Re: Linked-in and its Phishing-like contacts option!
Bennett Todd <[email protected]> Fri, 26 Apr 2013 10:26:55 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <CAA9gXs_8OWFEHHg48351Cw1Ch5fcj0EyUUyfJVY6bv7OukiMCw@mail.gmail.com> |
--===============0349311561== Content-Type: multipart/alternative; boundary=047d7b6d9fcab3add304db44533c --047d7b6d9fcab3add304db44533c Content-Type: text/plain; charset=ISO-8859-1 If user operational security was adequate, we could retire our firewalls, let our users remote compute with full VPNs in and out, and replace these relatively slow, fragile, complex, maintenance-intensive sets of boxes with wire-speed switches. Plus IDS. If we feel user operational security isn't adequate, I think it's a fair topic of discussion, because the drive to try to mend or at least detect issues ends up in our hands. We can secure every machine that has IP connectivity to the inside net, more or less, but user operational security lapses will let vandals or thugs molest our users. >From everything I've heard, the targets of some recent high-profile intrusions had petty good security architecture in place. Whether it's carrying USB sticks between home and work, or clicking on links using an overly-complex and hence insecure browser or MUA, folks need to get their work done. Some behavior problems can sometimes be partially addressed by training, but mostly, if there's a problem, we should look for a way to adjust our firewall and the services it permits, or provide companion services (owncloud sounds interesting) to help them get their work done without exposing themselves to folk with hostile intent. I think discussion of what we should try to do, and why, is every bit as relevant as - and maybe more useful than - chatting about how best to do it. --047d7b6d9fcab3add304db44533c Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable <p dir=3D"ltr">If user operational security was adequate, we could retire o= ur firewalls, let our users remote compute with full VPNs in and out, and r= eplace these relatively slow, fragile, complex, maintenance-intensive sets = of boxes with wire-speed switches.</p> <p dir=3D"ltr">Plus IDS.</p> <p dir=3D"ltr">If we feel user operational security isn't adequate, I t= hink it's a fair topic of discussion, because the drive to try to mend = or at least detect issues ends up in our hands.</p> <p dir=3D"ltr">We can secure every machine that has IP connectivity to the = inside net, more or less, but user operational security lapses will let van= dals or thugs molest our users.</p> <p dir=3D"ltr">From everything I've heard, the targets of some recent h= igh-profile intrusions had petty good security architecture in place.</p> <p dir=3D"ltr">Whether it's carrying USB sticks between home and work, = or clicking on links using an overly-complex and hence insecure browser or = MUA, folks need to get their work done.</p> <p dir=3D"ltr">Some behavior problems can sometimes be partially addressed = by training, but mostly, if there's a problem, we should look for a way= to adjust our firewall and the services it permits, or provide companion s= ervices (owncloud sounds interesting) to help them get their work done with= out exposing themselves to folk with hostile intent.</p> <p dir=3D"ltr">I think discussion of what we should try to do, and why, is = every bit as relevant as - and maybe more useful than - chatting about how = best to do it.</p> --047d7b6d9fcab3add304db44533c-- --===============0349311561== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============0349311561==--