Securing a Smart Dog Collar: Secure Elements, Key Lifecycles, and Why TLS Isn't Enough on 5 Microamp
The key that was never really yours
Years ago I shipped a battery-powered NB-IoT pet collar and wrote about the firmware side of it: FreeRTOS, an STM32L4, safe OTA, and the small humiliations of making a radio live inside a dog's daily schedule. That article was about keeping the device alive. This one is about a question I started asking myself after the collar was already in the field, and it kept me up more than any battery budget ever did.
The collar authenticated to the backend the way most small devices do: a symmetric key, provisioned at manufacture, stored on the device, stored on the server. And one evening, while re-reading my own provisioning code, I noticed the shape of what I had built. The key sat in flash. Flash can be dumped. Debug interfaces are pins on the board unless you burn the fuses, and burning them makes...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE