Re: Linked-in and its Phishing-like contacts option!
"Gautier . Rich" <[email protected]> Fri, 26 Apr 2013 16:51:37 +0000
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
Yes, that's what I meant...turn off Webmail access entirely - I was mostly = kidding - but if it's something that you can afford to do [users all have w= orking VPNs, e.g.] - it would reduce a great deal of risk. ;) Oh, and can that guy who gave the "God, whatever you do, don't fire your ne= twork geek" speech please come and give a motivational speech here? Richard Gautier, CISSP Enterprise Architect, Federal Group 650 Massachusetts Avenue NW Suite 510 Washington, DC 20001 Office: (571) 226-8828 | Cell: (703) 231-2156 [email protected] | www.drc.com -----Original Message----- From: [email protected] [mailto:firewall-wizar= [email protected]] On Behalf Of Jim Seymour Sent: Friday, April 26, 2013 11:39 AM To: [email protected] Subject: Re: [fw-wiz] Linked-in and its Phishing-like contacts option! On Wed, 24 Apr 2013 19:26:01 +0000 "Gautier . Rich" <[email protected]> wrote: > Thoughts? I'm wondering why User Operational Security falls under the > realm of Firewall Wizards.. I think of it this way: Firewall security, in and of itself, doesn't get th= e job done. You may have the most bullet-proof border the world has ever s= een, but, unless that bullet-proof-ness means essentially blocking everythi= ng, both incoming and outgoing, it will not be enough. A layered defense i= s mandatory. One of those layers is end-user operational security. Our goal is to protect the organizational jewels, no? Besides: We've pretty-much beaten stateful/deep-packet inspection vs. application proxy to death, no? :) > ... plenty of users seem to > be perfectly willing to accept the risk (or be unaware of it). Both, IME. > However, not much you can do on the firewall side other than turning > off webmail access... Turning off webmail access? How would one accomplish that, exactly, witho= ut essentially turning off web access entirely? As for LinkedIn: I've received so many LinkedIn emails reported as spam at = work that they've occasionally been there. I may have them listed on my ma= ilserver at home, for the same reason. (Possibly so. Can't say as I've seen= LinkedIn spam for a while.) This nonsense of them asking for "work email password" is grounds, in _my_ = view, to block them entirely. That's intolerable. I'm going to see if I c= an do that. But I'm old school. I don't believe convenience, golly-gee-whiz-bang, and = _especially_ "social networking" ought to trump security. Generally my bos= ses tend to agree. (Esp. ever since a couple of the Big Guys attended some-= or-another network security briefing, which incl. a retired FBI agent, and = were told that "whatever your network security is, it's probably not good e= nough" and "for God's sake, whatever you do, do not lose your network geek"= ;).) Regards, Jim -- Note: My mail server employs *very* aggressive anti-spam filtering. If you= reply to this email and your email is rejected, please accept my apologies= and let me know via my web form at <http://jimsun.LinxNet.com/contact/scfo= rm.php>. _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards ________________________________ This electronic message transmission and any attachments that accompany it = contain information from DRC=AE (Dynamics Research Corporation) or its subs= idiaries, or the intended recipient, which is privileged, proprietary, busi= ness confidential, or otherwise protected from disclosure and is the exclus= ive property of DRC and/or the intended recipient. The information in this = email is solely intended for the use of the individual or entity that is th= e intended recipient. If you are not the intended recipient, any use, disse= mination, distribution, retention, or copying of this communication, attach= ments, or substance is prohibited. If you have received this electronic tra= nsmission in error, please immediately reply to the author via email that y= ou received the message by mistake and also promptly and permanently delete= this message and all copies of this email and any attachments. We thank yo= u for your assistance and apologize for any inconvenience.