Re: SCADA

"Paul D. Robertson" <[email protected]>
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
On Wed, 15 Apr 2009, Marcus J. Ranum wrote:

> Paul D. Robertson (noble foil) wrote:
> > 1.  I'm not sure "no more" fits in the definition- for instance a system 
> > that's designed to send company email can also send personal email- how 
> > does that make the system less reliable?
> 
> If its purpose is only to send company email, it is flawed if it
> sends personal email. Indeed, it then becomes a "spam source" instead
> of a "corporate resource." If it is loosely specified it may later
> be determined that the company email server is flawed or that the
> specification is.

Personal email isn't "spam."  Just like the ability o play solitaire on a 
file server doesn't necesarily make the file server any less reliable (the 
Admin, certainly- the box not so much.)

> > 2.  An "insecure" system _can_ host hostile activity, but that doesn't 
> > mean it does.
> 
> 
> It eventually will.

We can talk about the likelihood, but it's not a certainty- that's a large 
part of why we're in the pickle we're in today.  If it was a certainty, 
then we wouldn't have to prove insecurity and pen testers would have to 
get real jobs.

> > If I had one beer for every time I've heard that, you'd be out of beer!  
> > Again! :)
> 
> 
> :) Bask in your victories, Obi-wan!

Always!

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
[email protected]       which may have no basis whatsoever in fact."
           Moderator: Firewall-Wizards mailing list
           Art: http://PaulDRobertson.imagekind.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.