4 ms·
The answer is: no and yes. No, in that you're completely correct that network positioning and exposure does not inherently increase the vulnerability a compute
by Kalium 4y ago
The answer is: no and yes.
No, in that you're completely correct that network positioning and exposure does not inherently increase the vulnerability a computer has. It does not introduce new flaws.
Yes, in that it's not just about vulnerability. A computer turned off may be in theory vulnerable, but in practice not exposed. Exploits happen when vulnerabilities meet opportunities. The more a computer is exposed, the greater the opportunity for exploitation. Making something publicly available, such as it offering up a website, is a pretty dramatic way to increase its exposure. As you might imagine, trying to perform useful work with data coming in over a network provides many more chances to try to exploit something than silently dropping all inbound connections. In extreme cases, you get things like the numerous worms of the 2000s.
It is precisely because of this excellent point you have made that modern networks are designed with layers of security. That there are other vectors is a concern you wisely and rightfully point to, but each vector is concerning and the ease with which any given one can be guarded or exploited is considered.
tl;dr: There's a substantial and very meaningful difference.
- lmm 4y ago> Making something publicly available, such as it offering up a website, is a pretty dramatic way to increase its exposure. As you might imagine, trying to perform useful work with data coming in over a network provides many more chances to try to exploit something than silently dropping all inbound connections. Sure; what matters is, roughly, the extent to which the computer is doing something complex based on data sent by an attacker. The thing is that these days people's pocket computers do so much complex work with user-submitted data, compared to low-level protocol parsing which mostly hasn't changed for decades, that I struggle to believe adding the latter would actually increase attack surface that much. Back in the '90s, where the main way to send data from computer A to computer B was for computer A to open a socket connection to computer B, that thinking made sense, but today almost everyone is consuming a firehose of data from random strangers via, well, almost every app on their phone and every website they visit.