Some questions regarding the internet and the problem of hacking.

I wonder to what extent hacking problems via the internet could be suppressed if we had a bit less connectivity or a bit less compatibility? Who decreed that critical systems like the power grid or banking or corporate enterprise systems be connected and compatible in a way that can be entered from outside? Why not trade in some convenience for greater security? Another approach would be to have intranet systems that are incompatible with internet protocols. Who is calling the shots here? Cisco? Microsoft? Fresh MBA’s wanting to implement the latest thinking from B-School?

A separate, air-gapped and incompatible system for intranet use in key infrastructure might be quite effective in blocking access to control systems from the outside. An electronically isolated conventional internet system would allow the public or vendor access to a store front site.

I’m sure there is ways a clever intruder who can cause some kind of trouble in this scenario, such as the intrusion of Stuxnet into the Iranian nuclear processing facility. So you epoxy the USB ports shut or remove the CD/DVD drives on as many computers as possible. Supervised data transfer could occur via numbered CD disc drives issued to employees temporarily for security. Again, cash in some flexibility for security.

But the basic question remains: Why should there be internet access to system wide locations. Who says it should be this way? Some IT/MBA enthusiast drunk on the idea of IoT?  C’mon. Why?



