Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Firewalls in high security environments aren't just port/protocol based. You lock everything down - source ip/port and destination ip/port. You should know where it is coming from and where it is going to.

Navy ships don't upload via Dropbox.



Certainly true, since Dropbox doesn't work on Windows XP anymore.


In the parent I described a system which would be able to communicate through those restrictions to another compromised host (remember we're assuming everything is compromised for the sake of this article, which actually seems like a good assumption now).


Networks where security is taken seriously implement data diodes, and this attack vector is mitigated.


> remember we're assuming everything is compromised

I think Bloomberg (and all related) web servers displaying the article are compromised and they're leaving out critical facts the point the finger elsewhere.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: