Every since the OPM hack of 2015, I've been apparent to me that my former field of IT administration has lost the plot. Nobody knows what a data diode is, or why you would use one. Systems that should clearly be air-gapped aren't.
While it's easy to lay this at the feet of AI getting better at hacking. I see it as an primarily an IT issue. We've collectively ignored the lessons of history, and made do with patch jobs over poorly chosen operating systems instead.
--
We need air gaps, data diodes, and capability based operating systems. Now that I'm retired, when I have the energy, I'm working on the data diode part.
This weeks lesson for me, personally, as I try to build an open source data diode, is that the Waveshare RP2350-ETH is a horrible choice for a proxy/data source/sink, as the CH9120 ethernet interface can't do promiscuous mode. It might still be sufficient to build a data diode that can mirror a website, with << $50 component cost. Time will tell.
> Systems that should clearly be air-gapped aren't.
I'd take systems that were permitted to have filtered egress at this point. The lion's share of my work is in networking, so network segmentation is the "hammer" I pick up first.
Vendors gnash teeth and complain when I ask for their app's dependencies on hosted APIs and off-site resources. In the environments where I'm mandated to maintain FBI CJIS compliance I can still hold vendors accountable and get what I want. It's pretty much a lost battle in every other environment and unfiltered egress to the Internet from servers is just expected.
That's not even to get into the topic of communication flow within an application. >sigh<
So true. I used to work on a cloud-based product that deals with highly sensitive information. On the one hand, we made so much hay about how no sensitive data ever leaves our system.
On the other hand, the whole thing is largely cobbled together from various SaaS products that we use for telemetry, reporting, log management, workflow orchestration, data warehousing, etc. There's no way to ensure nothing sensitive ever gets sent to any of these services. Indeed, some of them are used for the express purpose of processing it.
So Corporate conveniently decided that all of them count as part of our system. So the data still isn't technically leaving it, you see. Even though we don't operate the software or servers, don't have any way of knowing if they in turn are sending data to still more SaaS vendors, can't verify their access and retention policies are properly implemented, etc.
mikewarot · · focus · HN ↗
While it's easy to lay this at the feet of AI getting better at hacking. I see it as an primarily an IT issue. We've collectively ignored the lessons of history, and made do with patch jobs over poorly chosen operating systems instead.
--
We need air gaps, data diodes, and capability based operating systems. Now that I'm retired, when I have the energy, I'm working on the data diode part.
This weeks lesson for me, personally, as I try to build an open source data diode, is that the Waveshare RP2350-ETH is a horrible choice for a proxy/data source/sink, as the CH9120 ethernet interface can't do promiscuous mode. It might still be sufficient to build a data diode that can mirror a website, with << $50 component cost. Time will tell.
EvanAnderson · · focus · HN ↗
I'd take systems that were permitted to have filtered egress at this point. The lion's share of my work is in networking, so network segmentation is the "hammer" I pick up first.
Vendors gnash teeth and complain when I ask for their app's dependencies on hosted APIs and off-site resources. In the environments where I'm mandated to maintain FBI CJIS compliance I can still hold vendors accountable and get what I want. It's pretty much a lost battle in every other environment and unfiltered egress to the Internet from servers is just expected.
That's not even to get into the topic of communication flow within an application. >sigh<
bunderbunder · · focus · HN ↗
On the other hand, the whole thing is largely cobbled together from various SaaS products that we use for telemetry, reporting, log management, workflow orchestration, data warehousing, etc. There's no way to ensure nothing sensitive ever gets sent to any of these services. Indeed, some of them are used for the express purpose of processing it.
So Corporate conveniently decided that all of them count as part of our system. So the data still isn't technically leaving it, you see. Even though we don't operate the software or servers, don't have any way of knowing if they in turn are sending data to still more SaaS vendors, can't verify their access and retention policies are properly implemented, etc.