Choir, preaching to (was Re: Proxy advantage)
Bennett Todd <[email protected]> Tue, 16 Apr 2013 17:57:49 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <CAA9gXs8ZvJJXY+KnL2zn1TnGkfVHHhHRxvFsKaaaZZPK7UE3yQ@mail.gmail.com> |
--===============1770379894== Content-Type: multipart/alternative; boundary=20cf306f732ad50a6404da817597 --20cf306f732ad50a6404da817597 Content-Type: text/plain; charset=ISO-8859-1 Computer Security serves a very specific purpose, and that's helping improve reliability in the face of a hostile world. If you do or say things that mustn't be known in public, it may serve to help there, too, but that's neither the sole nor a necessary justification. Implementing computer security comes at a cost. It may be paid in money, or time, but it will always be paid in sacrificed flexibility, speed, ease of use, and so on. If your security policy lays out the decision criteria well, you can do things -- like making all IP addresses other than your internal network unroutable and unreachable to anything but the proxies in your firewall plant. If you allow individuals' mobile devices to attach to your network, or vpn for work from home; or if you allow anyone to install software without careful review and supervision; or if you allow excessively complex applications to access excessively complex data from untrusted sources (say, gui web browsers or email clients), your security stance is cruising along well below the threshold to repel casual thugs with limited motivation and expertise. A low-tech kludge for must-have apps with unacceptable security issues is to run them on a sandbox machine. Happily, in this day of VMs, the cost of doing so is smaller than it used to be. --20cf306f732ad50a6404da817597 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable <p dir=3D"ltr">Computer Security serves a very specific purpose, and that&#= 39;s helping improve reliability in the face of a hostile world.</p> <p dir=3D"ltr">If you do or say things that mustn't be known in public,= it may serve to help there, too, but that's neither the sole nor a nec= essary justification.</p> <p dir=3D"ltr">Implementing computer security comes at a cost. It may be pa= id in money, or time, but it will always be paid in sacrificed flexibility,= speed, ease of use, and so on.</p> <p dir=3D"ltr">If your security policy lays out the decision criteria well,= you can do things -- like making all IP addresses other than your internal= network unroutable and unreachable to anything but the proxies in your fir= ewall plant.</p> <p dir=3D"ltr">If you allow individuals' mobile devices to attach to yo= ur network, or vpn for work from home; or if you allow anyone to install so= ftware without careful review and supervision; or if you allow excessively = complex applications to access excessively complex data from untrusted sour= ces (say, gui web browsers or email clients), your security stance is cruis= ing along well below the threshold to repel casual thugs with limited motiv= ation and expertise.</p> <p dir=3D"ltr">A low-tech kludge for must-have apps with unacceptable secur= ity issues is to run them on a sandbox machine. Happily, in this day of VMs= , the cost of doing so is smaller than it used to be.</p> --20cf306f732ad50a6404da817597-- --===============1770379894== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============1770379894==--