Hacker News new | ask | show | jobs
by covidthrow 1890 days ago
Plaintext transport doesn't matter if at least one part of the payload chain is cryptographically protected/verified.

If you have a machine that's air-gapped and its only IO is strictly humans (read: keyboard/screen, not USB or other electronic means) then your weak point is the human, so center your security around that. You can look at security of lottery machines to get a good idea how that's handled.

But if you're updating the machine with updates, then it doesn't really fit that criteria, soooo....