Re: DISA eliminating firewalls
"Young,Greg" <[email protected]> Sat, 6 Jul 2013 18:33:26 +0000
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
--===============0826379384== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_25D308BE2CEA4C45BECDB9C067C5DBDBgartnercom_" --_000_25D308BE2CEA4C45BECDB9C067C5DBDBgartnercom_ Content-Type: text/plain; charset="windows-1256" Content-Transfer-Encoding: quoted-printable BYOD doesn't mean give up on the network edge and firewalls. And a more co= mplex Internet edge doesn't mean your data center doesn't need protecting f= rom the outside and the WAN: just the opposite. This is why the increase i= n defence in depth. As long as end points are not all vulnerability free = and all managed we can't exclusively rely on host security. And firewalls = aren't the silver bullet, but they can sure narrow the aperture for attacks= . This is a similar discussion to the ones a few years ago around the Jericho= Forum. Anyone up for hanging their data server off the inet? Have an upd= ated CV if you do. I think that article speaks more to the frustrations around data security r= eally. Data security and network security aren't exclusive though. On 2013-07-06, at 12:11 PM, "Crispin Cowan" <[email protected]<mailt= o:[email protected]>> wrote: =93What will happen when firewalls go away?=94 is a very good question, i d= on=92t have that answer. I simply assert that firewalls will go away, becau= se they will become irrelevant. They are already barely relevant because of= mobile devices. The threatscape is ignoring your firewall and walking stra= ight through the front door attached to each individual worker in the form = of a smart phone or a tablet. Not only do the users use them any way they w= ant while away from the office, most of these devices are dual-homed to you= r network and a cellular network plumped right to the internet. It is neither my choice nor my wish that firewalls will go away, merely an = inevitable consequence of pervasive mobile computing in the enterprise. Sent from Windows Mail From: Tim Harris Sent: =FDSaturday=FD, =FDJuly=FD =FD6=FD, =FD2013 =FD8=FD:=FD11=FD =FDAM To: Firewall Wizards Security Mailing List I don=92t disagree with your comment about the crunchy outside/gooey middle= but If firewalls are to go away, what will happen to the function they per= form? Are we going to discard the entire function of coarse filtering? It= has been amply demonstrated that the individual device is not currently ca= pable of adequately defending itself. Going back to my other comment about many points of administration, is ther= e a software package or system that can/will reduce it down to a manageable= problem? Is there a =93meta-admin=94 system out there or under developmen= t? From: [email protected]<mailto:firewall-wizard= [email protected]> [mailto:firewall-wizards-bounces@listserv.= icsalabs.com] On Behalf Of Crispin Cowan Sent: Friday, July 05, 2013 12:04 PM To: Firewall Wizards Security Mailing List Subject: Re: [fw-wiz] DISA eliminating firewalls Firewalls are virtually guaranteed to disappear. The writing was on the wal= l the first time =93crunchy outside, gooey middle=94 was uttered. Smart pho= nes and tablets dig the hole deeper, and BYOD is the nail in the coffin. You cannot protect your networks in a world full of smart phones and tablet= s, owned by consumers, which must be allowed to connect to the network. The= only thing you can do at that point is to stop trusting the network, and i= nstead trust individual nodes, and use encrypted channels (IPsec, SSL, what= ever) between nodes that trust each other. When this will happen is far less clear, and it may be that DISA is a bit p= remature here. But this is coming, get used to it. Sent from Windows Mail _______________________________________________ firewall-wizards mailing list [email protected]<mailto:[email protected]= alabs.com> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards ________________________________ This e-mail message, including any attachments, is for the sole use of the = person to whom it has been sent, and may contain information that is confid= ential or legally protected. If you are not the intended recipient or have = received this message in error, you are not authorized to copy, distribute,= or otherwise use this message or its attachments. Please notify the sender= immediately by return e-mail and permanently delete this message and any a= ttachments. Gartner makes no warranty that this e-mail is error or virus fr= ee. --_000_25D308BE2CEA4C45BECDB9C067C5DBDBgartnercom_ Content-Type: text/html; charset="windows-1256" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dwindows-1= 256"> </head> <body dir=3D"auto"> <div>BYOD doesn't mean give up on the network edge and firewalls. And= a more complex Internet edge doesn't mean your data center doesn't need pr= otecting from the outside and the WAN: just the opposite. This is why= the increase in defence in depth. As long as end points are not all vulnerability free and all managed we can'= t exclusively rely on host security. And firewalls aren't the silver = bullet, but they can sure narrow the aperture for attacks.