Remix.run Logo
27183 4 hours ago

You can't have both secure infrastructure and Internet exposed infrastructure. I don't know if I'd frame it as incompetence, but it does seem firmly outside the capabilities of current engineering practice.

If you need a computer system to be actually secure, rule #0 is absolutely ensure it cannot receive unauthorized inputs of any kind (airgapped, big Faraday cage, JB Weld all the ports, big scary guys with guns, redundant locks, blast doors, etc). Otherwise you've lost against any sufficiently motivated adversary.

Kim_Bruning 4 hours ago | parent | next [-]

Right, enclose it in meters thick reinforced concrete walls and let no one near it.

While that works for Chernobyl, if you have a real world systems you might want somewhat more practical access.

Of course exposing industrial hardware directly on the internet is the other extreme, and you get what you're asking for.

Do something in between, if you even just apply normal network security you'll be ahead of the pack.

Problem is, a lot of these systems are not built by IT people. While they have a lot of quite admirable skills, it's just not their primary job, and thus they tend to lack the necessary paranoia at times.

27183 4 hours ago | parent [-]

> normal network security

The problem is there's no good way to actually enforce this. Every organization has their own idea of what is "good enough". The NSA has some pretty good advice[0]. But as far as I know there's no written-in-stone engineering standard organizations have to meet, just "best practices". If the building inspector finds fault with the construction of your facility, it gets evacuated and shut down until the defect is remedied. There's no inspector for your network security. That's the problem.

[0] https://media.defense.gov/2022/Jun/15/2003018261/-1/-1/0/CTR...

4 hours ago | parent | prev [-]
[deleted]