‹ BackHN Continuity

Thread

Systems that no one will test

154 points · 84 comments · perone

  1. mikewarot · · focus · HN ↗
    Every since the OPM hack of 2015, I've been apparent to me that my former field of IT administration has lost the plot. Nobody knows what a data diode is, or why you would use one. Systems that should clearly be air-gapped aren't.

    While it's easy to lay this at the feet of AI getting better at hacking. I see it as an primarily an IT issue. We've collectively ignored the lessons of history, and made do with patch jobs over poorly chosen operating systems instead.

    --

    We need air gaps, data diodes, and capability based operating systems. Now that I'm retired, when I have the energy, I'm working on the data diode part.

    This weeks lesson for me, personally, as I try to build an open source data diode, is that the Waveshare RP2350-ETH is a horrible choice for a proxy/data source/sink, as the CH9120 ethernet interface can't do promiscuous mode. It might still be sufficient to build a data diode that can mirror a website, with << $50 component cost. Time will tell.

    1. jandrewrogers · · focus · HN ↗
      In the last few years I’ve seen multiple startups describe normal systems running on AWS as “air-gapped” because there is a firewall. LARPers have diluted several terms that had specific meaning in a system isolation and security context to the point that I can no longer trust when people describe their systems using them.

      There are far too many unserious people representing our industry.

      1. bunderbunder · · focus · HN ↗
        I suspect that part of the problem here is that PaaS cloud deployments are fundamentally incompatible with some of these security measures. Putting everything into a big slushpool of compute that you dynamically reconfigure at the software layer via an Internet service pretty much precludes the use of true data diodes and air gapping.

        But companies still want to sell products, including to people who are at least nominally concerned about security, and marketing's gonna market.

        1. NichoPaolucci · · focus · HN ↗
          The vast majority of people who decide how safe to make software do not care about how safe their software is.

          Security is expensive, C suite does not understand the benefit (we have been fine for X years!), and the ROI is seemingly 0 (until it is not).

          If most ICs had a say, their system would probably be Fort Knox. I try to instill good security practices around my company, but over and over again the response is… “okay but does this slow us down or speed us up?” or “just fill out the compliance form and make it sound like we do this stuff” (which I refuse to, every time).

          I cannot imagine what the worst of the worst looks like, but security is one of those things where something FINALLY happens and you start to adopt better practices. But until then, who cares!

          1. yencabulator · · focus · HN ↗
            Security is "expensive" in the sense that fossil fuels have been "cheap". If you account for the externalities, lack of security is expensive too.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.