7 ms·
Why would "cyberattack" imply non-physical access? Cybersecurity has always had physical components to it. Would you consider an attack using a rubber ducky a c
by joe_name 4y ago
Why would "cyberattack" imply non-physical access? Cybersecurity has always had physical components to it. Would you consider an attack using a rubber ducky a cyberattack?
- QuarterReptile 4y agoThe killer feature of cyberattack is that it exposes you to a global market of criminals. If physical access is required, that presumably cuts back on the market size. In the age of significant ecosystems for stealing devices from network stores to conduct SIM-swaps, complete with intermediate stooges paid to protect the anonymity of higher-ups, it's fair to point out that this split is less clear-cut. Much like network exploitation required mass-market standardization, maybe you could argue that breaking physical security for critical systems isn't quite at that point. On the other hand, if it turns out that everyone follows the same 10-step guide to legal compliance for physical security, we might end up with standardized attacks against that security.
- joe_name 4y agoI was purely responding to the notion that "cyberattack" as a term implies something exclusively non-physical, since it has been used many, many times to refer to techniques that require physical access to the system that is being attacked.
- TheNewsIsHere 4y agoThis kind of disparate interpretation is why I still prefer the term information security (and related, information assurance). It’s much more unambiguously inclusive, and still perfectly descriptive of the field and practice.
- QuarterReptile 4y agoI'm sympathetic to that idea on first glance. Would you consider Stuxnet a cyber attack, though? I think I instinctively would, despite liking your description, yet it required USB drive placement.