Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I imagine this is to target old manufacturing or scada equipment. If you want to sabotage an industrial target then you're going to be seeing a lot of legacy equipment. /r/sysadmin posts from manufacturing and industrial sysadmins are fascinating as they are scary.

Also it may reveal that the target is using old methods for security purposes. Imagine an office where no one has any sort of user accessible networking (ethernet would be just for updates, security, auditing, etc), just a 1980s style set of workstations each accessing things from the floppy drive. If you want to see a file on a certain topic then you'd walk up the librarian who would check your ID and give you the disk. If you wanted to sneak that data out, then you'd have to physically copy the disk or steal it. The latter being much more risky as the librarian knows you had it last. Perhaps there's enough empty space in the floppy case to put in some kind of tracker as well.

You also don't need to worry about USB vulnerabilities with USB sticks nor the worry that someone will show up with the right cable, mount the USB drive to their phone, and copy the data. Nor the write limits and versioning exploits on writable CD media. You could also set off a EM burst that'll wipe a room full of floppies in a millisecond if need be.

If you deal with text data files then the 3.5" space limitation is not an issue, what's the average word file size? 80k? Imagine an intelligence service that keeps its state secrets like this. You'd be hard pressed to hack them. This isn't a hypothetical as we have data that suggests some intelligence services have moved to typewriters to avoid hacking[1]. Seems to me, I'd much rather just use 3.5" disks on a linux box with no networking attached to a printer than a typewriter. Even spies can't live without WYSIWG editors. Perhaps the great typewriter experiment has failed and sneakernet is a better compromise between security and convenience.

[1]

https://www.theguardian.com/world/2013/jul/11/russia-reverts...

https://www.theguardian.com/world/2014/jul/15/germany-typewr...

edit (as it wont let me reply) in regards to exploits here:

Your attack surface has now changed from "Anastasia in accounting clicking on resume.js" to now dragging TEMPEST equipment into the basement of the Lubyanka building undetected.

Or a mole now trying to sneak in a bulky 3.5" copy device instead of right-click > encrypt > email.



Typerwriters won't help. Soviets could bug them in 1976: https://arstechnica.com/security/2015/10/how-soviets-used-ib... I bet that now, CIA can do it much more stealthily.

And I also think that it is pretty hard to make these 1980's workstations secure -- that old DOS software was full of vulnerabilities, and it has no modern protections at all (usernames, kernel mode). I remember back at high school we had "1980s style set of workstations each accessing things from the floppy drive." and they were full of viruses. And once you have your code on target computers, you can exfiltrate data pretty easily (emit right patterns with pc speaker, memory access, display, etc..)


All of those vulnerabilities are pretty useless unless you can get the data out easily, the CIA solution seems better


You could definitely put an RF tag on a floppy and then have detectors at all exits like a retail store does with merchandise. Hell, you could use a "mantrap" like banks do so that you automatically catch the person on their way out.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: