Re: Linked-in and its Phishing-like contacts option!

"Gautier . Rich" <[email protected]> Fri, 26 Apr 2013 16:51:37 +0000
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
Yes, that's what I meant...turn off Webmail access entirely - I was mostly =
kidding - but if it's something that you can afford to do [users all have w=
orking VPNs, e.g.] - it would reduce a great deal of risk. ;)
Oh, and can that guy who gave the "God, whatever you do, don't fire your ne=
twork geek" speech please come and give a motivational speech here?

Richard Gautier, CISSP
Enterprise Architect, Federal Group

650 Massachusetts Avenue NW
Suite 510
Washington, DC 20001
Office: (571) 226-8828  |  Cell: (703) 231-2156
[email protected]  |  www.drc.com


-----Original Message-----
From: [email protected] [mailto:firewall-wizar=
[email protected]] On Behalf Of Jim Seymour
Sent: Friday, April 26, 2013 11:39 AM
To: [email protected]
Subject: Re: [fw-wiz] Linked-in and its Phishing-like contacts option!

On Wed, 24 Apr 2013 19:26:01 +0000
"Gautier . Rich" <[email protected]> wrote:

> Thoughts? I'm wondering why User Operational Security falls under the
> realm of Firewall Wizards..

I think of it this way: Firewall security, in and of itself, doesn't get th=
e job done.  You may have the most bullet-proof border the world has ever s=
een, but, unless that bullet-proof-ness means essentially blocking everythi=
ng, both incoming and outgoing, it will not be enough.  A layered defense i=
s mandatory.  One of those layers is end-user operational security.

Our goal is to protect the organizational jewels, no?

Besides: We've pretty-much beaten stateful/deep-packet inspection vs.
application proxy to death, no? :)

> ... plenty of users seem to
> be perfectly willing to accept the risk (or be unaware of it).

Both, IME.

> However, not much you can do on the firewall side other than turning
> off webmail access...

Turning off webmail access?  How would one accomplish  that, exactly, witho=
ut essentially turning off web access entirely?

As for LinkedIn: I've received so many LinkedIn emails reported as spam at =
work that they've occasionally been there.  I may have them listed on my ma=
ilserver at home, for the same reason. (Possibly so. Can't say as I've seen=
 LinkedIn spam for a while.)

This nonsense of them asking for "work email password" is grounds, in _my_ =
view, to block them entirely.  That's intolerable.  I'm going to see if I c=
an do that.

But I'm old school.  I don't believe convenience, golly-gee-whiz-bang, and =
_especially_ "social networking" ought to trump security.  Generally my bos=
ses tend to agree. (Esp. ever since a couple of the Big Guys attended some-=
or-another network security briefing, which incl. a retired FBI agent, and =
were told that "whatever your network security is, it's probably not good e=
nough" and "for God's sake, whatever you do, do not lose your network geek"=
 ;).)

Regards,
Jim
--
Note: My mail server employs *very* aggressive anti-spam filtering.  If you=
 reply to this email and your email is rejected, please accept my apologies=
 and let me know via my web form at <http://jimsun.LinxNet.com/contact/scfo=
rm.php>.
_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
________________________________

This electronic message transmission and any attachments that accompany it =
contain information from DRC=AE (Dynamics Research Corporation) or its subs=
idiaries, or the intended recipient, which is privileged, proprietary, busi=
ness confidential, or otherwise protected from disclosure and is the exclus=
ive property of DRC and/or the intended recipient. The information in this =
email is solely intended for the use of the individual or entity that is th=
e intended recipient. If you are not the intended recipient, any use, disse=
mination, distribution, retention, or copying of this communication, attach=
ments, or substance is prohibited. If you have received this electronic tra=
nsmission in error, please immediately reply to the author via email that y=
ou received the message by mistake and also promptly and permanently delete=
 this message and all copies of this email and any attachments. We thank yo=
u for your assistance and apologize for any inconvenience.