Firewall Wizards mailing list archives
Re: Air gap technologies
From: daw () mozart cs berkeley edu (David Wagner)
Date: 26 Jan 2001 03:08:43 GMT
Elad Baron wrote:
And again, none of these protocols were designed with security in mind (for example, SCSI protocol relies on the "honesty" of the bus members when doing its negotiation - the lower SCSI ID member should stop using the bus after it loses to a higher number).
Can you clarify your threat model? Are you trying to defend against attackers with physical access to the SCSI bus? (seems unlikely) Or, just trying to prevent the external host from being able to attack the internal host's protocol stack in case the external host gets compromised? (seems more likely, but still highly unlikely that this is dominant failure mode for a firewall) In either case, what's wrong with just using a serial cable? It seems just as good for all security purposes that I can think of. I'd love to be enlightened, though, if I went wrong somewhere. _______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://www.nfr.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: Air gap technologies, (continued)
- Re: Air gap technologies Eilon Gishri (Jan 24)
- RE: Air gap technologies Marcus J. Ranum (Jan 25)
- Re: Air gap technologies Aleph One (Jan 25)
- RE: Re: Air gap technologies Predrag Zivic (Jan 24)
- RE: Air gap technologies Bill Stout (Jan 25)
- RE: Air gap technologies Elad Baron (Jan 25)
- Re: Air gap technologies Avi Rubin (Jan 25)
- RE: Air gap technologies Frank Knobbe (Jan 25)
- RE: Air gap technologies daN. (Jan 25)
- RE: Air gap technologies Elad Baron (Jan 25)
- Re: Air gap technologies David Wagner (Jan 25)
- Re: Air gap technologies Adam Shostack (Jan 26)
- Re: Air gap technologies Aleph One (Jan 25)
- Re: Air gap technologies David Wagner (Jan 25)
- RE: Air gap technologies Bill_Royds (Jan 25)
- RE: Air gap technologies Elad Baron (Jan 25)
- Re: Air gap technologies Aleph One (Jan 25)
- Re: Air gap technologies Aleph One (Jan 25)
- Re: Air gap technologies Aleph One (Jan 25)