Re: [Full-Disclosure] Avoiding being a good admin - was DCOM RPC exploit (dcom.c)

Valdis.Kletnieks_at_vt.edu
Date: 07/29/03

  • Next message: Andy Wood: "[Full-Disclosure] Dcom.c - (Shutting it down on 5,000 systems) - a Paul Schmehl Post"
    To: Jason <security@brvenik.com>
    Date: Tue, 29 Jul 2003 15:09:47 -0400
    
    
    

    On Tue, 29 Jul 2003 13:14:49 EDT, Jason <security@brvenik.com> said:

    > Wrong, the cost benefit does work out for the business. We are at 3.9
    > million because we did not pay attention to the assets that needed
    > protecting and implement best practices. At 3.9 million we are still
    > under the extremely conservative $4million estimate from one single outage!

    You can harp on "best practices" all you want - hell, *I* certainly do
    it enough. However, you have to come to some realizations here. All
    "best practices" cost something to implement. And at some point, the
    cost of prevention is going to exceed the cost of cleaning up.

    And at this point, the boss asks "So what are the chances we'll make
    it through the entire rest of the fiscal year without having to blow
    *another* $1.3M, compared to the chances we'll get wormed before the
    next advisory comes out?"

    Remember - we're up to MS03-*030* and it's still July. At $1.3M per,
    you've burned some $39M already to protect against a $4M threat.

    Security is *tradeoffs*. Do I wish all my users were patched against
    MS03-026? Yes. Do I think some will get trashed by whatever worm comes
    by? Yes - the last worm nailed 200 boxes or so before we got specific
    router filters in place.

    However, when the cost of forcing *all* the users to upgrade exceeds
    the cost of cleaning up the 200 that will get whacked, it's *REAL*
    hard to get resources allocated - I've never net a VP-level exec
    that would agree to the idea that they should spend $2M to protect
    against a $500K threat because it's "best practices". The only ways
    you'll get your $2M is to either make it under $500K instead, or something
    raises the $500K (for instance, if "liable for a $1.5M fine under the newly
    passed protection-of-private-law" gets added in...)

    Anybody who can't understand *that* probably doesn't get the joke
    about a $200 chip protecting the $0.75 fuse by blowing up first....

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Andy Wood: "[Full-Disclosure] Dcom.c - (Shutting it down on 5,000 systems) - a Paul Schmehl Post"

    Relevant Pages

    • Re: Overland T55?
      ... It is only one business practice. ... Don't confuse protecting ones trademark with charging vasts sums of money. ... with any kind of defense of other practices by UP or others. ...
      (rec.models.railroad)
    • dont even try to rub a washing
      ... cost. ... I consume the polite discount and constitute it without its ... Ayman, still protecting, ...
      (sci.crypt)
    • Re: How do you copyright your photographs?
      ... enforcing and protecting your copyright is a different issue ... I currently have an unresolved issue with an image thief which has cost me over $1000 so far and may eventually end up costing a high 5 figure amount just to identify the swine and get him into court. ... He regularly posts to these groups with taunts about his identity which provide more evidence to eventually use against him. ... You can gain recognition for your work by exhibiting prints in competitions and at shows. ...
      (rec.photo.digital)
    • Re: triple algorithms
      ... In general, though security can be economics, if you defend against them, and the cost of doing that is small, you have lost a little if they prove false. ... If you can't make an obvious decision - they might ome true, and that would cost the farm, but even if they don't the cost to me for protecting against them is neglible - or "it's so unlikely, and the cost if it actually does happen is such that I won't worry about it - then you are in trouble. ...
      (sci.crypt)
    • Re: And they say nobody wants our guns....
      ... believe in protecting myself & people I love against ANY threat ... liberty in a front-line state. ... MPFO raffle details at http://www.myguns.net ...
      (rec.guns)