Live data from Hacker News

Why older tech is sometimes safer from hackers

bbc.com

71–80 of 87 posts

Re: Why older tech is sometimes safer from hackers

#71
post #53

Earlier quoted context omitted.

I'm not seeing why it has to be connected to the internet. Make it a private, air-gapped intranet for all (or most) of the benefits of being "connected", but with no entry point for someone sitting on another continent to turn off the water.

mostly, because setting up a separate network is harder. a virtual network built upon the regular internet is much easier. And yes, mostly done wrong

I’m glad you raised this point. What are some of the better VPNs you’ve seen for secure industrial .

I asked because of books I had read about the bad ones, where unsecured industrial control protocols were exposed wirelessly , or via vpns. And I’ve been curious if any good ones are out there .

Re: Why older tech is sometimes safer from hackers

#73

This seems largely to be about security by obscurity. I was hoping it was gonna be about how our modern practices are making things less secure. For instance, we claim we need to be able to rapidly update clients so that we can patch security vulnerabilities as they are discovered (often without involving the user at all). And there are a lot of companies that have an incentive to push this narrative because they hav…

Right, the sub-headline "security through antiquity" is a nod to both the oft-repeated "security through obscurity," while pointing out the fact that antiquity is sometimes underutilized or undervalued as a security mechanism (even if not tamperproof). Cyber defenses are thus best multi-pronged, which offers the best protection- by maximizing the amount of time an intruder would need to spend to determine what system…

Sure, it can go either way, and so which version to use is a decision to be made by the user, not on their behalf by a vendor.

Consider the CrowdStrike debacle. It wouldn't have been a big deal if they could just boot to yesterday's config because today's config is broken, but neither vendor involved trusts their users enough for that kind of thing, which turned it into a disaster.

Re: Why older tech is sometimes safer from hackers

#74

Earlier quoted context omitted.

Right, the sub-headline "security through antiquity" is a nod to both the oft-repeated "security through obscurity," while pointing out the fact that antiquity is sometimes underutilized or undervalued as a security mechanism (even if not tamperproof). Cyber defenses are thus best multi-pronged, which offers the best protection- by maximizing the amount of time an intruder would need to spend to determine what system…

Sure, it can go either way, and so which version to use is a decision to be made by the user, not on their behalf by a vendor. Consider the CrowdStrike debacle. It wouldn't have been a big deal if they could just boot to yesterday's config because today's config is broken, but neither vendor involved trusts their users enough for that kind of thing, which turned it into a disaster.

Forgot about that. I intially thought you were referring to CloudFlare Captcha's, which Google and Firefox are partnering with: https://www.techtimes.com/articles/318891/20260623/cloudflar...

It's remarkable how much more time one has to wait just to access the same level of information (Cookie Policy, EULAs, etc).

Even with "lighter" weight HTTP Firewall utilities such as Anubis (https://github.com/techaroHQ/anubis), the average user has to pay for other's (DDoSers) misdeeds. Now no one can visit a site without a firewall unless it's static and rate-limited by IP address to avoid crashing a small home server. Some impressive LMDBs might be able to serve up to 100,000 requests per second on a lightweight PC, but then again they could still be knocked offline from a super resourceful organization. I like not putting all my eggs in one basket.

A similar bug could happen with something like Cloudflare- the computer serving up the firewall could have a bug, and it's not programmed to fall back on serving the site without the gatekeeping. If the site is prominent enough, it might routinely face DoS attacks which prevents it from being used. But if it's an uneventful day, it could still manage a lower-tech firewall and still be functional.

Re: Why older tech is sometimes safer from hackers

#75

Sadly, the real lesson we need to learn from Battlestar Galactica is not this. They weren't saved by old software, they were saved by not having critical systems on the network unnecessarily. Our water and power utilities need to re-watch the pilot.

"They weren't saved by old software, they were saved by not having critical systems on the network unnecessarily."

"Modern" software unnecessarily includes and routinely unnecessarily forces network connectivity

Perhaps they were saved by an old mindset

Doing some reading over at textfiles.com can reveal how cautious people were in the 1990's about connecting to the internet

Re: Why older tech is sometimes safer from hackers

#76

Earlier quoted context omitted.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

Because other replies aren't really stating it explicitly, let me add... The water and power utilities are themselves large distributed systems. They need communications between elements just to function properly. They don't exist in a single location where people can go locally manage them in some air-gapped, offline fashion. There is no option of not having a communication network to monitor and manage these geogra…

That explains why they are networked, not why internet access is required.

The problem of secure networking has been solved long ago but there is no incentive for OT solution architects to get it right.

Re: Why older tech is sometimes safer from hackers

#77

Earlier quoted context omitted.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

Because other replies aren't really stating it explicitly, let me add... The water and power utilities are themselves large distributed systems. They need communications between elements just to function properly. They don't exist in a single location where people can go locally manage them in some air-gapped, offline fashion. There is no option of not having a communication network to monitor and manage these geogra…

> You really need to treat it as untrusted and build your security on top with encryption, authentication, authorization, etc

Infrastructure usually has a long lifetime.

Things become much more vulnerable as time rolls on e.g. we should be worried about AI hacking of smart meter firmware (hard to secure and expensive to upgrade).

Today's secure system is tomorrow's insecure system. E.g. https://news.ycombinator.com/item?id=49413320 :

  Finally, I poked at something that wasn’t connected over USB but WiFi instead, the Elgato Key Light Mini. This one turned out to be way more interesting than I expected: it’s the only one with meaningful firmware integrity protection.

  Unfortunately, while that’s an improvement over all of the other devices we’ve looked at, it protects the firmware at exactly one point in time: when an update is happening. It’s not a boot time check enforced by the bootloader or any other kind of secure boot scheme, and the updater happens to be running while everything else in the device is still operating, meaning there’s huge attack surface to try to disable that signature validation. I asked Claude to look for an exploit that might enable this, and it found a doozy

Re: Why older tech is sometimes safer from hackers

#78

Earlier quoted context omitted.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

Sounds like a good application of mesh networks.

Not really practical when the nodes are separated by large distances.

Re: Why older tech is sometimes safer from hackers

#79

Earlier quoted context omitted.

> the real lesson we need to learn from Battlestar Galactica It's the same lesson that we can learn from Star Trek, Star Wars, and all the other self-aggrandising lore that humanity concocts when gazing lovingly in the mirror. There is no greater enemy than greedy, barbaric humanity itself.

They're good lessons, so why insult it? Why mock quality storytelling that makes good impressions on people?

And BSG was some of the best storytelling on TV, ever.

And, when someone mentions Star Trek as a good example of engineering, I can’t do anything other than laugh. Do they really need to pass high power systems behind crewed consoles on the bridge so they can explode dramatically?

Re: Why older tech is sometimes safer from hackers

#80
post #55
post #8

It's incredible how far back the surveillance state goes - GSM mobile phones have an IMEI number that's tied to the handset - and the SIM is tied to the subscriber, and your phone broadcasts imei to neighboring towers constantly. I haven't really gotten really into this, but from what I can tell, anything that has to do with mobile phones is strictly worse in terms of anonimity than Wifi. At least anything that ties…

Doesn't the whole SIM architecture exist so that phones don't have to be trusted? I believe IMEI can be anything in practice, so long that there isn't a blatant duplicate nearby, a bit like Ethernet MAC address. I don't know if it's legal but phone nerds seem to be editing IMEI all the time for non-Apple phones as well, using those leaked vendor tools.

> I believe IMEI can be anything in practice

It used to be that when the telco detects an IMEI change for your SIM, they send a configuration over the air so that you have access to the data network.

Post reply on HN