Back to the Future

Part 3: Back to the Future

(Did you miss Part 1 and/or 2? Click here for part 1 and here for part 2 to catch up!)

I apologize for this, but I have to jump back to the beginning again. You see, the Internet was designed during the cold war, and a prime driver was the ability to sustain communication in the event of a nuclear attack. Back then, communication was usually point-to-point. DARPA and many smart people gave us “packet-switched networks.” It meant that a piece of data could flow through different paths and reassemble on the receiving side. This meant if communication hubs were taken out of service between you and where you were trying to communicate, due to, say, a nuclear bomb being dropped, your packets could now travel a different route and your Twitter post about the latte you purchased this morning would stick.

The lesson here is age-old; bolting on security after the fact is always more costly, time-consuming and less effective than baking it in from the start. The first email servers on the Internet were open relay by design. That meant anyone could send email through your email server to someone else. After all, the idea was sustained communications, so if my email server went down, why not use one of the other available email servers?

Unfortunately, as with many well-intentioned plans, it fails to account for bad people. Soon spam became a well-known term to define something other than the delicious food of previous association. Domain Name Services (which translates the web sites we type into IP addresses) is not secure. It has suffered from numerous attacks. The weakness of this core protocol has been known for a very long time and a secure DNS (DNSSEC) was proposed in 2005 via RFC 4033. You can go here to see how that has been going.

In general, the US Root DNS servers were operational in 2010. DNSSEC does not in any way totally fix DNS, as in recent months there has been a rash of DNS Amplification Denial of Services attacks. DNS is just one small area of vulnerability; the list of protocol weaknesses and associated attack vectors is legion.

In short, what we have put in place are insecure computing devices connected together using insecure protocols over a fabric connected to support some of our most critical dependencies and let anyone in the world – good or bad – have access to them.

I remember watching a video with one of the engineers that worked on the initial Internet design and protocols. He stated that, “If you would have told us that we would be putting critical infrastructure on a public network, we would have just laughed – that will never happen.” There was a completely different mindset back in those days. Business standards existed beyond the “want of the moment.” Thought was given to business risk, mostly driven top-down. Today, one could argue business risk is driven bottom-up and in the Information Security world, I would posit that 80-90% of InfoSec programs are driven in exactly that same direction.

About the Author

Martin Zinaich is the information security officer for the City of Tampa’s Technology and Innovation department. The insights in this article were shared at a Wisegate member event, where senior IT professionals discussed these pressing security issues.

Featured

  • Hot AI Chatbot DeepSeek Comes Loaded With Privacy, Data Security Concerns

    In the artificial intelligence race powered by American companies like OpenAI and Google, a new Chinese rival is upending the market—even with the possible privacy and data security issues. Read Now

  • Survey: CISOs Increasing Budgets for Crisis Simulations in 2025

    Today, Cyber Performance Center, Hack The Box, released new data showcasing the perspectives of Chief Information Security Officers (CISOs) towards cyber preparedness in 2025. In the aftermath of 2024’s high-profile cybersecurity incidents, including NHS, CrowdStrike, TfL, 23andMe, and Cencora, CISOs are reassessing their organization’s readiness to manage a potential “chaos” of a full-scale cyber crisis. Read Now

  • Human Risk Management: A Silver Bullet for Effective Security Awareness Training

    You would think in a world where cybersecurity breaches are frequently in the news, that it wouldn’t require much to convince CEOs and C-suite leaders of the value and importance of security awareness training (SAT). Unfortunately, that’s not always the case. Read Now

  • Windsor Port Authority Strengthens U.S.-Canada Border Waterway Safety, Security

    Windsor Port Authority, one of just 17 national ports created by the 1999 Canada Marine Act, has enhanced waterway safety and security across its jurisdiction on the U.S.-Canada border with state-of-the-art cameras from Axis Communications. These cameras, combined with radar solutions from Accipiter Radar Technologies Inc., provide the port with the visibility needed to prevent collisions, better detect illegal activity, and save lives along the river. Read Now

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.