Re: [fw-wiz] RE: In defense of non standard ports



On Tue, Jan 24, 2006 at 03:28:37PM -0600, Behm, Jeffrey L. wrote:
>
> Overheard at the water cooler: "Well, company X allows this traffic, why
> don't we? They are much larger than us and probably understand security
> *much* better than we do. Since they think it's safe, shouldn't we think
> it's safe, too?" I'm still looking for wording used to combat the
> cluelessness of such mindset in both our own companies, as well as
> companies that are creating situations that make us run web traffic on
> non-web ports.
>

When I hear this, I usually start with something along the lines of "and company X certainly has a legal department prepared to handle the litigation when a boxen inside their network is used to attack or probe a sensitive computer system."

While this may or may not be true, it usually gets enough attention from the original speaker that the LART follow-up is met with something other than a glassy-eyed stare. That's when we get to talk about containment, detection, compartmentalization, individual responsibility, and all those other topics related to accepting the risk of a networked computer system.

Its not about *if* you're gonna get hacked. Its about *when*, and what happens next.

YMMV, but this approach has worked for me.

-k
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: MyPC extra directories: Documents / Shared
    ... lists of settings in Inet Opts: ... security forensics... ... Instead of tinkering with system files/folders, stay safe by practicing ... http://www.microsoft.com/security/protect/default.asp - Protect Your PC ...
    (microsoft.public.windowsxp.general)
  • Re: MyPC extra directories: Documents / Shared
    ... lists of settings in Inet Opts: ... security forensics... ... had uauthorized access before.. ... Instead of tinkering with system files/folders, stay safe by practicing ...
    (microsoft.public.windowsxp.general)
  • Re: Download To Desktop
    ... The security issue was the initial interest. ... I closed it and was surprised to find the icon on my desktop. ... > Files in the Temporary Internet Files usually have strange filenames. ... which are both official and safe sites. ...
    (microsoft.public.windowsxp.basics)
  • Re: detecting nasty class/jar files - statically ?
    ... It's something of a truism of security that, in any complex system, attempting ... to create a "blacklist" of disallowed operations is going to leave holes. ... A method is safe if and only if: ... JNI code cannot be verified by the above algorithm, ...
    (comp.lang.java.programmer)
  • Re: Disney Cruise Ships Will Be Next
    ... >>REAL ID will do not one bit of good towards stopping a terrorist act. ... > A major point of security is just to make people feel safe. ... average man and woman" are only happy with cookie cutter ...
    (rec.travel.cruises)