I definitely love this article and this spirit. I've accumulated a lot of crap/cheap IoT, I'll probably owning them!
Two things:
- to rain on the parade, the European RED directive makes secure upgrades mandatory for anything connected to the internet (I suspect that's why Elgato Key Light Mini has signed firmwares). So OEMs are now required to prevent you from doing that. (EN18031-1). It even requires that network credentials (WiFi SSID/PSK) to be stored on secure storage (idk if you can pass that requirement without secure boot. I would guess Elgato does?). "secure upgrade" is loosely defined as "integrity and authenticity are valid at the time of installation" so this requirement doesn't forbid us from upgrading our hardware, but the most likely implementation of OEMs does.
- When you want to do that on Android smartphones (please do!): I recommend to go through GSI/Treble route: This way you quickly have an OS that boots. There are a lot of things to fix, but it will be mostly userspace stuff, which will be easier for the agent to work with. Agent will be able to decompile OEM's userspace and compare with AOSP's userspace, and implement the differences. (That's compared to the ""legacy"" or LineageOS official method which are more convoluted, including kernel stuff, and getting just to "it boots" can be complicated).
> for anything connected to the internet
Are you sure? iirc that (for now?) only applies to stuff with wireless connectivity, though maybe I'm misinformed or misremembering.
Which would still be "all IoT, basically", of course.
I have a box of ancient Android and Windows phone handsets which I'm now looking at in a new light.
The CRA that will be active starting december 2027 will also do similar things like RED. Cant ship with fixed static credentials anymore or manufacturer backdoors (unless the user activates them)