Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It just goes to show that "sufficient paranoia" is something that should be evaluated relative to the value you are protecting and the estimated potential strength and persistence of adversaries.

Security measures (should be) a line item on a budget with a total. The details are something that might be reviewed by an expert in the field with the necessary clearance. Secrecy also has a cost (security by obscurity isn't a design feature, but security //plus// obscurity might have a worthwhile value).

I think at a site level a sufficiently sized dynamo, maybe per section, could be utilized as both an initial gaping measure and as a mux for different power sources (line, stopgap, and local generation). For high value sections one or more full re-regulation stages would help. (Off the shelf, a UPS that always AC > DC > AC converts comes to mind.)

Finally, at an OS level, it seems that the highest value targets should probably examine a feature similar to the 'constant time' style cryptographic / security response paths better algorithms and designs have; in this case always running the system within a constant performance (and power use) envelope. I had not previously considered that such ultra-high security environments might be harmed by /efficiency/ as a means of leaking data.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: