Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It’s not obvious to me why engineering and accounting should need to transfer any data and back forth beyond basic email communications.


Email seems simple to you, but in fact it's an incredibly complicated protocol, so software treating it is likely to have many (exploitable) bugs. Also, there are attachments. Those are the classical way to hack many places.

Even if you got all of the issues caused by e-mails figured out, somehow you have to transfer them from one network to another. You'll either have to poke holes into your firewall or use USB sticks.

My point is: even in airgapped networks you usually want to exchange some data. The moment you want to exchange data, you have a path where a virus can be smuggled in.


Single sign on etc: usually there's a resource that everyone in the company needs to use. Besides, email is a major infection vector.


I mean email is a vector too. And remember that 0 day no touch iOS exploit that was discovered by project zero? Surely that could have been vector too. After that use a compromised iOS device to do something similar by exploiting some bluetooth vulnerability.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: