Great Circle Associates Firewalls
(September 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Mulitple levels of security (was Secure version of sendmail)
From: peter @ nmti . com (Peter da Silva)
Date: Fri, 15 Sep 1995 12:38:17 -0500 (CDT)
To: mdr @ vodka . sse . att . com
Cc: peter @ nmti . com, firewalls @ GreatCircle . COM
In-reply-to: <9509151404 . AA16148 @ ig1 . att . att . com> from "mdr @ vodka . sse . att . com" at Sep 15, 95 10:01:24 am

> True, applications programmers can get lazy, and even the best ones
> may not have security in mind.   That makes the secure OS *more*
> valuable not less.   Are you trying to imply that they will be lazier
> because they trust a secure OS more?

That's exactly what I'm saying. Its like they're using a PC and you install
a virus checker on the PC lan and all of a sudden all these new applications
show up. You're probably *more* likely to get a virus.

> The lazy ones can't get any worse.  

It's not that they're lazy. It's that they're energetic but not interested
in security. They haven't put IRC on their firewall yet because it's
not "safe", but now you've put a B level system under them they will.

> If the weren't thinking about security under C1(no security) they won't 
> bother to think less about it under B level security.

D is no security. C1 is discretionary access control. C2 mostly adds
auditing. And, yes, they will think less about security under B level
because they think they're OK. I've seen it happen too many times...
not this specific example, but others that are pretty similar.


References:
Indexed By Date Previous: 5 bit subnet for Bastion
From: Dean Waters <dwaters @ RedBrick . COM>
Next: re:firewall with only one ip-address???
From: matt <100632 . 1345 @ compuserve . com>
Indexed By Thread Previous: Mulitple levels of security (was Secure version of sendmail)
From: mdr @ vodka . sse . att . com
Next: Re: Secure version of Sendmail
From: mdr @ vodka . sse . att . com

Google
 
Search Internet Search www.greatcircle.com