A question posted to Hacker News this week cuts to the heart of a growing anxiety in security-conscious communities: if AI systems are getting better at finding and exploiting vulnerabilities in connected devices, should individuals start disconnecting their most sensitive hardware from the internet entirely? The post, titled "Should we start airgapping our personal devices?", is short, but the concern it raises is worth examining.

The underlying worry

The poster frames the question around AI's improving ability to find footholds on internet-connected devices. The concern is that AI-powered exploitation could eventually become general enough to compromise any device that's reachable, regardless of how well it's maintained. If that happens, the poster asks, how do people continue sharing information between humans when the systems that enable that sharing are under constant automated attack?

This isn't a paranoid fantasy. The trend lines are real. AI systems are already being used to discover vulnerabilities in mature, widely-deployed software. Attackers are using AI to reverse-engineer patches within hours of disclosure. The tools that once required deep specialized knowledge are becoming accessible to people who can describe what they want in plain language. The question isn't whether AI will change the threat landscape. It already has. The question is how far that change goes.

What airgapping actually means

An air gap is a physical disconnection from any network. A device that has never been connected to a network, or whose network hardware has been physically removed, is air-gapped. The term comes from the days when telephone lines were physically separated from sensitive government systems by an actual air gap between wires.

In practice, airgapping a personal device means accepting that it will never receive updates over the network, never sync with cloud services, and never be accessible remotely. You transfer data to it via physical media: USB drives, SD cards, optical discs. The device is secure from remote attack by definition, but it's also isolated from the convenience and connectivity that make modern computing useful.

For organizations, airgapping is a well-established practice. Classified government networks, industrial control systems in sensitive facilities, and financial trading systems all use air gaps as a layer of defense. The tradeoffs are understood and accepted because the value of the protected data justifies the operational friction.

For individuals, the calculus is different. The poster's suggestion that people might use "known-infected devices to access the internet" while keeping sensitive work on disconnected hardware reflects a mental model where infection is inevitable and the goal is containment, not prevention. That's a significant shift from the current security paradigm, where the assumption is that a well-maintained, regularly updated device can stay reasonably safe online.

The practical barriers

Airgapping a personal device introduces several problems that don't have easy solutions. Software updates are the most immediate. Operating systems, browsers, and applications need regular security patches, and those patches are distributed over the network. An air-gapped device either forgoes updates entirely, which creates its own security problems, or requires a manual update process using physical media, which most people won't maintain consistently.

Data transfer is another friction point. If your photos, documents, and communications are on an air-gapped device, getting them to anyone else requires a physical handoff or a bridge device that connects to a network. The poster acknowledges this tension directly, asking how people share information while the systems that enable sharing are compromised. The honest answer is that airgapping trades one set of risks for another, and the tradeoff isn't clearly favorable for most personal use cases.

There's also the question of where to draw the line. If your laptop is air-gapped, is your phone? Your router? Your smart home devices? A fully air-gapped lifestyle means carrying USB drives between devices, managing local file shares, and giving up the cloud services that most people rely on for backup, collaboration, and access across devices. The operational overhead is substantial.

What the concern actually points to

The real value of the poster's question isn't the literal proposal to air-gap everything. It's the recognition that the current model of always-connected, always-updating devices may not be sustainable if AI-driven exploitation becomes sufficiently general. When the attack surface is the entire internet and the attacker is an automated system that can find and exploit vulnerabilities faster than defenders can patch them, the traditional security model of patch-and-pray starts to break down.

For most people, the practical response isn't to disconnect. It's to think more carefully about what devices are connected, what data they hold, and what the consequences of compromise would be. A laptop with banking credentials and personal documents is a different risk profile than a smart thermostat. The security industry talks about defense in depth, and for individuals, that depth might mean segmenting networks, using hardware security keys, keeping sensitive data on encrypted storage, and accepting that some devices will be more trusted than others.

The poster's instinct toward isolation as a defense strategy isn't wrong. It's just expensive in terms of convenience, and the question is whether the threat justifies the cost. For most people, right now, it doesn't. But the trend toward AI-powered exploitation is young, and the cost-benefit analysis could shift faster than anyone expects.

A question worth asking early

The post received only a few comments, but the question it raises will become more common as AI capabilities improve. The security community has spent decades building systems that assume remote access is a feature, not a threat. If that assumption starts to fail, the conversation about physical isolation as a security measure will move from niche paranoia to mainstream strategy. Asking the question now, before the answer is forced, is the right instinct.