Re: RE:[fw-wiz] Vulnerability Scanners ( was: concerning ~el8 / project mayhem )

From: Dave Piscitello (dave@corecom.com)
Date: 08/25/02


From: Dave Piscitello <dave@corecom.com>
To: firewall-wizards@honor.icsalabs.com
Date: Sun Aug 25 10:23:01 2002


> In my humble opinion, corporate security people not authenticing and
> filtering/monitoring traffic heading off the corporate network is a like
> airport personel not verifying individuals identities who are on an outbound
> airplane, or checking what they are carrying. 99.99% of the time nothing
> happens, that last 1% can be very painful though.
-------------
>That's when positive
>authentication is necessary. One needs to know its positively Jane Doe that
>went to the porn site (which is against policy) or it was someone who sat
>down at her authenticated workstation when she walked away without logging
>off (which is against policy) before disciplinary actions are initiated.

You'll need non-repudiable authentication (evidence), as a court of law
would describe.
How would you propose to verify Jim was at Jane's workstation at the time
of the porn site visit?
In addition to "strong authentication" as we define it today, do you
propose cameras? Keyloggers that distinguish typing behavior?

Something that's annoyed me for ages is the distinction that policy
violations conducted through computing and networking are so different from
any other medium. If an employee uses his phone card to dial a phone sex
number during work hours, from a business phone, is it as serious an
offense (granted, there's no temporary or long term cache of the "image"
unless he's taped the conversation). What about print media and fax
(although I've never heard of fax sex?)

Content inspection is an odd business, and it seems perpetually focused on
computer networking. My point is that I've seen some policies that don't
uniformly treat all media - it's acceptable to have a sexy calendar, but
not to visit Victoria's Secret online, or thumb through PlayBoy during
lunch? I've told folks that such policies are an HR nightmare waiting to
happen.

I wrote a paper a while ago on this subject, but I think it's still
accurate and hopefully relevant
http://www.tisc2002.com/newsletters/211.html

At 02:38 PM 8/23/2002 -0400, B Scott Harroff wrote:
>One needs to know its positively Jane Doe that
>went to the porn site (which is against policy) or it was someone who sat
>down at her authenticated workstation when she walked away without logging
>off (which is against policy) before disciplinary actions are initiated.

David M. Piscitello
Core Competence, Inc. &
3 Myrtle Bank Lane
Hilton Head, SC 29926
dave@corecom.com
843.689.5595
www.corecom.com



Relevant Pages

  • Re: Can I turn off authentication to speed up networking?
    ... >authentication or security since I'm the only user. ... What version of Windows does each computer run? ... Steve Winograd, MS-MVP (Windows Networking) ... Please post any reply as a follow-up message in the news group ...
    (microsoft.public.windowsxp.network_web)
  • Re: RE:[fw-wiz] Vulnerability Scanners ( was: concerning ~el8 / project mayhem )
    ... I believe authentication is necessary since one can't positively identify ... all the potential weapons in outbound traffic. ... information to send a brief "Don't do that, its agaist policy message" is ... > This is one of my pet peeves: Verifying my identity wasn't what was ...
    (Firewall-Wizards)
  • Re: ISA Inconsistent performance
    ... Windows Server 2003 SP2 or the Scalable Networking Pack: ... Jim Harrison (ISA SE) ... ISA 2004 SP3 on Windows SP2, authentication doesn't work!! ...
    (microsoft.public.isa.enterprise)
  • Re: SBS Wireless policy
    ... I clicked Edit Profile, went to the authentication ... I clicked OK until I was back at the Connections to ... I then setup the WAP to use WPA-EAP and the raduis server. ... tab I just set the policy to Grant access, ...
    (microsoft.public.windows.server.sbs)
  • Re: Issues with IAS/802.1x authentication
    ... from the event below you need to modify the policy on IAS server (the policy ... name from the event below is:"Connections to other access servers". ... and select "Grant remote access permission" ... When I check the eventlog I find the IAS> server is throwing up a heap of authentication errors, ...
    (microsoft.public.internet.radius)