logoalt Hacker News

27183yesterday at 10:11 PM2 repliesview on HN

You can't have both secure infrastructure and Internet exposed infrastructure. I don't know if I'd frame it as incompetence, but it does seem firmly outside the capabilities of current engineering practice.

If you need a computer system to be actually secure, rule #0 is absolutely ensure it cannot receive unauthorized inputs of any kind (airgapped, big Faraday cage, JB Weld all the ports, big scary guys with guns, redundant locks, blast doors, etc). Otherwise you've lost against any sufficiently motivated adversary.


Replies

Kim_Bruningyesterday at 10:19 PM

Right, enclose it in meters thick reinforced concrete walls and let no one near it.

While that works for Chernobyl, if you have a real world systems you might want somewhat more practical access.

Of course exposing industrial hardware directly on the internet is the other extreme, and you get what you're asking for.

Do something in between, if you even just apply normal network security you'll be ahead of the pack.

Problem is, a lot of these systems are not built by IT people. While they have a lot of quite admirable skills, it's just not their primary job, and thus they tend to lack the necessary paranoia at times.

show 1 reply