Accompanying the article is a stock picture of an olive Olivetti Lettera 32. It's got its cover missing, poor thing, and it appears to have had a photoshop job to remove the label at the front. It looks like this is an Italian QZERTY version, which makes sense because the olive green is rare with other keyboard layouts. Millions were sold. They're nice machines - I have one with a cursive font that gives me a headach…
Kremlin security agencies buying typewriters "to avoid leaks"
21–30 of 35 posts
Re: Kremlin security agencies buying typewriters "to avoid leaks"
#22Re: Kremlin security agencies buying typewriters "to avoid leaks"
#23Re: Kremlin security agencies buying typewriters "to avoid leaks"
#24Re: Kremlin security agencies buying typewriters "to avoid leaks"
#25Earlier quoted context omitted.
there is significant time overhead and increased visibility/decreased quality(in terms of usability) in this method. a 100 page document would take a long time to photograph, but not as long to transfer, and you'd be less visible.
Not only that but you need to be physically present to take photos, that isn't the case where hacking is concerned.
Re: Kremlin security agencies buying typewriters "to avoid leaks"
#26I worked for a short while in a national lab. They used to call this "air-gap" security. i.e., there would be computers which would have no internet connection and no usb/harddrive inputs etc. If they needed data in there, they would have one person read data from one computer and type it into the secure one. Essentially there would be a literal air-gap between the secure computer and the non-secure ones.
The modern way of doing this is to have something called a 'sheep dip' station. This is an unconnected system that's used to check the contents of any import/export. The idea is that you cryptographically sign the material you want to import/export, burn it to write once media, pop it in the sheep dip box, confirm it's all hunky dory and if it is, import/export to/from the network. The media is then archived so it ca…
Then again, I suppose in that case you could have malware that detects what system it's on and decides not to activate on the dip station :)
Re: Kremlin security agencies buying typewriters "to avoid leaks"
#27Re: Kremlin security agencies buying typewriters "to avoid leaks"
#28Earlier quoted context omitted.
Collect cellphones at door. Put them in steel cabinet. When workers leave, they can get the phones on the way out.
Because no person has two cellphones.
Re: Kremlin security agencies buying typewriters "to avoid leaks"
#29Accompanying the article is a stock picture of an olive Olivetti Lettera 32. It's got its cover missing, poor thing, and it appears to have had a photoshop job to remove the label at the front. It looks like this is an Italian QZERTY version, which makes sense because the olive green is rare with other keyboard layouts. Millions were sold. They're nice machines - I have one with a cursive font that gives me a headach…
It had a sister; unfortunately, we recently lost her to a flood. I would have preferred a rescue/rehabilitation, but it wasn't my call -- and, past a point, there's only so much you can hang onto.
Kind of negating my original point... But, that's nostalgia.
I don't want to live on one, but a good typewriter is a bit of a monument that deserves continuing respect. And sometimes, the quality of the engineering -- and design -- is timeless.
Re: Kremlin security agencies buying typewriters "to avoid leaks"
#30Earlier quoted context omitted.
The modern way of doing this is to have something called a 'sheep dip' station. This is an unconnected system that's used to check the contents of any import/export. The idea is that you cryptographically sign the material you want to import/export, burn it to write once media, pop it in the sheep dip box, confirm it's all hunky dory and if it is, import/export to/from the network. The media is then archived so it ca…
This is fascinating! Let me understand one thing: The sheep dip station is network connected to the sealed computer? Doesn't that still pose a risk and violate the principle? It seems you'd be better off checking at the dip station and then reimporting on the sealed computer. Then again, I suppose in that case you could have malware that detects what system it's on and decides not to activate on the dip station :)
> unconnected system
I understood this to be a literal description.
I presume that this sheep dip station is maintained and updated, from time to time. However, that would be done using controlled, vetted media. And, if something goes wrong there, it has to been in the nature of something that will cause the masking of problems existing on the written/finalized media that the sheep dip station is in turn vetting. (Unless it's something that can "un-finalize" the vetting media and further write to it.)
Or is the sheep dip station periodically connected while it is itself maintained/updated? That I could see presenting problems.
In any event, I read this to mean in particular that the sheep dip station is not networked with the air gapped system.