Hacker News new | ask | show | jobs
by solotronics 2498 days ago
As a network engineer it is terrifying that they would try this. Also, even if you have no MAC learning its trivial to sniff the MAC on an endpoint and then spoof it. You would really need pubkey based encryption where the key is stored in secure chips on every endpoint to know for sure what each device is connected to.
2 comments

Companies do these things all the time and in other industries they get away with it. It would be nice if other industries would have similar strict audits and requirements.
the difference is that AFDX is a "closed" network. If you attached anything to it directly, you're already past the security boundary, as timing and reliability is more important than verifying identities in it.