Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SLIP past the firewall
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Date: Thu, 20 Apr 95 08:49:24 -0400
To: "firewalls @ greatcircle . com"@UVS1.dnet.mmc.com

David rites:
>Well yes, that is a possibiity. But then with Linux, using dip, you can set
>I'm mainly trying to disuade people from hardcoding passwords into dial-up 
>scripts. I don't want someone walking up to a user's PC and clicking on an 
>icon and 2 minutes later being connected to my network. The obvious way is 
>not to have the same password each time.

In theory I agree. In practise, if I can eliminate the threat from everyone 
who does not have physical access to the box, I have done a Good Thing and
have a much smaller threat to work on that can be handled physically rather
that electronically. Perfect security is rarely achievable and almost never
practical.

The role of the security policy is to determine what is necessary and to 
provide authority to do it.
						Warmly,
							Padgett

ps My FreeWare anti-virus software just handles low-level (MBR - boot sector)
   viruses. Some have asked why it does not go after all viruses. My feeling
   is to eliminate what is easy (and causes the most infections) first, then
   go after the rest.

Indexed By Date Previous: Re: 4.4BSD-lite and MULTICAST
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: Dual Homed GTWY question
From: mclancy @ iga . com (Mark Clancy)
Indexed By Thread Previous: [no subject]
From: ctan @ amix . is . murdoch . edu . au (Collin Tan)
Next: Dual Homed GTWY question
From: mclancy @ iga . com (Mark Clancy)

Google
 
Search Internet Search www.greatcircle.com