6 ms·
Read the article in full. Timekeeping upgrades and cold-weather functionality are the flashy headlines that are easy to explain to the masses, but there's plen
by jakobson14 3y ago
Read the article in full.
Timekeeping upgrades and cold-weather functionality are the flashy headlines that are easy to explain to the masses, but there's plenty in there about russian cyberattacks too. Russia has been attacking ukrane's infra over the internet for over a decade now.
- sgift 3y agoWell, as usual, the answer is a mix of cost and usability. I don't know if people outside of Germany remember it, but there was a big splash when it came out the NSA hacked Merkels phone. Our chancellor! Why doesn't she have a secure phone?! What do our security authorities even do?! Well, the thing is .. she had one. And it probably wasn't hacked. But the usability of these secure phone is so bad (one common thing is that everyone needs one, which has to be compatible with each other) that she usually just used the phone that her party gave her (she was also the head of the party), which was a normal smartphone and the NSA hacked this one. Same goes for switches etc. There are no real standards, everyone does a bit of their own thing, so you have a bunch of incompatibility. Then you need to configure them special, which takes more time and effort and so on. And, at the end of the day, there's always the matter of cost. Resisting cyber attacks means probably different chips, which are safe according to e.g. https://en.wikipedia.org/wiki/Tempest_(codename) https://en.wikipedia.org/wiki/Tempest_(codename), and the software has to be checked extra and programmed to different standards. Someone has to pay for this, simple as that. Also, if you are not the US, the US will probably want to have a say in whether Cisco can sell you such machines. Same goes for other companies and their countries.
- jakobson14 3y agoYou are vastly over-estimating the competence of both cisco and the russian hackers https://www.csoonline.com/article/656427/over-40000-cisco-devices-exploited-with-the-latest-zero-day-vulnerability.html https://www.csoonline.com/article/656427/over-40000-cisco-de...
- Veserv 3y agoNo, these systems are not secure in any configuration. There are exactly zero large scale commercial IT companies that can deploy systems that can protect against commercially-motivated criminal attackers let alone well-funded intelligence agencies. These companies do not have any super secret secure smartphones, or super secret secure routers, or super secret secure configurations. They are all just plain easily hacked, routinely get hacked, and the government agencies and companies using them get ransacked regularly. Companies such as Cisco, Microsoft, Apple, etc. are just systemically incapable of deploying or even developing secure systems. They have no knowledge or expertise in that field and for their employees to develop that knowledge would take both prioritization and years to decades of learning and experimentation.
- marcus0x62 3y agoThere aren’t any systems that are “secure” or “not secure” in the abstract anywhere in existence. Every system has strengths and weaknesses and is suitable for some purposes and not others, depending on your threat model. It is perfectly possible to use products from each of the vendors you mentioned to build a high assurance system. It depends on what you build, how you configure it, and what threats you are trying to protect against. The non-commercial/open source world isn’t exactly a bastion of impeccable security practice, either. You can counter every Solar Winds or Double Pulsar anecdote with a Heartbleed or Log4J anecdote. But, if you look behind the headlines of every major breach, for every 1 company that got popped by a zero-day, 99 got popped by either social engineering or improper configuration/outdated software. Why do they have poor configs and outdated software? They’re short-staffed and can’t make changes due to fear of outages. That’s a business culture problem, not a technology problem. > Companies such as Cisco, Microsoft, Apple, etc. are just systemically incapable of deploying or even developing secure systems. They have no knowledge or expertise in that field and for their employees to develop that knowledge would take both prioritization and years to decades of learning and experimentation. Each of these vendors employs many widely known and respected security researchers. I’ll grant their product teams can be hit or miss, but to say they have no security expertise at all is just false.
- Veserv 3y ago
- peblos 3y agoThat's true but reading the article in full (again), nowhere does it say what other special features have been added that other companies might require Even in the referenced article from The Register there’s no mention. Lots more context of the types of threats being faced, but no additional features beyond time keeping and better reliability at low temperature.