4 ms·
I worked in a factory that produces critical parts for both the nuclear industry and the silicon fabs. Their main software stack is old dos software with a win9
by cuboidGoat 8y ago
I worked in a factory that produces critical parts for both the nuclear industry and the silicon fabs. Their main software stack is old dos software with a win95 front end bolted on running in compatibility mode with an integrated database that went obsolete in the early '90s.
I asked them what protections they took against hacking, and they told me that nobody would be interested in what they do, so they didn't have to spend any money on protecting themselves.
- jakelarkin 8y agosecurity by obsolescence is a thing too
- FactolSarin 8y agoIt's actually one of the security layers for America's nuclear arsenal https://www.businessinsider.com/hacker-us-nukes-report-2016-5 https://www.businessinsider.com/hacker-us-nukes-report-2016-...
- cuboidGoat 8y agoSecurity by obsolescence isn't the thing where you just dump old code on internet connected computers and steadfastly refuse to do any form of technical assessment other then "Does it run?", due to the assumption that nobody would be interested in screwing you over, though.
- FactolSarin 8y agoWas that computer connected to the Internet? If not, then no problem.
- EvanAnderson 8y agoDefine "the Internet". Do contractors plug laptops into the network with these "air gapped" computers? How about IoT devices? Printers? I can't recall who said it, but a venerable infosec practitioner once said "Think of an air gap as a very high-latency connection."
- caymanjim 8y agoAir gapping is often "good enough" protection for all but the most sensitive and desirable targets, even if people plug things into them all the time. An air-gapped PC might get a virus that way, which could be damaging in some way, but it's not something that most companies need to worry about. A counter-example is something like Stuxnet; that likely leapt an air gap, but it was exquisitely targeted for that scenario. I'd worry about this as a nuclear component manufacturer.
- FactolSarin 8y agoStuxnet was spread via a USB stick. You know what doesn't have a USB port? A computer from 1995. :) An ancient piece of air-gaped hardware is pretty bulletproof. I bet the NSA would have more trouble hacking it than a fully up to date install of <modern OS> that is on the Internet. It's very possible the biggest threat vector is leaving the door unlocked.
- 3pt14159 8y agoEven though I'm largely against air gaps as a defensive measure, there is something to this. Though I think the breadth of the problem isn't properly appreciated. It's too dimensional. There are too many unforeseen interactions and complications with computers and the humans in the organizations that run them. Even leaving aside moles[0] people trust to easily and often have interests that are odds with their organization. [0] Which, why should we? The world has moles.
- cuboidGoat 8y agoYes, of course it was. Anything with a network port was plugged into the lan, which was plugged into the free router that came with the business broadband package. Which was also the only firewall and it was still on factory defaults other than the wireless password. As far as I can tell this is more or less standard business practice in the small to medium enterprise sector here, which is to say, the vast majority of specialist engineering companies in the UK.
- darpa_escapee 8y agoStuxnet.