In this intriguing book, the author introduces the topic of Internet-Plus and the concept of Security by Design.
Computer Security should not be an "at the end" kind of experience -- it needs to be designed-in" from the beginning.
Here are the author's top ten recommendations around improving security and privacy of our devices.
- Be transparent aout how a product's security works, what it secures against, for how long, etc.
- Make the software patchable and to authenticate patches as valid. This is a crucial aspect for embedded devices.
- Test pre-production for not only "function" but also "security".
- Enable secure "default" operation. A product should not require that security features be turned on.
- Fail predictably and safely -- i.e. without harm to anyone.
- Use standard protocols rather than custom or proprietary implementations which often are error-prone.
- Avoid known vulnerabilities -- do not ship a product with a known flaw.
- Preserve offline functionality. If a device loses network connectivity, it should continue to operate in a safe manner.
- Encrypt and Authenticate data exchanges, always.
- Support responsible security research by third parties.