8 ms·
Air gaps never exist (2011)
- horanimal 11y agoScrolling through this article where WIRED speculates that Craig Wright is the creator of BitCoin. While scrolling I recognized the page design from their screen shot and realized its from this same blog. Yesterday his house was raided and now this blog is down. Did the original poster cba9 know there was speculation the blog author could be BitCoin creator? WIRED article: http://www.wired.com/2015/12/bitcoins-creator-satoshi-nakamoto-is-probably-this-unknown-australian-genius/ http://www.wired.com/2015/12/bitcoins-creator-satoshi-nakamo...
- hackuser 11y ago> the blue cables in gas filled tubes Cat5/6 cables? Why would they be in gas-filled tubes?
- SpikeGronim 11y agoYou can pressurize the gas and put a barometer in the tube in order to detect any breach of the tube. This was used during the cold war and the NSA tapped the communications cable anyway by filling the space around the tube with gas as well. Source: James Bamford's books on the NSA.
- cba9 11y agoGood question - I have no idea. But if I google 'gas-filled tube ethernet', I get a number of hits like http://en.tdk.eu/blob/174150/download/5/smd-surge-arresters-pb.pdf http://en.tdk.eu/blob/174150/download/5/smd-surge-arresters-... and http://www.first-electronic.com/uploadfile/2010989552637708.pdf http://www.first-electronic.com/uploadfile/2010989552637708.... which suggest that these products are sold for networking purposes to prevent surges. Since this is in a military context, I would hazard a guess that this may be some sort of standard hardening requirement to try to protect the datacenter against lightning strikes, EMPs (such as from nuclear strikes), and general accidents. This may sound paranoid, but then again, so do Faraday cages, and it is the military - it's their job.
- dkbrk 11y agoThe wording didn't sound like he was talking about a gas-discharge tube for surge protection. Also, that wouldn't have anything to do with security. I think what may be happening is the ethernet cable runs are in sealed tubes running at either positive or negative pressure so that if someone tries to breach the tube and splice onto the cable it would be detected by a pressure sensor.
- AnimalMuppet 11y agoMy interpretation was that the gas tubes were TEMPEST shielding, but if so, I don't understand how it works...
- undersuit 11y agoOther responder might be more right, but I was thinking about how hard it would be to discreetly tap into a ethernet cable when I have to break glass.
- peterwwillis 11y agohttps://webcache.googleusercontent.com/search?q=cache:wZ0CexrlrU0J:https://cryptome.org/2014/10/cnssam-tempest-1-13.pdf+&cd=14&hl=en&ct=clnk&gl=us https://webcache.googleusercontent.com/search?q=cache:wZ0Cex... http://www.gocsc.com/userfiles/file/ortronics/whitepapergovtv5aug2011final.pdf http://www.gocsc.com/userfiles/file/ortronics/whitepapergovt... https://security.stackexchange.com/questions/10447/is-the-us-military-secret-network-siprnet-physically-or-cryptographicaly-separat https://security.stackexchange.com/questions/10447/is-the-us... I'm honestly not familiar with these kinds of facilities, but with a potential "Collateral Confidential" type cable, one could imagine a gas-filled tube being a countermeasure of some sort.
- jessaustin 11y agoFor instance if the gas were poisonous?
- inopinatus 11y agoMore likely there is a pressure sensor, intended to detect splicing attempts.
- genericresponse 11y agoThat's why you commit to multiple layers and types of defensive and recovery measures. Intelligence, preparation, prevention, prevention, prevention, monitoring, adaptation, more monitoring, effective response, well planned recovery.
- kbenson 11y agoI'm pretty sure you missed another 2-3 prevention layers. Shit's pretty dire after you're past that layer.
- elchief 11y agoPedantically, not a "gap" if there's a network cable going to another network...
- jis 11y agoYears ago I was told by a colleague that he was required to setup an administrative system that was NOT connected the network, but also had to be able to send and receive e-mail. The inherent contradiction was lost on the people giving the orders. So...
- Nadya 11y agoWell he was an expert.. wasn't he? https://www.youtube.com/watch?v=BKorP55Aqvg https://www.youtube.com/watch?v=BKorP55Aqvg (Draw seven perpendicular red lines)
- cpdean 11y ago+1, parenthetical
- jib 11y agoThat sketch annoys me. Sure, marketing/sales/PM/design guys are idiots, whatever. Here are 11 things "I can't do it" can mean: I don't have time I don't want to I don't have anyone who knows how to I want someone else to do it I don't want to maintain it once built I want to work on this other thing Doing it would take away job security for me I think it is beneath me You're not going to use it anyway I don't think it is worth doing I think it is too expensive I think it would be easyish to fill out another 10 reasons for what "can't" really means that are more common than "it is flat out impossible regardless of budget/resources".
