Great Circle Associates Firewalls
(April 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Wanted: firewall manager position description
From: "G.J.W. Hagenaars" <xx247 @ freenet . carleton . ca>
Date: Thu, 28 Apr 1994 13:30:22 -0400 (EDT)
To: dorian @ cobalt . house . gov (Dorian Deane)
Cc: firewalls @ greatcircle . com
In-reply-to: <9404281835 . AA03432 @ cobalt . house . gov> from "Dorian Deane" at Apr 28, 94 11:35:19 am

% > Among
% > the requirements is "separation of duties"--that is, it should be
% > impossible for a single individual, including a firewall manager, to
% > subvert the purpose of the firewall.
% 
% > "Steve"   Stephen L. Arnold, Ph.D., Principal, Arnold Consulting
% 
% But seriously, is that really possible?  Without thinking too deeply
% about it, my initial reaction is that it's a bit like trying to
% play yourself in chess:  it's fairly difficult to outsmart yourself.

There are mathematical solutions to this. It is possible to design a
(mathematical) lock with n keys, and to open it you need a sufficienlty
large subset m of those n keys (most of the time m = n/2 + 1 or
larger). How you would _implement_ something like this so that it would
be possible to _work_ with this situation is an entirely different
matter.

% BTW, this question still applies even if you trust the designer
% %100 at the moment.  (And obviously, if you trusted this person
% forever, then there would be no need to worry about this issue.)

It also keeps the designer from being sued as the one who broke into
the system (if that has happened). (S)he can "only" be held responsible
for not anticipating every attack.

% dorian

GJ


References:
Indexed By Date Previous: RE: Wanted: firewall manager position description
From: Adam Shostack <adam @ bwh . harvard . edu>
Next: Re: What is a firewall
From: farsight @ clark . net
Indexed By Thread Previous: RE: Wanted: firewall manager position description
From: Adam Shostack <adam @ bwh . harvard . edu>
Next: Wanted: firewall manager position description
From: francis @ avalle . insoft . com (John [Francis] Stracke)

Google
 
Search Internet Search www.greatcircle.com