Are Air-Gapped Computers Hacker-Proof?

In business and government the fight against hackers has been a high-stakes contest since before the Internet even existed. The measures we take to combat the ever-growing threat of data breaches have grown so sophisticated that we sometimes overlook one of the simplest approaches to security which we call air-gapping (i.e. disconnecting the system from the Internet entirely). While the concept of air-gapping is mind-blowingly simple, there are a lot of things that could potentially present some risks even in an isolated environment. Of course, while it’s ridiculous to think anything is actually 100 percent hacker-proof, it’s worth exploring everything revolving around air gapping, why it is so secure, and what threats it may face.

What Makes Air Gapping Secure?

airgap-craftcarrier

Most attacks from hackers are carried out far away from the target system. Breaches like the ones that happened to Wendy’s and Massachusetts General Hospital are often the work of a person or group that specializes in creating malware that can siphon sensitive data from corporate systems connected to the Internet. The most obvious solution for this involves air-gapping the most sensitive data by storing it in a computer that isn’t connected to any network. Instead of transferring data to it through the web, someone has to go in and manually update the database.

The main disadvantage of an air gap is that connected systems cannot query any data stored on the air-gapped system. Because of this its only feasible use is to archive things that other systems don’t need to reach on a daily basis such as contracts, property deeds, and business-to-business transaction data. Basically, anything that is highly sensitive but isn’t accessed frequently can be air-gapped without any major impact. Air gapping is often practiced in military organizations, stock exchanges, nuclear plants, oil and gas fields, and within some vehicles. (You wouldn’t want someone controlling your brakes remotely.)

Chances are you don’t own a multi-million-dollar enterprise, but you still air gap information by storing it on USB sticks or external hard drives. Once the drives are disconnected from your computer, they can no longer be accessed by hackers. It’s a good way to store things like password lists. (Although it would be safer to use SSO services like PerfectCloud and LastPass for these things.)

The Threats

airgap-usb

Storing data in an air-gapped system doesn’t necessarily mean that the data can’t be infiltrated. Nothing protects a company from complacency. If it isn’t careful about who has physical access to the system, there’s an unaddressed risk of sabotage. An untrustworthy person can easily slip in a USB stick and download a portion of the data stored in the air-gapped machine. Researchers at Ben-Gurion University have also designed a method through which an air-gapped machine can be infected and transmit its data through radio waves, heat, and even fluctuations in its cooling fans’ rhythm. The latter method will make it very difficult to tell what data has been accessed and who accessed it when the inevitable investigation takes place.

To circumvent these threats, machines will need routine security checkups, and people accessing the system need to be vetted thoroughly. The truly paranoid out there could isolate the computer from any sort of radio signalling and use liquid cooling.

The Takeaway

Although there are some ways to undermine air gapping, it still stands as the most secure way to store data. The issue from here on in becomes complacency, a vice that has taken down giants for thousands of years. The point here is that regardless of what security measures you have in place, your prudence is key to making sure that they work the way they should.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?
Chrome Extensions Ownership Transfer is a Direct Threat to You: How to Stay Safe