Google tries internet air-gap for some staff PCs
theregister.com
theregister.com
My workstation is just an SSH server that I do builds on, everything else is on my laptop. I can’t remember the last time I used the internet on my workstation. I install packages but those come via a mirror, I scp files back and forth but that’s internal only.
Lots of people aren’t on this workflow yet, but I don’t think anyone is suggesting airgapping the main interface people are using.
I.e. things like installing and updating clang, cmake, etc
You can BYO ChromeOS devices too which make great thin terminals to a remote workstation or cloud VM. I have a whole bunch from dogfooding preproduction Chromebooks.
We had a Sparcstation somewhere in the office being used as a mail server and nothing else. I don't recall how but I managed to SMB or NFS mount a directory so that I could edit code on my piddly little desktop but compile it on the Sparc. First time Java really worked as advertised for me.
Saved me loads of time and let me iterate on ideas that I don't think I or my boss would have had the patience for otherwise.
I'm not entirely keen on language servers, but those would be another area where distributed computing could come in handy. I think what might be missing though is a multitenant version. Everyone on my team has a duplicate model of our dependencies loaded into Webstorm and it's a pig.
Aside, but I 100% believe most developers of user-facing programs should be forced to use their app on a slow computer/phone with a slow internet connection before being able to ship it.
I decided at the very start of my career, before Google, to use a laptop at the primary interface and only use workstation / dev environment / etc. remotely. That way I have the same working experience at my desk, at a cafe, on my desk at home. The only thing that changes is the number and size of monitors. It's worked out really well, and during the COVID era it only got better due to investments in the remote workflows.
I wouldn't even notice if my VM lost internet access and root.
It has been “the year” for Linux on the desktop for the last 10 years, even more so if you use Emacs as your WM.
SSH disconnects are still annoying. And mosh/tmux/screen don't do it for me.
> It seems so weird to me to want to use Linux on the desktop. This is not The Year.
It seems so weird to me everybody considering their Windows or Mac as desktop ;)
Why? I've used it for many years and still like it very much. I use Windows too, but I do most of my work in Linux. Why would this be weird?
I can only infer that you're suggesting people would only want to use Macbooks? Setting aside the fact that that is wrong, you don't make any argument as to why that would be.
gLinux laptops are OK I guess? I dunno. Every time I've tried to use Linux as my main interface, it's been crashy and confusing. Maybe it's gotten better since the last time I tried.
All my dev work, personal, and internet while I work. KVM to swap. External screens.
Strict separation of work and life. No key logging like the work system. No fillers.
>The report says Google's new pilot program "will disable Internet access on the select desktops, with the exception of internal web-based tools and Google-owned websites like Google Drive and Gmail.
https://arstechnica.com/gadgets/2023/07/to-defeat-hackers-go...
Because some people like to use remote desktop with it. And because some people's "build machine" is a VM, or a physical desktop in the office for some others.
Sounds more like Google isn't talking about workstations but the peoples normal computer they work one, just with limited internet access.
I used a cloud VM as my main machine, and still used internet all the time. I used github to sync my configuration (using a proxy would be out of date and no way to push), amongst other things.
I switched to a Chromebook in the pandemic and honestly it was fine. My workflow barely changed. I wasn't a vim fanatic at the time so I didn't really care.
You see an error message on your desktop, you want to search for it. What do you do?
possibly, not everybody is ok with using a not so good editor, no debugger integration and keeping their ssh and pgp keys somewhere else than a local machine.
This is Google. Who is using ssh keys for anything?
There's not even a current plan to continue limiting access after the trial period ends, much less a plan for expanding it to more machines.
Even just having hosts that are sometimes internet connected and sometimes on the airgap network will greatly weaken the isolation. Stuxnet could cross an airgap with just static media, allowing thousands of computers that sometimes connect to the internet across the airgap seems like a fatal weakness.
For those that don't know: air gapped means completely disconnected, as in literally pull the network cable out the back and never back in again. File transfers have to happen using some physical medium (traditionally write-once CDs/DVDs). You can have an air gapped network so long as the machines are just connected to each other and there's no physical route whatsoever to the internet.
You can certainly argue that, at a general level, air gaps don't work for the same reason teen abstinence doesn't work. They don't happen. But in specifics, particularly for infosec professionals, it should be your job to call out dishonesty. Not to not along sagely and say "air gaps don't always work". If your airgapped machine is breached, there better be a USB lying around, or a physical configuration change.
JFC, my Xbox is not airgapped.
(actually it currently is. But you get the point.)
You use the internet from your laptop, not the workstation.
Also, the article is using “air gap” wrong - it refers to an actual physical disconnect, which is not what this is. Only some firewall rules are apparently getting changed.
Disclaimer: I have no privileged information, only common sense from working in security and at FAANGs.
This approach from google is basically the opposite. No internet on your workstation but your laptop works like normal.
Air-gapping is creating a system-low zero access enclave. No different architecturally than running a separate access gateway.
Or is this a case of "yeah nobody ever actually believed that?"
Having run classified networks there's absolutely a need for compartmentalized system-high networks
That’s how I always interpreted the marketing and technical documentation anyway.
I would be surprised if they’re not already running PAWs for things like administrative access to production GCP primitives and similar, even if they’re also running PAM, hardware authentication, and so on. I know Microsoft does for admin privileges to the Azure fabric.
"We are removing the requirement for a privileged intranet and moving our corporate applications to the Internet."
That's from the original ZT paper and is making a HUGE claim that all access in computing is more secure if you use ZT over physically (not just logically) separated networks.
