• Adalast@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    4 months ago

    Isn’t a true air gap pretty solid though? Aside from someone actually coming into your house and interfacing directly it would be pretty hard to bypass, or am I on Mt. Dunning-Kruger over here this time?

    • MajorHavoc@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      4 months ago

      You are correct.

      The uncomfortable part is what I’ve learned about the challenges to gain physical access.

      Most physical security is equally appalling to most Cybersecurity.

      Edit: Incredibly unfun exercise: pick a physical security device you rely on, personally, and do a YouTube search for “device name break in test”. I’ve rarely been able to find a video more than 3 minutes long, for any product, at all. And the actual breaking is usually mere seconds in the middle bit.

        • bionicjoey@lemmy.ca
          link
          fedilink
          arrow-up
          0
          ·
          4 months ago

          Imagine you wake up in the night, you hear your front door rattling. Someone is trying to break in. “No problem” you think to yourself, “I have a good lock on my front door”. Then you hear the five most terrifying words you could possibly hear in that moment:

          “This is the Lockpicking Lawyer”

        • ColeSloth@discuss.tchncs.de
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          4 months ago

          That guy is an exceptional picker/exploiter, and he isn’t even the best.

          However, I’ve casually picked locks and always have a set of picks with me for the past 20 years. LPL makes me look like a 10 year old kid trying to open a lock with a pair of chopsticks.

          In other words, probably less than 5% of the population have ever picked a lock. Of them, I’m probably better than 90% and I still suck at it. So running across an LPL level skilled person, who’s also a criminal is going to be like a list of names on a single piece of paper. Just buy a lock complicated enough that you can’t scrub it open and everyone will be fine.

    • hperrin@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      4 months ago

      Most online services would struggle to provide their service to their users if all of their servers were air gapped.

    • communism@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      4 months ago

      Aside from someone actually coming into your house and interfacing directly

      If any state entity is in your threat model then this would be major concern. If you’re of any interest to the state, first thing they’ll do is raid your home and seize your electronics. Your threat model shouldn’t depend on assuming an attacker can’t physically access your device (I know you never said an air gap should be the only defence, I’m just saying in general).