I have you an up vote simply because you're pretty dead-on right up to the point where you give a prescription. There are no perimeters anywhere. You have no choice but to use whitelists everywhere, with signatures even though those can be got around as well (nobody uses two differing hash signatures yet), and a slash and burn approach to air gaps center out to edges, never edges to center. And no, badbios is still a problem with new media.

Many years I came up with my "bastion" defense scheme, basically along the same lines of the largest castles ever built but digital. Now, any and all of my past work isn't sufficient now that nation-state grade tools are falling into the hands of "less sophisticated" criminals. I guess a fortress of solitude next.

