Re: [fw-wiz] Lists of IP's we should be blocking

From: Adam Shostack (adam_at_homeport.org)
Date: 12/12/04

  • Next message: Paul D. Robertson: "Re: [fw-wiz] Defense in Depth to the Desktop"
    To: Crispin Cowan <crispin@immunix.com>
    Date: Sun, 12 Dec 2004 12:56:35 -0500
    
    

    On Sat, Dec 11, 2004 at 05:22:06PM -0800, Crispin Cowan wrote:
    | Bruce Smith wrote:
    |
    | >Is there a list of dangerous, evil IP's that should be blocked or at least
    | >watched closely at the borders of the Internet? Address like virus targets,
    | >root-kit sources and so forth.
    | >
    | >And what is the group's opinion on the idea of a general purpose dark IP
    | >list?
    | >
    | >
    | I think the idea is good only for brushing off ankle-biter threats. The
    | problem is that serious attackers can acquire new IPs at will through a
    | substantial pool of zombie nodes on consumer broadband networks, and so
    | deliberate attacks that come at you will almost certainly *not* be on
    | anyone's dark IP list.

    Not to mention, your real customers may well be on those zombie
    machines. If you're a bank, do you want your customers calling *your*
    tech support line to fix their spyware problems?

    Admittedly, having your customers' passwords stolen is bad and
    annoying. But its probably less expensive *to you* than the support
    call, unless your money transfer controls are weak.

    If you're a bank, and your answer is yes, you want me calling with my
    spyware concerns, please let me know which bank. I'll have everyone I
    know open up a $100 savings account with you so that people stop
    calling me with their spyware problems.

    The belief that a list of 'bad identities' will help security is
    suprisingly persistant. We see it distorting air travel safety.
    (Just ask Congressmen Ted Kennedy or John Lewis, or any David Nelson
    you meet, or Johnnie Thomas, or...) Let's not let it distort internet
    security as well.

    Adam
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "Re: [fw-wiz] Defense in Depth to the Desktop"

    Relevant Pages

    • La merde de newportman
      ... IT WAS ONLY £233,000, and it was only about 20 British customers who ... Bangalore call centre had fiddled accounts and helped himself to ... the bank says they caught the crooked employee before he had ... Accountants Finance Terrorism - and Why Governments Can't Stop Them ...
      (rec.travel.europe)
    • You can trust Barclays Bank
      ... my bank trainer told a classroom full of call ... Barclays call centre in Doxford, ... I've seen customers misled, lied to and treated with contempt. ... customer's account to another, without permission, purely so he could ...
      (uk.politics.misc)
    • Citigroup Lauches Internet Banking Site
      ... Customers, however, must open linked checking accounts to get ... The largest U.S. bank is hoping to better compete with ING Group NV's ... higher-yielding online accounts amid growing competition industrywide ... HSBC Direct offers a 4.8 percent yield on some savings accounts, ...
      (comp.dcom.telecom)
    • Re: No wonder fraud is on the increase
      ... Even the overview at the beginning makes this clear "Banks must prove the authenticity of their customers' handwritten instructions if challenged, but for telephone and online banking some banks are adopting terms which could make customers liable for transactions they have not authorised. ... The OP stated that a friend had been the victim of a "bank fraud" when credit card details were misused and goods were obtained by someone else. ... The fraud is actually committed upon the retailer, who is the one induced by a deception to despatch goods to someone else. ... Neither the bank nor the credit card holder have parted with any property, so nothing has been "obtained" from them and therefore no offence is committed against them by the original perpetrator. ...
      (uk.finance)
    • Re: OT: End of the dollar?
      ... In order to increase sales, she decides to allow her loyal customers, ... A young and dynamic customer service consultant at the local bank ... what these abbreviations mean or how the securities are guaranteed. ... Nevertheless, their prices continuously climb, and the securities ...
      (rec.crafts.metalworking)