Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Microsoft plans to offer a firewall
From: Frank Willoughby <frankw @ in . net>
Date: Wed, 02 Jul 1997 16:52:31 -0500
To: Kevin Brown - NetComm <Kevin . Brown @ NetComm . ie>
Cc: Frank Willoughby <frankw @ in . net>, Frank Willoughby <frankw @ in . net>, Vin McLellan <vin @ shore . net>, firewalls @ GreatCircle . COM
In-reply-to: <l03010d0cafe05b56dc5e @ [129 . 156 . 240 . 33]>
References: <3 . 0 . 2 . 32 . 19970701201820 . 006a16b0 @ in . net> <l03010d09afdf4d5a6dc4 @ [129 . 156 . 240 . 33]> <3 . 0 . 2 . 32 . 19970701072514 . 006a1968 @ in . net> <v03007800afde1bf820cc @ [198 . 115 . 179 . 81]>

At 08:32 PM 7/2/97 +0100, Kevin Brown - NetComm wrote:

>Frank,
>
>No I was not spoofed, but I have discovered that you do not have a sense of
>humour. ;->

Sure I do.  My puns are infamous.  8^)

>I was tying to point out that MS can even today, snare people into taking
>actions that are terribly foolish. Would you advise a bank to allow any
>customer to dial in for bank transactions with NT RAS as the sole form of
>Authentication for their internal Net?

No on both counts.  I wouldn't recommend that their customers use any
authentication-only mechanism for dial-in bank transactions.  Nor would 
I allow any inbound connection to terminate on their internal network.

As anyone who has audited a bank can tell you, banks are notoriously
insecure.  Many (most?) banks are still using antiquated (and insecure) 
technologies to secure customer dial-in bank transactions.  <sigh>  
I recommended one solution to secure customer dial-in banking to an 
out-of-country bank.  It was my understanding that this was going to 
be a competitive advantage for their bank over other banks. in the 
area.  It'd be nice if other banks followed suit.

Best Regards,


Frank

The opinions of the author of this mail may not necessarily be 
representative of the opinions of Fortifed Networks, Inc.

Fortified Networks, Inc. - http://www.fortified.com/
Expert (vendor-neutral) Computer and Network Security Consulting
Phone: (317) 573-0800     Fax:   (317) 573-0817


References:
Indexed By Date Previous: ICQ messaging system (was Re: ICQ network)
From: Gabriel Dura <dura @ geocities . com>
Next: [no subject]
From: Asley Lugo Avila <asley @ mail . infocom . etecsa . cu>
Indexed By Thread Previous: Re: Microsoft plans to offer a firewall
From: Kevin Brown - NetComm <Kevin . Brown @ NetComm . ie>
Next: Re: Microsoft plans to offer a firewall
From: peter @ baileynm . com (Peter da Silva)

Google
 
Search Internet Search www.greatcircle.com