Re: Linked-in and its Phishing-like contacts option!

Bennett Todd <[email protected]> Fri, 26 Apr 2013 12:35:21 -0400
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <CAA9gXs8axh9cKKj8ThGzeFWXADLHvZWOOafxDFDfSQmva=ZCqQ@mail.gmail.com>
--===============0518097462==
Content-Type: multipart/alternative; boundary=20cf3077615f11ecc604db461f93

--20cf3077615f11ecc604db461f93
Content-Type: text/plain; charset=ISO-8859-1

On Apr 26, 2013 10:44 AM, "Marcus Ranum" <[email protected]> wrote:
>
>  Bennett Todd wrote:
>> If user operational security was adequate, we could retire our firewalls
> Software flaws.

For myself, I prefer using software that's sufficiently simple, or widely
scrutinized, that it's not an easy target for an unskilled thug with little
incentive.

I'm happy to keep everything on systems patched up, for all my users.

But they invariably choose to use systems that have never been nor will
ever be secure, due to their complexity.

I think MIME represented a landmark, tragic fall we'll never recover from.

Unwise or imprudent folk have always dabbled with file formats that
embedded programming languages, but they used to have to at least try some
social engineering to fool their victims into running their intrusions. But
MIME made it too easy to automate any manual intervention out of existence.

So, I agree, software flaws, where the root flaw happens early in the
design process, in the problem specification, deciding to solve "problems"
that were in fact features.

--20cf3077615f11ecc604db461f93
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<p dir=3D"ltr"><br>
On Apr 26, 2013 10:44 AM, &quot;Marcus Ranum&quot; &lt;<a href=3D"mailto:mj=
[email protected]">[email protected]</a>&gt; wrote:<br>
&gt;<br>
&gt; =A0Bennett Todd wrote:<br>
&gt;&gt; If user operational security was adequate, we could retire our fir=
ewalls<br>
&gt; Software flaws.</p>
<p dir=3D"ltr">For myself, I prefer using software that&#39;s sufficiently =
simple, or widely scrutinized, that it&#39;s not an easy target for an unsk=
illed thug with little incentive.</p>
<p dir=3D"ltr">I&#39;m happy to keep everything on systems patched up, for =
all my users.</p>
<p dir=3D"ltr">But they invariably choose to use systems that have never be=
en nor will ever be secure, due to their complexity.</p>
<p dir=3D"ltr">I think MIME represented a landmark, tragic fall we&#39;ll n=
ever recover from.</p>
<p dir=3D"ltr">Unwise or imprudent folk have always dabbled with file forma=
ts that embedded programming languages, but they used to have to at least t=
ry some social engineering to fool their victims into running their intrusi=
ons. But MIME made it too easy to automate any manual intervention out of e=
xistence.</p>

<p dir=3D"ltr">So, I agree, software flaws, where the root flaw happens ear=
ly in the design process, in the problem specification, deciding to solve &=
quot;problems&quot; that were in fact features.</p>

--20cf3077615f11ecc604db461f93--

--===============0518097462==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============0518097462==--