Re: AV/Spam Alert response messages
From: Paul Robertson (proberts_at_PATRIOT.NET)
Date: 09/02/03
- Previous message: Memet Anwar: "hfnetFU is gone, now it is MbsaFU"
- In reply to: Nick FitzGerald: "Re: AV/Spam Alert response messages"
- Next in thread: Michael D. Barwise, BSc, IEng, MIIE, MBCS: "Re: AV/Spam Alert response messages"
- Reply: Michael D. Barwise, BSc, IEng, MIIE, MBCS: "Re: AV/Spam Alert response messages"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 2 Sep 2003 10:03:04 -0400 To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
On Fri, 22 Aug 2003, Nick FitzGerald wrote:
> I know that word scares the beejezus out of most of them, but it's time
> for AV vendors of Email and other gateway scanning products to simply
> _remove_ "send warning to sender" options from their products. We have
I can see where attachment blocking information is sometimes important,
and as AV gateways move to be content gateways, simple removal won't
always work (though I can't for the life of me figure out why anyone would
want their product to prove it knows the virus, knows it spoofs, and still
send a warning to the sender.)
The simplest solution is to switch from notifying based on return_path to
notifying based on forward_path. The recipient would know they didn't get
an intended attachment, and admins would be given more oppertunities to
disable the "feature" due to local management pressure. So, rather than
harming a 3rd party with local policy restriction notification, it'd be
all first-party. Heck, they could even sell the feature as notifying
local management of their AV gateway's protective features!
Paul
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
proberts@patriot.net which may have no basis whatsoever in fact."
probertson@trusecure.com Director of Risk Assessment TruSecure Corporation
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Whatever Happened to Octopus?
LEGATO RepliStor, formerly known as Octopus, delivers breakthrough
replication performance that's 5X faster than the competition in an
independent head-to-head test. Learn how RepliStor uses patented,
asynchronous, real-time replication, to deliver disaster recovery, data
distribution and consolidated backups. It is the first replication solution
to achieve Windows 2003 certification. Get the performance report now.
http://portal1.legato.com/products/replistor/upgrade.cfm
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
- Previous message: Memet Anwar: "hfnetFU is gone, now it is MbsaFU"
- In reply to: Nick FitzGerald: "Re: AV/Spam Alert response messages"
- Next in thread: Michael D. Barwise, BSc, IEng, MIIE, MBCS: "Re: AV/Spam Alert response messages"
- Reply: Michael D. Barwise, BSc, IEng, MIIE, MBCS: "Re: AV/Spam Alert response messages"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]