3 ms·
My use for an air-gapped machine is for a personal CA (certificate authority). I'm using a RPi2 for this (no wifi). Proceedure: 1. Download all the software ne
by rthille 10y ago
My use for an air-gapped machine is for a personal CA (certificate authority). I'm using a RPi2 for this (no wifi).
Proceedure:
1. Download all the software needed for the CA (possibly getting compromised packages).
2. Disconnect from the network, setup the CA.
3. Setup an intermediate CA on a YubiKey.
4. Turn off RPi2 and store micro-SD card with CA secrets in a safe.
5. If CA needed in the future, only plug in "CA" micro-SD when RPi is not connected to the network.
6. Since the CA is never in a machine connected to a network, even if the RPi2 is compromised (assuming it's not the secret generation) the secrets aren't leaked.
However, with this attack, or a similar one, maybe my laptop is also compromised and the RPi2 can exfiltrate to the laptop (which is nearby and connected to the network). Perhaps via toggling the caps-lock LED on the keyboard (at a high rate with low duty cycle so it's invisible to the eye) or via the monitor cable.
Security is "fun"