← Back to context

Comment by ofjcihen

2 days ago

I’m honestly impressed that they managed to screw this up somehow.

Setting up defense in depth, gaps, logical blocking etc is a standard practice for malware sandboxing. The entire purpose is to prepare for what you can’t foresee.

This isn’t a new practice and I agree that this makes me wonder if they’re fit for this kind of research.

did you read the post? The model found new Zero-days to bypass existing blocks. Thats the point. Do you still think you can build a containment facility, which is still physically connected to the internet (only firewalled off or whatever) and contain it, if it can discover new unknown vulnerabilities in your whole plan?

  • Yes.

    You factor this in when creating environments for malware research.

    Defense in depth is one way.

    Logical blocks on the network is another.

    Just claiming “0-Day” isn’t really an excuse.

  • > which is still physically connected to the internet

    I mean that's the point. Why was it connected to the internet at all and just firewalled off and not completely airgapped?