Every since the OPM hack of 2015, I've been apparent to me that my former field of IT administration has lost the plot. Nobody knows what a data diode is, or why you would use one. Systems that should clearly be air-gapped aren't.
While it's easy to lay this at the feet of AI getting better at hacking. I see it as an primarily an IT issue. We've collectively ignored the lessons of history, and made do with patch jobs over poorly chosen operating systems instead.
--
We need air gaps, data diodes, and capability based operating systems. Now that I'm retired, when I have the energy, I'm working on the data diode part.
This weeks lesson for me, personally, as I try to build an open source data diode, is that the Waveshare RP2350-ETH is a horrible choice for a proxy/data source/sink, as the CH9120 ethernet interface can't do promiscuous mode. It might still be sufficient to build a data diode that can mirror a website, with << $50 component cost. Time will tell.
Air gaps and data diodes are mostly impossible or useless for regular commercial settings. That means your daily servers and VMs. Even tcp requires back and forth. I don't even know if satellites broadcast unidirectionally and just hope base station picks up on it. Surely just shouting into the void is never "communication". It's like receiving FM radio. That's useless for most companies.
And if that is already useless, true air gapping is even more useless. Why would I run something offline in the age of the internet? And bypasses are always put in to make things more convenient, defeating the purpose of having the measure in place in the first place.
Thus there is only a very small segment of industries and people that utilize these things, and with it becoming a niche, it gets forgotten. I won't be surprised that the only users are small part of government and defence.
A more useful thing will just be what homelabbers use - if you're lazy cloudflare tunnels, or if you put in the effort, corporate VPN and DMZ and ACLs and VLANs etc. It's already well established, it's not a lack of knowledge, it's a lack of effort.
Data diodes of some level are semi-common in my experience. An SSH bastion host is a sort of that thing.
I think it works better than you realize, though it is about as painful. Most of these just ban UDP leaving the subnet. TCP is stateful so you can set firewalls to allow inbound connections but not outbound, and you can terminate TCP connections based on bandwidth ratios (ie if you’re sending more than 10% of what you’re downloading then the connection gets killed).
Im largely with you on air gaps in the modern day, with the exception of storage. Backups should be airgapped, but that’s common practice basically anywhere that runs their own servers.
mikewarot · · focus · HN ↗
While it's easy to lay this at the feet of AI getting better at hacking. I see it as an primarily an IT issue. We've collectively ignored the lessons of history, and made do with patch jobs over poorly chosen operating systems instead.
--
We need air gaps, data diodes, and capability based operating systems. Now that I'm retired, when I have the energy, I'm working on the data diode part.
This weeks lesson for me, personally, as I try to build an open source data diode, is that the Waveshare RP2350-ETH is a horrible choice for a proxy/data source/sink, as the CH9120 ethernet interface can't do promiscuous mode. It might still be sufficient to build a data diode that can mirror a website, with << $50 component cost. Time will tell.
podocarp · · focus · HN ↗
Thus there is only a very small segment of industries and people that utilize these things, and with it becoming a niche, it gets forgotten. I won't be surprised that the only users are small part of government and defence.
A more useful thing will just be what homelabbers use - if you're lazy cloudflare tunnels, or if you put in the effort, corporate VPN and DMZ and ACLs and VLANs etc. It's already well established, it's not a lack of knowledge, it's a lack of effort.
everforward · · focus · HN ↗
I think it works better than you realize, though it is about as painful. Most of these just ban UDP leaving the subnet. TCP is stateful so you can set firewalls to allow inbound connections but not outbound, and you can terminate TCP connections based on bandwidth ratios (ie if you’re sending more than 10% of what you’re downloading then the connection gets killed).
Im largely with you on air gaps in the modern day, with the exception of storage. Backups should be airgapped, but that’s common practice basically anywhere that runs their own servers.