RE: [fw-wiz] A little paranoia for the weekend...

From: Paul Robertson (proberts_at_patriot.net)
Date: 07/29/03

  • Next message: ark_at_eltex.net: "Re: [fw-wiz] A little paranoia for the weekend..."
    To: Josh Welch <jwelch@buffalowildwings.com>
    Date: Tue, 29 Jul 2003 17:03:22 -0400 (EDT)
    
    

    On Tue, 29 Jul 2003, Josh Welch wrote:

    > > > Sure. That's what one-time passwords are for ;-)
    > >
    > > Classic security/admin mindset--
    > >
    > > The data is often much more important than the credential. Protecting
    > > the credential doesn't solve the problem for most situations. That's why
    > > we spent so much time as an industry on SSL, and not enough on Web server
    > > security.
    > >
    > In this case, however, it seems to have been the credentials that were
    > compromised. From what I have seen of gotomypc, their data security is
    > pretty good. The problem lies in keeping secure credentials that may be used
    > in god knows what kind of circumstances. The instance of the trojaned
    > terminal at some public location seems to be how this type of system would
    > be most likely compromised.
    > Josh

    But keystroke loggers aren't just for passwords, and lots of trojans have
    contained screen scrapers for a while. The point of the password is to
    limit access to the data for most users (admin mindsets are about access
    to machines- that's why it's a classic issue.) Solving the "credential
    isn't compromised" problem is only a part of the solution, and may only
    be the most trivial of them. For instance, remote access may only be
    valid for a small window of time, but one look at the data may devistate
    an organization. Thinking of keyboard loggers and trojans as password
    snooping devices only narrows your defenses.

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    proberts@patriot.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: ark_at_eltex.net: "Re: [fw-wiz] A little paranoia for the weekend..."

    Relevant Pages

    • Re: GW loses more credibility (again)
      ... Paul, I never claimed any credentials other than I can read, and I ... I very much dispute that. ... What do you define as "basic" science? ...
      (alt.smokers.cigars)
    • Re: GW loses more credibility (again)
      ... Paul, I never claimed any credentials other than I can read, and I ... You really must stop making these global statements. ... disagrees with your preconceived opinions is automatically in the pay ...
      (alt.smokers.cigars)
    • Re: GW loses more credibility (again)
      ... Paul, I never claimed any credentials other than I can read, and I ... understand basic science. ... I very much dispute that. ...
      (alt.smokers.cigars)
    • Re: Connecting to a File Server
      ... Thanks Paul, but I confirmed by lookin directly in the registry using ... Using 4.2 we were able to save the credentials and then pass 0 to ... BOOL RetValue = FALSE; ...
      (microsoft.public.windowsce.platbuilder)
    • Re: GW loses more credibility (again)
      ... global climate instability we are facing and which gets worse every ... Professor Paul who will dismiss everything you say out of hand because ... And you did start this thread so tough beans, fella. ... Paul, I never claimed any credentials other than I can read, and I ...
      (alt.smokers.cigars)