99% of dev and admin work then takes place outside that perimeter, outside the VPN, by authenticating machines and encrypting traffic with TLS. Since you will always expect compromised machines and bad actors in this area outside the inner perimeter, a four-eyes principle for any critical actions, such as code changes and configuration changes, is necessary.
[1] https://www.techradar.com/news/upcoming-windows-11-pro-updat...
I like HN full of acronyms, it teaches me what's important enough in an industry to shorten.
VDI is Virtual Desktop Infrastructure. https://en.wikipedia.org/wiki/Desktop_virtualization
To have it be successful you need to not have persistent VMs that individuals are connecting to individually but rather ephemeral VMs that get created/deleted when a user needs one.
Those ephemeral VMs then need to be able to connect to the rest of the infrastructure that supports development - your artifact repositories, version control system, docker nodes, k8s clusters, etc.
Your artifact repository then needs to mirror public repositories where your source packages can be found, be it pypi, github, golang, helm, docker hub, etc. You will now have to setup your IDE or shell package manager to use this artifact repository as a proxy.
The developer tooling is usually an entire team and the infrastructure for the VMs is also.
Not an easy or cheap thing to setup. But it can be done so that the developer experience is good and so that you don't have developers running random versions of software.
In addition, some employees will have no root access, meaning they won’t be able to run administrative commands or do things like install software. """
-https://www.cnbc.com/2023/07/18/google-restricting-internet-...
This is pretty standard across the industry for some workstations/build machines.
Works just fine on macOS!
What'll be their next old-school corporate move? Time cards? A ban on phones with cameras? A buggy middlebox that forges TLS certs?
Most of the reference documentation is actually internal project/other google sources and internal docs/guides/design docs.
Todays LLMs are no suitable replacement for documentation, in my experience, because their knowledge is so sparse. You will not notice it immediately because they fill the gaps with plausible nonsense. Also training a model with domain specific knowledge is not a realistic option for most of us as of today.
For having all the reference documentation locally (possibly indexed in a vector database and accessible to the LLM) I'm doubtful as well, since it is so hard to determine scope beforehand. A couple of years ago I tried to program off-grid and prepared a MacBook with Dash (an OSX offline doc reader) and all the reference docs I thought I need. It was a nightmare, and that is from a dude who learned programming before the Internet, based on offline docs solely.
Not relying on network connectivity in my entire pipeline is still today a big discriminator in the stack I choose.
The biggest downside was, and still is, documentation. I had a script that scavenged the installed packages and downloaded all relevant documentation packages automatically, along with a local indexing service (I'm still using and recommend "recoll").
There is a humongous gap between libc/posix (anything instantly accessible with "man" with stunning quality) and pretty much everything else. Even python, which has a decent "online" (built-in) reference, is not as convenient and easily searchable when looking at the html manual itself.
A local search index doesn't have the inference power of something like google to point you to the right example you're looking for something in cppreference.
And once you pass the top 10 best documented packages you have on system, you realize how downright bad everything else is documented and how much you rely on the search engine to fill the gaps from unofficial sources.
For me at least, documentation was always THE problem.
I have not, will not, and am not allowed to copy and paste anything into chatGPT from my company that I wouldn't be comfortable putting on twitter. I agree with this policy.
The last thing someone expects is that when they're replying to a support ticket is Google or OpenAI being fed that info and it's being put into a training dataset.
We all value our privacy but it seems accepted to breach other people's privacy for the sake of using an LLM to make your job easier.
If GDPR were actually enforced consistently, or similar laws covering more specific information that exist in the United States, the economy would crawl to a screeching halt and there would be warlords fighting it out over what's left of civilization within a week.
I'm not really sure what the solution to this is, only that we are lying to ourselves that we are anywhere close to having figured it out, and anybody involved that tells you otherwise (people selling ztna, etc) is willfully ignorant or a conman.
There is also interesting discussion to be had about the meaning of all of this. It's not clear at all that we have ever had a society that guaranteed the level of privacy that some seem to expect. We always had other ways of monitoring people and violating privacy that did not require electronics. Community involvement to a level sufficient to ensure nobody is totally screwing everybody else over has always been a requirement if you wanted to not be living in a cardboard box or a prison. I happen to think that is better than a total state or the modern corporation, but recognize that others can have different views on this.
We have things like GDPR which are all about protecting your data. People are breaking the law and violating the rights of customers for the sake of making their job a little bit easier.
I’d like to know if chatgpt agrees.
godbolt would be a weird choice to whitelist if you go through the trouble of airgapping in the first place. All it takes is one accidental copy&paste of a sensitive code snippet and it's there for the world to see with no undo.
MDM like jamf and/or EDR/Antivirus like SentinelOne and Carbon Black can disable USB ports/anything in software. If your account is not admin/root you cannot remove them also.
That said, I'm sure Google's IT are far more competent than that horror-show.
7th largest DDos attack in history last august, Gmail cyberattack a few hours ago. That's just what we know too.
Is it just a software thing? For example IP blocking via iptables? 0-days in OS kernels are not something super surprising in these days, not really sure a software lock would really help that much.
Maybe they should just give their employees two computers, one air-gapped for accessing internal systems and must be kept in the company facility issued the computer, and another one fully online for accessing Stack Overflow and must not store any company information.
And why do you think that may not already be the case? Even other big tech companies already give out two computers.
> Google's tools and office software accessed via the web will still be accessible to those cut off from the internet generally. Workers in the program who require internet access for their jobs will be able to get exceptions.
The headline twists the definition of "air gap".