Also, since I've worked on military systems a lot, I suppose a military grade firewall is just iptables for which someone has written a shitty gui (that might as well just be a webshell) and packaged it into a green rugged box.
Consider this. Almost every car on the road today has an unsecured bus going back to like the 1980s. However you need to actually access the car to do something malicious so the threat vector is zero; since if you have access to the car you can also just cut brakes or put in a pipe bomb.
The only reason why this paradigm changes in the EV era is because the insistence on having EVs phone home. Now you can concievably hack all EVs of this model at once and that is now realistic and even attractive to do. But again not a necessity for running a car. Just something that modern software focused companies want to see that leads to a host of expensive security issues that didn’t exist before. The car could be airgapped with the dealer network used to flash software updates like they do with most other cars before EV era.
Sure someone in that situation could also "just cut brakes or put in a pipe bomb" but car theft is a lot more common than assassination, at least where I live.
See [1] from 2023, where popping the headlight gives access to the bus. Lack of internal security then gives a way to steal the car.
The threat just isn't the same as the one you are modeling.
Security will come eventually, if only to prevent bad publicity.
[1]: https://arstechnica.com/information-technology/2023/04/crook...
ETA: Just as the sibling says...
I would rather have OTA updates than enable parasitic middlemen to siphon money out of me
No clue about firewalls though.
I don’t know what constitutes a “military grade firewall” but presumably something that stops that. Or at least tries to.
Data streams are converted into a sequence of objects that are required to have and satisfy certain formally verifiable properties as a pre-condition of forwarding. Any data or objects that cannot satisfy formal analysis requirements are dropped. Forwarding policies are only applied to objects that meet the prerequisite of being rigorously analyzable.
This behavior is bidirectional. It applies equally to data egress to mitigate internal threats and accidental data leakage. The internal mechanics can be pretty complicated and they necessarily operate on a store-and-forward basis. The data objects may be “laundered” by the firewall, what you send may not be exactly what the other side receives.
To make this work, the wire protocol, data representation, etc must be designed specifically to allow this kind of rigorous analysis and work well within these constraints. It usually won’t work on a random web stream and the data representation often sacrifices efficiency of storage for efficiency of verification and analysis at runtime.
In reality, virtually no one uses this type of tech outside of defense and intelligence because it won’t let almost any of the standard web stack slop through.
"military grade" is often used as a marketing term used for things that pretend to be built to be extra strong.
In this case it is a stupid term to use to describe a firewall cause a firewall either works or it does not.