5 ms·
How would anything you recommend protect you against an attacker who could (for example) have 3G transmitting keyloggers installed in your last shipment of lapt
by bashinator 12y ago
How would anything you recommend protect you against an attacker who could (for example) have 3G transmitting keyloggers installed in your last shipment of laptops?
- atmosx 12y agoYou choose your hardware carefully and if paranoid enough, you perform statefull packet inspection on your OpenBSD transparent router to know possibly what's the reason/content for every connection. Once you tag those that are standard, you start narrowing things. Again policy is what matters, if you allow torrents you are making your job extremely difficult. I know easier said than done. Writing firewall rules/ confug reporting tools for every computer in the internal part of a network is hard too, that's why almost no one does it.
- bashinator 12y ago3G keyloggers. Data egress is completely bypassing your network. (There are pwnie express boxes that include a 3G data link for bypassing target networks when sending results back.) I guess you could add physical scans for unauthorized radio transmitters to your security routine. Opsec is hard.
- atmosx 12y agoSure, but that's a physical attack: You need someone to install the 3G Keylogger to your machinery. I was talking on a keyboard-only level, but even that can be largely mitigate with proper policies IMHO. That said, an insider is an achilles heel for every security scheme out there (e.g. Snowden).