</div> <div><br> </div> <div>This is a similar discussion to the ones a few years ago around the Je= richo Forum. Anyone up for hanging their data server off the inet? &n= bsp;Have an updated CV if you do.</div> <div><br> </div> <div>I think that article speaks more to the frustrations around data secur= ity really. Data security and network security aren't exclusive thoug= h.<br> <br> <div><br> </div> </div> <div><br> On 2013-07-06, at 12:11 PM, "Crispin Cowan" <<a href=3D"mailto= :[email protected]">[email protected]</a>> wrote:<br> <br> </div> <blockquote type=3D"cite"> <div><style> <!-- p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt} p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParag= raphCxSpFirst, p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle,= div.MsoListParagraphCxSpMiddle, p.MsoListParagraphCxSpLast, li.MsoListPara= graphCxSpLast, div.MsoListParagraphCxSpLast {margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; line-height:115%} --> </style><style> <!-- p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman","serif"} a:link, span.MsoHyperlink {color:blue; text-decoration:underline} span.MsoHyperlinkFollowed {color:purple; text-decoration:underline} p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman","serif"} p.msolistparagraphcxspfirst, li.msolistparagraphcxspfirst, div.msolistparag= raphcxspfirst {margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; line-height:115%; font-size:12.0pt; font-family:"Times New Roman","serif"} p.msolistparagraphcxspmiddle, li.msolistparagraphcxspmiddle, div.msolistpar= agraphcxspmiddle {margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; line-height:115%; font-size:12.0pt; font-family:"Times New Roman","serif"} p.msolistparagraphcxsplast, li.msolistparagraphcxsplast, div.msolistparagra= phcxsplast {margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; line-height:115%; font-size:12.0pt; font-family:"Times New Roman","serif"} p.emailquote, li.emailquote, div.emailquote {margin-right:0in; margin-left:1.0pt; border:none; padding:0in; font-size:12.0pt; font-family:"Times New Roman","serif"} span.EmailStyle22 {font-family:"Calibri","sans-serif"; color:#1F497D} .MsoChpDefault {font-size:10.0pt} --> </style> <div dir=3D"ltr" style=3D"font-family:Calibri,'Segoe UI',Meiryo,'Microsoft = YaHei UI','Microsoft JhengHei UI','Malgun Gothic','Khmer UI','Nirmala UI',T= unga,'Lao UI',Ebrima,sans-serif; font-size:12pt"> <div>=93What will happen when firewalls go away?=94 is a very good question= , i don=92t have that answer. I simply assert that firewalls will go away, = because they will become irrelevant. They are already barely relevant becau= se of mobile devices. The threatscape is ignoring your firewall and walking straight through the front door atta= ched to each individual worker in the form of a smart phone or a tablet. No= t only do the users use them any way they want while away from the office, = most of these devices are dual-homed to your network and a cellular network plumped right to the internet.</div= > <div><br> </div> <div>It is neither my choice nor my wish that firewalls will go away, merel= y an inevitable consequence of pervasive mobile computing in the enterprise= .<br> </div> <div> <div><br> </div> <div>Sent from Windows Mail</div> <div><br> </div> </div> <div style=3D"padding-top:5px; border-top-color:rgb(229,229,229); border-to= p-width:1px; border-top-style:solid"> <div><font face=3D"Calibri, 'Segoe UI', Meiryo, 'Microsoft YaHei UI', 'Micr= osoft JhengHei UI', 'Malgun Gothic', 'Khmer UI', 'Nirmala UI', Tunga, 'Lao = UI', Ebrima, sans-serif" style=3D"line-height:15pt; letter-spacing:0.02em; = font-family:Calibri,"Segoe UI",Meiryo,"Microsoft YaHei UI&qu= ot;,"Microsoft JhengHei UI","Malgun Gothic","Khmer= UI","Nirmala UI",Tunga,"Lao UI",Ebrima,sans-serif= ; font-size:11pt"><b>From:</b> Tim Harris<br> <b>Sent:</b> =FDSaturday=FD, =FDJuly=FD =FD6=FD, =FD2013 =FD8=FD:=FD11= =FD =FDAM<br> <b>To:</b> Firewall Wizards Security Mailing List</font></div> </div> <div><br> </div> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span style=3D"color:rgb(31,73,125); font-family:&qu= ot;Calibri","sans-serif"; font-size:11pt">I don=92t disagree= with your comment about the crunchy outside/gooey middle but If firewalls = are to go away, what will happen to the function they perform? Are we going to discard the entire function of coarse filtering? It = has been amply demonstrated that the individual device is not currently cap= able of adequately defending itself.