4 ms·
Interesting. I've been wondering if we're simply too over-connected at the moment and if there will be a regression back to using different networks that are l
by chasing 9y ago
Interesting.
I've been wondering if we're simply too over-connected at the moment and if there will be a regression back to using different networks that are literally physically disconnected with one other for certain kinds of professional work.
Meaning, the wonder of the internet is that there are now billions of people who have access to your office door. If a guy in Romania decides he wants to jimmy your lock and steal your filing cabinets, there's little stopping him from trying.
Will some offices simply disconnect entirely?
- jff 9y agoGovernments typically already do this for classified information. If there's data that really shouldn't get out to the Internet, don't let anything on that network connect to the Internet. They'll also have procedures for moving things from one network to the another which are intended to avoid inadvertent disclosure and malware infection. Your average company or public radio station won't implement this sort of thing because it's too complicated and costly--or at least that's been the attitude until recently. Maybe we'll start to see the use of small isolated networks for things like the security system they mentioned in the article, or accounting/HR which deal with PII and money. Then you just have to convince the security guy not to plug his personal laptop into the security network, and get the HR employees to stop moving USB sticks back and forth between HR-net and the regular Internet-connected LAN :)
- closeparen 9y agoAttackers certainly hope so: then their work will still be easy, as long as they can get a rogue device into the building. We need to actually write (and purchase) better software.
- PhasmaFelis 9y ago> Attackers certainly hope so They don't. As the parent said, the problem with the internet is that billions of people have access to your office door. Cut the external cable, and it's right back down to the number of people who literally have access to your office door. It's not a good fix, but it absolutely does make random or semi-targeted attacks far less likely, which leaves only someone with a specific bone to pick who is targeting you--and even they'll have more barriers to jump to get there.
- will_hughes 9y ago> We need to actually write (and purchase) better software. Ransomware is not a software problem, this is a human problem. We keep putting up barriers to make it harder for malicious software, but so long as you put a prompt infront of users saying "Whoa, this looks dodgy, are you sure?" they're going to click yes. Even if you make clicking yes more difficult and the warnings more obvious, they'll blame the software for being difficult and run it anyway. The only long term 'solution' to this from a computing perspective is to run only signed applications from trusted publishers on a restricted list which are sandboxed to such a high degree. No scripting beyond very basic building blocks. Effectively an end to general-purpose computing. Every time something like this comes along though, everyone loses their minds.
- mseebach 9y agoThe connection-cat is out of the bag, and the benefits (various kinds of remote collaboration) are too big to put it back (never mind that viruses were perfectly happy to indiscriminately spread on diskettes back in the days). The lesson to be learned is to start taking in-depth cyber security seriously, in this cases of WannaCry and Petya, specifically, vigilant constant patching and upgrading of all systems. Management needs to understand that if they can't afford to staff an IT department to this end, then can't afford to have computers, and IT departments need to understand this stuff, not just trust whatever snake oil salesman invited them to Vegas - especially that software tied to specific versions of other software (Windows and IE are common culprits, but far from the only one) must itself be updated (or else scrapped) the moment the other software receives an update - it must never be allowed to hold back a security update.