Re: Firewall Tester 0.6

From: Andrea Barisani (lcars@infis.univ.trieste.it)
Date: 04/12/02


Date: Fri, 12 Apr 2002 09:09:22 +0200
From: Andrea Barisani <lcars@infis.univ.trieste.it>
To: robert_david_graham <robert_david_graham@yahoo.com>

On Thu, Apr 11, 2002 at 03:42:04PM -0400, robert_david_graham wrote:
>
> ...
> complicated bit of logic for the protocol decode. It is not something that
> we can easily explain to a customer: opening the source would not make it
> any clearer.
> ...
> While this can be documented, you can't see how this works in the code.
> Bits of algorithm are spread throughout the code. For example, the generic
> ...
> short, while you may be interested in debugging the algorithm, there is no
> chance that you will be able to read the source code in order to understand
> how the algorithm works.

Now I mean no disrespect but frankly while I may accept the fact that you want
to say us that the poor snort won't ever be cool as RealSecure (very
questionable but I dont want to discuss it) please stop with all this 'you poor
humans cannot understand my code', is offensive. Show it and try us, then
we'll discuss.

Now if you are saying that customers and non-technical people cannot look at
your products configuration like looking at "simple" snort signatures that's
another thing, but frankly you haven't put that in this way.

Besides complexity doesn't reflect a good product.

> I don't mean to sound like a marketing droid, I could just as easily say
> Snort users deploy Snort because they get to look at the signatures, it's

I doubt that this is the only thing that snort users care.

Bye

------------------------------------------------------------
INFIS Network Administrator & Security Officer .*.
Department of Physics - University of Trieste /V\
lcars@infis.univ.trieste.it - PGP Key 0x8E21FE82 (/ \)
---------------------------------------------------- ( )
"How would you know I'm mad?" said Alice. ^^-^^
"You must be,'said the Cat,'or you wouldn't have come here."
------------------------------------------------------------



Relevant Pages

  • Re: [Snort-devel] RFC: Forking Snort
    ... You completely fail to provide any reasoning about how Sourcefire and the ... how Marty's goals with Sourcefire stand to harm Snort. ... I can assure you that every decision that Marty and the rest ... If Snort users decide that Sourcefire is a trustworthy ...
    (Focus-IDS)
  • Re: Snort + (OpenBSD or Linux)
    ... Snort + ... > Another problem that the Snort algorithm have is that it'll stop matching ... > the packet match another begnin signature (which have to be matched ... > *before* the one for the harmful attack). ...
    (Focus-IDS)
  • Re: ids inquisition
    ... Subject: ids inquisition ... I did not state that snort is deficient in any way, that ... Marty gives Snort away for free. ... Snort users can get help from thousands of other Snort users for free. ...
    (Focus-IDS)
  • Re: ids inquisition
    ... Marty gives Snort away for free. ... Snort users can get help from thousands of other Snort users for free. ... > instructors at the Sans IDS track? ...
    (Focus-IDS)

Quantcast