Re: SCADA

AMuse <[email protected]>
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
Marcus: Could Item #2 be more properly rephrased "Too much
complexity is the enemy of security" to make them nonexclusive?

Defense in depth is traditionally considered 'good' for security
because it's acknowleged that a single layer of security cannot be 100%
perfect, and any imperfection in a single-layered model leaves you
defenseless.

Complexity is traditionally considered 'bad' because the more variables
there are in a system the more potential failure points exist; that's
not to say that a reasonably complex system must be 'bad'
though or even 'the enemy'. Seems to me like there's an ever-shifting
and vaporous line where "complexity" suddenly becomes "too much
complexity" and that it's only really possible to see the line when
you've stepped on (or in) it.

Marcus J. Ranum wrote:

Paul D.
Robertson wrote:

The other side of the coin is that adding
layers adds complexity and code- and adding code adds bugs- so you
don't *always* get a net security gain by adding "protecion."

You raise a problem that I've spent too much time pondering. In effect,

it refutes the "conventional wisdom" of computer security. Which goes

as follows:

Item #1 - Defense in depth is good

Item #2 - Complexity is the enemy of security

If #2 is true, #1 can't be, because defense in depth adds complexity.

Puzzled,

mjr.

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.