← Back to context

Comment by CursedSilicon

1 day ago

Could you skirt around it and just remark "there are no viruses for AmigaOS"

(Probably not literally true. But functionally true in the sense that they were likely transmitted via infected floppy disks, of which there'd be virtually none left in the wild in 2007)

It wasn't the AmigaOS running in the emulator that they were worried about, it was the Windows system running the emulator. (Not that the average IT auditor there could have understood the difference.)

  • How would a virus get in there?

    • If it were a newer version of NT I'd be concerned about USB media, but being NT 4.0 and not supporting USB it's imminently more capable of being air-gapped than later versions. (I recall a fun Ed Skoudis quote-- "At best, an air gap is a high-latency connection". Evidence Stuxnet.)

    • The auditor probably doesn't know nor care. "Every windows machine runs antivirus" is a checkbox item, zero thought involved.

Depends. A lot of these audits are quite prescriptive and don't leave much room for actually thinking about the problem. There is often some kind of mechanism for 'this is sufficiently segregated it doesn't matter that it's utterly out of date' but then usually some awkward rules develop that prevent some things from being put into that category. More subtly you can get whether the thing even exists as a thing that the audit cares about, and that often depends on the framing (embedded software is often invisible here but it needs to not look too much like a general-purpose OS even though it often is).

(Also, in my experience, what the auditors think the rules are and what is written down can often be divergent and even contradictory)

  • > Also, in my experience, what the auditors think the rules are and what is written down can often be divergent and even contradictory

    Sounds interesting, could you elaborate?