Re: SCADA
AMuse <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
Marcus: Could Item #2 be more properly rephrased "Too much complexity is the enemy of security" to make them nonexclusive? Defense in depth is traditionally considered 'good' for security because it's acknowleged that a single layer of security cannot be 100% perfect, and any imperfection in a single-layered model leaves you defenseless. Complexity is traditionally considered 'bad' because the more variables there are in a system the more potential failure points exist; that's not to say that a reasonably complex system must be 'bad' though or even 'the enemy'. Seems to me like there's an ever-shifting and vaporous line where "complexity" suddenly becomes "too much complexity" and that it's only really possible to see the line when you've stepped on (or in) it. Marcus J. Ranum wrote: Paul D. Robertson wrote: The other side of the coin is that adding layers adds complexity and code- and adding code adds bugs- so you don't *always* get a net security gain by adding "protecion." You raise a problem that I've spent too much time pondering. In effect, it refutes the "conventional wisdom" of computer security. Which goes as follows: Item #1 - Defense in depth is good Item #2 - Complexity is the enemy of security If #2 is true, #1 can't be, because defense in depth adds complexity. Puzzled, mjr. _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards