Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: controlling cern-httpd-proxy
From: "Bryan D. Boyle" <bdboyle @ maverick . erenj . com>
Date: Thu, 6 Jul 1995 14:44:35 -0400
To: dorian @ oxygen . house . gov (Dorian Deane)
Cc: firewalls @ GreatCircle . COM
In-reply-to: dorian @ oxygen . house . gov (Dorian Deane) "Re: controlling cern-httpd-proxy" (Jul 6, 12:17pm)
Posted-date: Thu, 6 Jul 1995 14:44:35 -0400
References: <9507061617 . AA18794 @ oxygen . house . gov>

On Jul 6, 12:17pm, Dorian Deane wrote:
> Subject: Re: controlling cern-httpd-proxy
> > Before you say Pass http://* say
> >
> > # Block access to porno
> > Map http://www.cnam.fr/* /nono.html
> > Map http://intertain-inc.com/xxx/* /nono.html
> >
> > /nono.html may or may not exist, depending on what action you wish to take.
> > Having it not exist is probably easiest.
> >
> > D.
> >
>
> A minor point:  if your intent is to limit all access to pornography,
> this is not a solution that scales well on the Internet.  If your
> intent is to limit access to only sites that contain work-related
> items, then it doesn't scale at all.
>
> The usual refrain here is that this is more of a management/social
> issue--something that's hard to fix with technology.

However, it does tend to make the users sit up and take notice when the
nono.html file restates the company policy when users try for the more
egregious sites that probably don't have a business use.

You won't capture everything.  You don't have to keep track of each little
dirty photo.  You just enforce the policy, and occasionally remind the users
that their access is a privilege, and use may be monitored.


-- 
Bryan D. Boyle           |The Moving Finger writes,and having writ, moves on.
#include <disclaimer>    |Nor all your Piety nor Wit can call it back to cancel
EMAIL: bdboyle @
 erenj .
 com |Half a line, or all your tears wash out a Word of it.
---------<URL:http://www.access.digex.net/~bdboyle/index.html>-----------



References:
Indexed By Date Previous: Re: Proceedings Now Available - 5th USENIX UNIX Security Symposium
From: Brent @ GreatCircle . COM (Brent Chapman)
Next: Re: controlling cern-httpd-proxy
From: Bob Beck <beck @ cs . ualberta . ca>
Indexed By Thread Previous: Re: controlling cern-httpd-proxy
From: dorian @ oxygen . house . gov (Dorian Deane)
Next: Re: controlling cern-httpd-proxy
From: Bob Beck <beck @ cs . ualberta . ca>

Google
 
Search Internet Search www.greatcircle.com