USENIX Security2026Top-tier venue
Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air Updates
Huancheng Hu, Christian Doerr
Abstract
Over-the-air (OTA) firmware updates are essential for maintaining IoT device security. However, vendors frequently reduce update frequency and discontinue support before devices reach end of life. Prior work has focused on protocol design and deployment measurements, but has not explained why vendors struggle to sustain long-term update support. Through interviews with 30 IoT vendors and a survey of over 100 practitioners, we examine OTA practices from the vendor perspective. We find that OTA failures stem from fragmented responsibility across multi-tier supply chains, economic constraints that determine support duration independent of security needs, and structural mismatches between component lifecycles and deployment periods. These organizational and economic factors create systematic barriers to security maintenance that technical solutions alone cannot address. Our findings reveal why current approaches to IoT security are insufficient and suggest policy interventions for sustainable update practices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on11
- "It's the Company, the Government, You and I": User Perceptions of Responsibility for Smart Home Privacy and SecurityJulie M. Haney, Yasemin Acar, Susanne FurmanUSENIX Security 2021 · 49 citations
- Security Update Labels: Establishing Economic Incentives for Security Patching of IoT Consumer ProductsPhilipp Morgner, Christoph Mai, Nicole Koschate-Fischer, Felix C. Freiling et al.S&P 2020 · 41 citations
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai et al.USENIX Security 2024 · 33 citations
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu et al.ICSE 2022 · 21 citations
Related papers
- Patchy Performance? Uncovering the Vulnerability Management Practices of IoT-Centric VendorsSandra Rivera Pérez, Michel van Eeten, Carlos Hernandez GañánS&P 2024 · 3 citations
- Missing, Present and Conflicting: A Large Scale Analysis of IoT Update Information in the EU MarketSwaathi Vetrivel, Michel van Eeten, Carlos H. GañánUSENIX Security 2026
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
- Mind the Advisory Gap: Comparing Security Advisory and Patch Management Practices Across IoT and Non-IoT VendorsSandra Rivera Pérez, Mathew Vermeer, Savvas Zannettou, Arwa Al Alsadi et al.CCS 2026
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin et al.S&P 2025
