‹ BackHN Continuity

Thread

Systems that no one will test

154 points · 84 comments · perone

  1. mikewarot · · focus · HN ↗
    Every since the OPM hack of 2015, I've been apparent to me that my former field of IT administration has lost the plot. Nobody knows what a data diode is, or why you would use one. Systems that should clearly be air-gapped aren't.

    While it's easy to lay this at the feet of AI getting better at hacking. I see it as an primarily an IT issue. We've collectively ignored the lessons of history, and made do with patch jobs over poorly chosen operating systems instead.

    --

    We need air gaps, data diodes, and capability based operating systems. Now that I'm retired, when I have the energy, I'm working on the data diode part.

    This weeks lesson for me, personally, as I try to build an open source data diode, is that the Waveshare RP2350-ETH is a horrible choice for a proxy/data source/sink, as the CH9120 ethernet interface can't do promiscuous mode. It might still be sufficient to build a data diode that can mirror a website, with << $50 component cost. Time will tell.

    1. daveguy · · focus · HN ↗
      I'm curious what function a data diode (unidirectional network) would provide besides sensor data/mirroring/replication. Once you do anything that requires packet confirmation (TCP) you open yourself to OSI layer 4 security risks. Seems like mirroring/replication would need some feedback and then is it just sneakernet restore? Or another diode out from the replication for specific processing? If the same control system has access to both diodes then it's not a unidirectional system anymore. Is a data diode more of a pseudo-unidirection where it is enforced above TCP?

      I completely agree that IT admin could be a lot more secure by design. Combined with better interfaces for responsible configuration.

      1. dezgeg · · focus · HN ↗
        Not to mention how any sort of TLS key exchange is supposed to happen with an unidirectional network.
        1. mikewarot · · focus · HN ↗
          Nothing is supposed to ingress, that's the point. You'd do a TLS exchange with the proxy on the outside of the protected network. Then proceed as normal.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.