- vacri 11y agoHalf of those are perfectly valid responses. "I don't have time" or "I don't know anyone who knows how" or "it is too expensive" - these aren't the passive-aggressive responses that you're implying.
- deleted 11y ago[deleted]
- tlrobinson 11y agoDoesn't "air gapped" imply physical separation? Putting a firewall, even if it's totally locked down, between two networks does not make it "air gapped".
- jimrandomh 11y ago> "How do you think I got the firmware updates? We just made an SSH tunnel over TCP 53 and proxied HTTP to the Sun website." Sounds like the real problem was they didn't have a better mechanism for getting things like that in. If a security system stops people from doing their jobs, they'll poke a hole in it unless you provide a better option.
- AnimalMuppet 11y ago> Sounds like the real problem was they didn't have a better mechanism for getting things like that in. Any mechanism for getting things like that in is a break in the air gap, by definition. (Well, by a strict definition.) But at least a better mechanism would be managed by security policy, not by underlings' need to get their job done. (That is, the security policy would have to take into account the need for updates as well as the potential security implications of importing new executable code from outside.)
- alkonaut 11y agoI thought "air gap" meant a machine or network that is physically separated (these days also without any radio connection) to other machines. How can those not exist?
- cba9 11y agoPerhaps you should read the submission. The larger point here is that even if you set up a network in the first place which is genuinely airgapped, as time passes and systems evolve there will be constant pressure from within and without to re-establish a network connection somewhere in order to make everyone's lives easier and eventually, whether deliberate or inadvertent, a connection will be made (and of course, we know that the NSA has a variety of infiltration and exfiltration methods to get across air gaps, such as dropping flash drives and waiting for an insider to be foolish enough to bring it inside). Believing that an air gap exists or will continue to exist indefinitely is hence setting yourself up for some unpleasant surprises in the future, and encourages weak security designs where the network/system is crunchy on the outside and all delicious and soft and gooey on the inside. (Which is more secure, to have your local WiFi set up with WPA or whatever and have employees telnet into servers, or just go Google-style and have fully encrypted end to end links without requiring any belief in security of the links?)
- vonmoltke 11y ago> Perhaps you should read the submission. The larger point here is that even if you set up a network in the first place which is genuinely airgapped, as time passes and systems evolve there will be constant pressure from within and without to re-establish a network connection somewhere in order to make everyone's lives easier and eventually, whether deliberate or inadvertent, a connection will be made (and of course, we know that the NSA has a variety of infiltration and exfiltration methods to get across air gaps, such as dropping flash drives and waiting for an insider to be foolish enough to bring it inside). The article is not well written, and I personally had to parse it several times to figure out what he was trying to say. I'm still not even sure if this is the correct interpretation. > Believing that an air gap exists or will continue to exist indefinitely is hence setting yourself up for some unpleasant surprises in the future, and encourages weak security designs where the network/system is crunchy on the outside and all delicious and soft and gooey on the inside. (Which is more secure, to have your local WiFi set up with WPA or whatever and have employees telnet into servers, or just go Google-style and have fully encrypted end to end links without requiring any belief in security of the links?) That depends on your physical security. A facility like the one he described should have had regular security audits to verify that no hard lines were placed where they should not be. All hard lines and ports should have been marked with identifying information. Nobody should have been able to keep a line open for any significant period of time unless these processes broke down.
- munin 11y ago> I have seem so many kludges connecting SIPPER and NIPPER networks I don't know how much I trust someone who can't even get the acronym for SIPR and NIPR right (https://en.wikipedia.org/wiki/SIPRNet https://en.wikipedia.org/wiki/SIPRNet https://en.wikipedia.org/wiki/NIPRNet https://en.wikipedia.org/wiki/NIPRNet)
- _wldu 11y agoAir gaps can also be bridged by using radio or sound waves. There could be a bunch on non-networked computers in a secure lab all talking to each other. This assumes trojaned hardware and/or operating system software in the systems that can send and receive data and commands. Finally, technology such as Morse Code is still useful in these scenarios. Dits and dahs. Zeros and ones. That's all you need to be able to send and recv data. http://www.jocm.us/index.php?m=content&c=index&a=show&catid=124&id=600 http://www.jocm.us/index.php?m=content&c=index&a=show&catid=... http://www.wired.com/wp-content/uploads/2014/11/air-hopper-malware-final-e-141029143252-conversion-gate01.pdf http://www.wired.com/wp-content/uploads/2014/11/air-hopper-m...
- wallaceowen21 11y agoBack in the early days of Ethernet there were fiber to AUI widgets, that used 2 multimode fibers, one for TX, one for RX. We used these on classified systems with ony RX connected - we could send data in to these systems over UDP, and it was truly a one-way path.