Re: [Full-Disclosure] RE: Probable new MS DCOM RPC worm for Windows

From: Karl DeBisschop (kdebisschop_at_alert.infoplease.com)
Date: 09/27/03

  • Next message: David Vincent: "RE: [Full-Disclosure] CyberInsecurity: The cost of Monopoly"
    To: Paul Schmehl <pauls@utdallas.edu>
    Date: Sat, 27 Sep 2003 14:53:56 -0400
    
    

    On Sat, 2003-09-27 at 12:40, Paul Schmehl wrote:

    > ... the focus right now is completely on the
    > Microsoft clients. I recently suggested that we should switch all MS
    > clients to Mac OS X. :-) They actually didn't laugh this time.
    >
    > We already are pretty diversified. Our "backoffice" stuff is primarily
    > Solaris, but we've got plenty of Linux flavors, HP_UX, SGI, FreeBSD,
    > OpenBSD, etc.

    As someone noted, alot of the problems we face have to do with the
    promulgation of idea that a running system needs no maintennence.
    Compounded of course by the having more and more software installed on
    unmaintained desktops that acts as a server (in the sense that it
    listens for and responds to requests for services from the surrounding
    network).

    Further, most people will allow that unless your job is computing, that
    computers should aid your work, rather than become yet another
    distraction - even if your work is to be a student.

    As food for thought, what if you took an OS that gave you a little
    lattitude - say Mandrake Linux, which is considered fairly user
    friendly, and said "If you install this, the default configuration will
    automatically download and install updates as they come from the vendor"
    (after UT has done some light verification I'd assume).

    Not that you or I would likely want this on our desltop, but maybe some
    of your students would. And again, unless their job is computing, I
    don't think that wish is totally ill-founded.

    One problem would be that it would be hard then to avoid some degree of
    responsibility for the quality of the patches.

    I suppose you could allow students to sign up for a UT-sponsored
    SMS-style software push for windows. And in the long run, the cost might
    be less than some of the other efforts you have to undertake to secure
    things. But the initial outlay might be daunting.

    Just sort of thinking out loud -- all these require additional work on
    your part. But there may be some useful middle ground.

    -- 
    Karl DeBisschop <kdebisschop@alert.infoplease.com>
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: David Vincent: "RE: [Full-Disclosure] CyberInsecurity: The cost of Monopoly"

    Relevant Pages

    • Re: Installing Office on an additional machine (laptop)
      ... I am quoting from the EULA relevant to Students and Teachers. ... Can I install one license of Windows Office XP for Students ...
      (microsoft.public.office.setup)
    • Re: Whats the best way to buy the same version of Office for 3 puter
      ... > teachers and students are allowed to do that.. ... >>>You can legally install a retail version on one laptop and one desktop. ... >>>the Students and Teachers edition but it may not have the programs ...
      (microsoft.public.office.misc)
    • Re: Installing Office on an additional machine (laptop)
      ... Office XP Students and Teachers Edition? ... || Office XP for Students and Teachers is a single installation license. ... You may install a copy of the Software on ... "General License Grant to Install and Use Software Product. ...
      (microsoft.public.office.setup)
    • Re: [redhat] Re: Red Hat Professional Workstation
      ... My students are assigned to teams. ... > server is installed fresh in the classroom/lab as part of the course ... I try not to do a fresh install on the home system ... > In the past I have used whatever was the latest version of the Red Hat Linux ...
      (RedHat)
    • RE: The Ultimate Steal !LOOK BEFORE YOU LEAP!
      ... upgrade not a clean install which makes the CD key useless. ... "Ultimate Steal" offer because it can wind up being just that; ... I bought both the Office 07' and Vista offers ... warning to other students who might now be enticed to take advantage of such ...
      (microsoft.public.dotnet.framework.setup)