back

by walrus01·10y ago·view on hn ↗
It's definitely not something to trust in, but intercepting (at a layer 1 level) a PTP 80 GHz link is actually harder than tapping fiber. You'd have to have Rx equipment either directly in the path or directly behind both ends of the radio link.

As compared to the effort required to cut an aerial or underground singlemode cable and fusion splice in place a passive prism split tap (basically the same thing as inserting a split in a GPON FTTH network). A practiced outside plant fiber crew of 2 persons and a bucket truck could do this with less than 5 minutes of downtime on a router-to-router optical interface, short enough time to clear any NMS alerts and prevent a repair team truck roll. Assuming we're talking about only two strands.

Either way actual security is accomplished through standard based crypto, not obfuscation or preventing people from messing with the layer-1.

4 comments
On a fiber you don't need downtime at all. If you manage to carefully clean the fiber from isolation and buffer and then bend it just enough to leak some light into yours.

So, assume that everything might be tapped and encrypt your data.

Yes, or if your fast, cheap new metro ethernet 10GbE circuit between two buildings has been provisioned by your ISP as some form of transport (handoff into a WDM system, EoMPLS tunnel), etc, it's not difficult for them to 'mirror' your port. It could be pre-tapped before it was ever turned up for customer service.

Or the splitter could be installed in your riser cable at one end, before you ever started moving packets across it.

Or a myriad of other things.

I recall reading about Soviet spies buying a cabin close to the AT&T long lines microwave path to intercept calls & fax transmissions in the 60s or 70s.
I wonder if introducing a semi-translucent obstacle, like a cloud of smoke, would be enough to capture the signal while not disrupting the original connection too much?
or a drone with a reflector