RE: [fw-wiz] Transitive Trust: 40 million credit cards hack'd

From: Paul D. Robertson (paul_at_compuwar.net)
Date: 06/21/05

  • Next message: Paul D. Robertson: "Re: [fw-wiz] Equifax Canada"
    To: "Behm, Jeffrey L." <BehmJL@bvsg.com>
    Date: Mon, 20 Jun 2005 18:59:51 -0400 (EDT)
    
    

    On Mon, 20 Jun 2005, Behm, Jeffrey L. wrote:

    > True, Marcus, but not everyone _does_ use 2 factor auth. So, at this
    > point, it can be effective. You don't gotta outrun the bear, just
    > the guy next to you.

    That assumes (1) a single bear OR (2) that you can outrun the bear in the
    time it takes it to disable the other target.

    Autonomous malcode changes that equation, as does semi-random targeting.

    Now, personally, I'm all for making most of the current crop of attacker
    tools outdated, not because I think it'll make us safe, but because it'll
    force attackers to keep up, and I'd rather they not be provided the
    option of being lazy if we all have to work too. But more importantly,
    two factor authentication starts to provide a really good base for
    accountability- and THAT is what we *need*. The only problem is that the
    m0r0ns will all want "soft tokens" to lower the attacker's bar again.

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    paul@compuwar.net which may have no basis whatsoever in fact."
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "Re: [fw-wiz] Equifax Canada"

    Relevant Pages

    • RE: [fw-wiz] Transitive Trust: 40 million credit cards hackd
      ... > Behm, Jeffrey L. wrote: ... >>You don't gotta outrun the bear, ... > It works great assuming the bear count remains a constant and the ...
      (Firewall-Wizards)
    • RE: [fw-wiz] Transitive Trust: 40 million credit cards hackd
      ... Behm, Jeffrey L. wrote: ... >You don't gotta outrun the bear, ... It works great assuming the bear count remains a constant and the ...
      (Firewall-Wizards)
    • Re: Unable to print from IE6
      ... No, I don't, nor can I remember seeing this as the fix in any other discussions. ... > ~Robear Dyer ... > Paul wrote: ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Another FIND problem
      ... "PA Bear" wrote: ... > compact of all OE folders while "working offline". ... > Your anti-virus application's email scanning feature can also cause such ... > paul wrote: ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Email Photos
      ... "Paul" wrote in message ... Jeez, I love these tooth pulling sessions, don't you Bear? ... >> You even ran a defrag session, ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)