‹ BackHN Continuity

Thread

Systems that no one will test

154 points · 84 comments · perone

  1. mikewarot · · focus · HN ↗
    Every since the OPM hack of 2015, I've been apparent to me that my former field of IT administration has lost the plot. Nobody knows what a data diode is, or why you would use one. Systems that should clearly be air-gapped aren't.

    While it's easy to lay this at the feet of AI getting better at hacking. I see it as an primarily an IT issue. We've collectively ignored the lessons of history, and made do with patch jobs over poorly chosen operating systems instead.

    --

    We need air gaps, data diodes, and capability based operating systems. Now that I'm retired, when I have the energy, I'm working on the data diode part.

    This weeks lesson for me, personally, as I try to build an open source data diode, is that the Waveshare RP2350-ETH is a horrible choice for a proxy/data source/sink, as the CH9120 ethernet interface can't do promiscuous mode. It might still be sufficient to build a data diode that can mirror a website, with << $50 component cost. Time will tell.

    1. jandrewrogers · · focus · HN ↗
      In the last few years I’ve seen multiple startups describe normal systems running on AWS as “air-gapped” because there is a firewall. LARPers have diluted several terms that had specific meaning in a system isolation and security context to the point that I can no longer trust when people describe their systems using them.

      There are far too many unserious people representing our industry.

      1. andwur · · focus · HN ↗
        Add in the suite of novel attachments of the prefix "cyber" to further muddy the water. The cyberfence will deter the cybertheives from accessing the cybercloud cybersuite we have just cybersold you (down the river on).

        Competence isn't widely valued, obedience and sales figures are. Which wouldn't be so problematic if evolution could run its course and eliminate incompetence naturally, but that's now hard to see coming to pass when we have towering circular supply chains that feed on it.

      2. bunderbunder · · focus · HN ↗
        I suspect that part of the problem here is that PaaS cloud deployments are fundamentally incompatible with some of these security measures. Putting everything into a big slushpool of compute that you dynamically reconfigure at the software layer via an Internet service pretty much precludes the use of true data diodes and air gapping.

        But companies still want to sell products, including to people who are at least nominally concerned about security, and marketing's gonna market.

        1. NichoPaolucci · · focus · HN ↗
          The vast majority of people who decide how safe to make software do not care about how safe their software is.

          Security is expensive, C suite does not understand the benefit (we have been fine for X years!), and the ROI is seemingly 0 (until it is not).

          If most ICs had a say, their system would probably be Fort Knox. I try to instill good security practices around my company, but over and over again the response is… “okay but does this slow us down or speed us up?” or “just fill out the compliance form and make it sound like we do this stuff” (which I refuse to, every time).

          I cannot imagine what the worst of the worst looks like, but security is one of those things where something FINALLY happens and you start to adopt better practices. But until then, who cares!

          1. yencabulator · · focus · HN ↗
            Security is "expensive" in the sense that fossil fuels have been "cheap". If you account for the externalities, lack of security is expensive too.
          2. bunderbunder · · focus · HN ↗
            I'm a little envious. Most ICs I've worked with don't seem to care that much.

            That said I'm pretty sure the main reason is that corporate cybersecurity policies are often such an incomprehensible byzantine mishmash that trying to do the right thing will be rewarded with an all expenses three week stay in a Kafka novel. Once, when I was new at a company and hopelessly naive, I triggered a multi-month delay in deploying a security fix because I made the mistake of filing proper paperwork as per the company policy that I had been so recently trained on. If I had just deployed it, as I later discovered everyone else usually did, I could have saved myself a person-week's worth of struggling with red tape.

      3. podocarp · · focus · HN ↗
        LARP is benign, or at least unintentional, I suspect most are just fraudulent claims. Air gap is easily explained by the two words themselves. You would be daft to think anything on AWS was air gapped.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.