Re: SCADA
"Paul D. Robertson" <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 15 Apr 2009, Marcus J. Ranum wrote: > Paul D. Robertson (noble foil) wrote: > > 1. I'm not sure "no more" fits in the definition- for instance a system > > that's designed to send company email can also send personal email- how > > does that make the system less reliable? > > If its purpose is only to send company email, it is flawed if it > sends personal email. Indeed, it then becomes a "spam source" instead > of a "corporate resource." If it is loosely specified it may later > be determined that the company email server is flawed or that the > specification is. Personal email isn't "spam." Just like the ability o play solitaire on a file server doesn't necesarily make the file server any less reliable (the Admin, certainly- the box not so much.) > > 2. An "insecure" system _can_ host hostile activity, but that doesn't > > mean it does. > > > It eventually will. We can talk about the likelihood, but it's not a certainty- that's a large part of why we're in the pickle we're in today. If it was a certainty, then we wouldn't have to prove insecurity and pen testers would have to get real jobs. > > If I had one beer for every time I've heard that, you'd be out of beer! > > Again! :) > > > :) Bask in your victories, Obi-wan! Always! Paul ----------------------------------------------------------------------------- Paul D. Robertson "My statements in this message are personal opinions [email protected] which may have no basis whatsoever in fact." Moderator: Firewall-Wizards mailing list Art: http://PaulDRobertson.imagekind.com/