RE: [fw-wiz] A fun smackdown...

From: Ben Nagy (ben_at_iagu.net)
Date: 05/19/05

  • Next message: Chuck Swiger: "Re: [fw-wiz] A fun smackdown..."
    To: "'Paul D. Robertson'" <paul@compuwar.net>, "'Martin'" <marty@supine.com>
    Date: Thu, 19 May 2005 15:33:22 +0200
    
    

    > > "Be liberal in what you accept; be strict in what you send."

    This was NEVER a security doctrine. It was an RFC doctrine, originally
    (AFAIK) from RFC 791 (cf):
     
    "In general, an implementation must be conservative in its sending behavior,
    and
     liberal in its receiving behavior."

    RFCs are concerned with interoperability. Security is concerned with risk.
    The two are not congruent. If you know anything about this history of the
    Internet Protocol and the RFCs < 1000 in general, you would not characterise
    it as security focused.

    This is intuitive - well at least to me and all of the 'old timers' on this
    list.

    > -----Original Message-----
    > From: firewall-wizards-admin@honor.icsalabs.com
    [...]
    > On Tue, 17 May 2005, Martin wrote:
    >
    > > "Be liberal in what you accept; be strict in what you send."

    [Paul, sensibly, rebuts ... ]
    > _All_ effective security controls break that tenet. The more
    > liberal your controls, the more risk you assume.
    >
    > Paul

    To borrow the vernacular,

    "w3rd."

    ben

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Chuck Swiger: "Re: [fw-wiz] A fun smackdown..."

    Relevant Pages

    • Re: [fw-wiz] A fun smackdown...
      ... "Standards that don't take security into account are not internet-worthy" ... FTP proxy* I realized that this could be used to issue arbitrary ... So in your terms, since it was in the RFC, it was "legitimate" ...
      (Firewall-Wizards)
    • Re: Really stupid question about z/OS HTTP server
      ... automagically logged on to their corresponding z/OS RACF id? ... IBM CICS RACF Security and Microsoft Windows Server 2003 Security ... kerberos was originally developed a MIT's Project Athena ...and then ... selecting RFC number brings up the corresponding summary in the lower ...
      (bit.listserv.ibm-main)
    • Re: Program that disables my anti-virus
      ... The RFC 1855 is still valid and hasn't been superceded. ... > the bots, or the new security method, which goes against the RFC? ... > realizing that Microsoft recommends renaming the Administrator account ...
      (microsoft.public.security)
    • Re: Security Standards for ISPs
      ... Subject: Security Standards for ISPs ... RFC 2142: Mailbox Names for Common Servies, Roles, and Functions. ... Recommended Internet Service Provider Security Services and ...
      (Security-Basics)
    • Re: Another possible RFC 2046 vulnerability.
      ... > code passes through two different network paths: ... The only real security risk is if a badly designed MUA automatically ... You may be interested in RFC 2017 that defines the URL access ...
      (Bugtraq)