Showing posts with label Data General. Show all posts
Showing posts with label Data General. Show all posts

Saturday, January 07, 2017

Cyber Security



Given the current brouhaha over the possibility of Russia trying to influence our recent presidential  election using computer hacking, it seems appropriate to shine a light on this subject. Please note that, although I have no deep expertise in this subject, I am not a complete neophyte either. I was involved in a Data General Corporation development project were computer security was a key element. And so, I have concluded that there is no such thing as complete cyber security. It all depends upon the amount of push back against possible breaches. If we need any example of same, point to Edward Snowden who, in order to teach the world about how we are being spied upon by our government, naively gave troves of invaluable information to those who would harm us. This breach was accomplished not over a communication connection but by using tiny portable flash drives that can store multiple gigabytes of data.

Many years ago when time-sharing computing was in its infancy, I concluded that, if a computer had a connection to the outside world, it was by definition compromised. Then came the personal computer whose operating systems developers, mostly Microsoft, left data security out of their designs for expediency (and profit) sake ... and because connecting these "personal" computers was thought anathema. Personal computers didn't take long to kill the economic advantage of time-sharing and thus kill this technology. And then came the Internet with almost universal connectivity ... an opening a mile wide for cyber security breaches. Now, the advent of the "cloud" makes the protection of remote data storage and processing even more vulnerable, albeit convenient.

So what steps can be taken to start to protect today's electronic devices from these data piracy threats? Here are just a few:

- Develop the ability to isolate various levels of network interconnectivity. China already has the ability to cut off its entire national network from the rest of the world. Clearly this capability should be available to the U.S. as well as other sub-sectors of the Internet. It would seem to me that those providing networking hardware and software such as Cisco Systems could find a ready market for such a rigorous and scalable capability which might be automatically triggered by 'denial of service' attacks.

- In particularly sensitive applications, install computers that have no ports through which data can be offloaded onto any external storage device.

- Move all critical operating system components to microcode or even hardware which cannot be accessed anyway but through physical access to the computer ... and physically secure such access as one would a vault. Other O.S., interface and even some application code should be located in memory which generates a default if any changes are attempted to the bit structure. Action taken on such a default would be under the the control of the system administrator.

- Encrypt all sensitive data and applications with software whose keys vary in length with the degree of sensitivity of what is to be encoded. But don't assume any encrypted information cannot be decoded unless a truly randomized one-time pad is used.

And I'm sure other more sophisticated steps are possible. However such cyber security is expensive in both money and computer performance terms. But we are rapidly reaching the point were such costs can and need to be borne.

Wednesday, February 29, 2012

Golden Moments


In his book, The Soul of a New Machine, Tracy Kidder quotes Tom West, the leader of the development team for Data General's "Eagle" computer (and a project where I was on the outside looking in), as saying, "there are no golden moments."  In other words, there is never a time when the road to success is assured. Such was with Mitt Romney's twin victories in Michigan and Arizona yesterday ... it was not a golden moment.

Mitt Romney is still in a slog up to the August Republican nomination convention.  I expect him to have setbacks and his share of gaffs prior to Tampa, but I do see him eventually to be (reluctantly) anointed to go up against our sitting President in the fall.  And the final contest might best be compared to his running a 400 meter dash after having just completed a marathon.  So, it will clearly not be easy for Romney ... The Barry will have the money edge and the bully pulpit.  Even the LasVagas oddsmakers have Obama's chances of winning at 6 to 4 (see: Intrade Odds).

But I still have faith that Romney will be our next President ... for no other reason than, if he isn't, I sincerely believe we are toast.

Wednesday, December 07, 2011

Cyber Warfare

RQ-170 drone aircraft
Recently, the United States lost its software "leash" to a drone aircraft over Afghanistan and it ostensibly (crash?) landed in nearby Iran.  This was an ultra-modern stealth drone, the RQ-170, which is now going to be reverse engineered by the Iranians, the Russians, or, more likely, the Chinese (see: A Lost Drone).  How did this happen?  I strongly suspect this is one of the latest manifestations of cyber warfare.  Was this in retaliation for the United States (or Israel) cyber attacking the Iranian centrifuges (making them spin out of control) that are being used to purify uranium for its atomic weapons?  I suspect so.

We have known for some time that the software controlling our drones has been hacked into (probably by the Chinese ... see: A Drone Virus) and, yet, we let this top-secret drone fly apparently without a backup self-destruct override if it were crippled by a cyber attack.  This is similar to the counter-espionage sloppiness we exhibited in the raid on the Osama bin Laden compound in Pakistan.  Here a stealth helicopter had to be left behind with critical parts not destroyed, again to be reverse engineered by the Chinese.  We have even had a minor cyber attack on a water treatment plant here in the United States which may have serious implications for more egregious future events (see: Hacked Water Treatment Plant).

Now, I am far from being an expert on cyber security, but I did work for a few years in the late 1970's at a Data General research center in North Carolina where a hack-proof computer (the FHP) was being developed ... and, as it turned out, too many years ahead of its time.  And I do know that, given the huge strides that have been made in the miniaturization and speed of computer chips since then, we surely should have been able to develop a super-secure computer/software combo.  The question is ... why haven't we?