</span></p> <p class=3D"MsoNormal"><span style=3D"color:rgb(31,73,125); font-family:&qu= ot;Calibri","sans-serif"; font-size:11pt"> </span></p> <p class=3D"MsoNormal"><span style=3D"color:rgb(31,73,125); font-family:&qu= ot;Calibri","sans-serif"; font-size:11pt">Going back to my o= ther comment about many points of administration, is there a software packa= ge or system that can/will reduce it down to a manageable problem? Is there a =93meta-admin=94 system out there or under devel= opment?</span></p> <p class=3D"MsoNormal"><span style=3D"color:rgb(31,73,125); font-family:&qu= ot;Calibri","sans-serif"; font-size:11pt"> </span></p> <div> <div style=3D"border-width:1pt medium medium; border-style:solid none none;= border-color:rgb(225,225,225) black black; padding:3pt 0in 0in"> <p class=3D"MsoNormal"><b><span style=3D"font-family:"Calibri",&q= uot;sans-serif"; font-size:11pt">From:</span></b><span style=3D"font-f= amily:"Calibri","sans-serif"; font-size:11pt"> <a href=3D"mailto:[email protected]">firewall-= [email protected]</a> [<a href=3D"mailto:firewall-wizar= [email protected]">mailto:firewall-wizards-bounces@listserv.= icsalabs.com</a>] <b>On Behalf Of </b>Crispin Cowan<br> <b>Sent:</b> Friday, July 05, 2013 12:04 PM<br> <b>To:</b> Firewall Wizards Security Mailing List<br> <b>Subject:</b> Re: [fw-wiz] DISA eliminating firewalls</span></p> </div> </div> <p class=3D"MsoNormal"> </p> <div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif"">Firewalls are virtually guaranteed to disappear. The wri= ting was on the wall the first time =93crunchy outside, gooey middle= =94 was uttered. Smart phones and tablets dig the hole deeper, and BYOD is the nail in the coffin.</span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif""> </span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif"">You cannot protect your networks in a world full of smar= t phones and tablets, owned by consumers, which must be allowed to connect = to the network. The only thing you can do at that point is to stop trusting the network, and instead trust individual nodes, and u= se encrypted channels (IPsec, SSL, whatever) between nodes that trust each = other.</span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif""> </span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif"">When this will happen is far less clear, and it may be t= hat DISA is a bit premature here. But this is coming, get used to it.</span= ></p> </div> <div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif""> </span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif"">Sent from Windows Mail</span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif""> </span></p> </div> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-family:"Calibri","= ;sans-serif""> </span></p> </div> </div> </div> </div> </div> </blockquote> <blockquote type=3D"cite"> <div><span>_______________________________________________</span><br> <span>firewall-wizards mailing list</span><br> <span><a href=3D"mailto:[email protected]">firewall-wi= [email protected]</a></span><br> <span><a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wi= zards">https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards</a><= /span><br> </div> </blockquote> <br> <hr> <font face=3D"Arial" color=3D"Gray" size=3D"1"><br> This e-mail message, including any attachments, is for the sole use of the = person to whom it has been sent, and may contain information that is confid= ential or legally protected. If you are not the intended recipient or have = received this message in error, you are not authorized to copy, distribute, or otherwise use this message = or its attachments. Please notify the sender immediately by return e-mail a= nd permanently delete this message and any attachments. Gartner makes no wa= rranty that this e-mail is error or virus free.<br> </font> </body> </html> --_000_25D308BE2CEA4C45BECDB9C067C5DBDBgartnercom_-- --===============0826379384== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============0826379384==--