when a release fails the criteria you set: a trusted publisher, a bad signature, a failed CI gate, a downgrade, or something else!
It is an early prototype. It hasn't had an external security review, and the README is blunt about what isn't built yet.
If this sucks* send me your most clever hate mail below. Thanks.
*If it sucks particularly bad, do the world's best possible revenge and build a better version of this tool. IOT is a damn mess and we can fix it together.
1. a damn identity server that goes on everything since some devices lose connectivity, change their IP etc. 2. a protocol for password resets over the network by a trusted host 2. a protocol for firmware updates over the network by a trusted host. 3. a way to manage device settings pages remotely over the network via API only.