As cited
Copy frozen at (site build).
ot ics
LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience
Joe FitzPatrick presents research on undocumented connectivity features in imported networked devices, particularly highlighting cellular radios discovered in U.S. highway solar inverters and the widespread reliance on foreign-manufactured hardware by small businesses and infrastructure operators. He argues that current safeguards like import bans and FCC regulations are ineffective at managing supply chain risks and recommends alternatives including right-to-repair policies with offline use guarantees, hardware bills of materials, and comprehensive privacy legislation. The talk examines how devices default to connecting to foreign entities and the practical challenges of using such hardware without establishing external connections.
Why it matters: Security practitioners and infrastructure operators need to understand that critical systems depend on imported hardware with undocumented connectivity features, creating supply chain exposure that import restrictions alone cannot mitigate, and should advocate for transparency mechanisms like hardware bills of materials and offline-capable designs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ot ics
LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience
Joe FitzPatrick presents research on undocumented connectivity features in imported networked devices, particularly highlighting cellular radios discovered in U.S. highway solar inverters and the widespread reliance on foreign-manufactured hardware by small businesses and infrastructure operators. He argues that current safeguards like import bans and FCC regulations are ineffective at managing supply chain risks and recommends alternatives including right-to-repair policies with offline use guarantees, hardware bills of materials, and comprehensive privacy legislation. The talk examines how devices default to connecting to foreign entities and the practical challenges of using such hardware without establishing external connections.
Why it matters: Security practitioners and infrastructure operators need to understand that critical systems depend on imported hardware with undocumented connectivity features, creating supply chain exposure that import restrictions alone cannot mitigate, and should advocate for transparency mechanisms like hardware bills of materials and offline-capable designs.
- Source published
- First seen by Cybersecurity Tracker