Great Circle Associates Firewalls
(April 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IPSEC / IPV6 and Firewalls & Network Security
From: Adam Shostack <adam @ homeport . org>
Date: Mon, 14 Apr 1997 08:47:30 -0500 (EST)
To: shaver @ neon . ingenia . ca (Mike Shaver)
Cc: firewalls @ greatcircle . com
In-reply-to: <199704140443 . AAA22125 @ neon . ingenia . ca> from Mike Shaver at "Apr 14, 97 00:43:44 am"

Mike Shaver wrote:
| Thus spake Adam Shostack:
| > Fix the foundations, not the buildings.  TCP should provide a reliable
| > stream connection, and I think I can make the argument that part of
| > reliable in todays world is authentication.
| 
| Sure, you need `good, solid authentication', and I need `good, solid
| authentication', but it'll mean different things to different people.

	You're right.  What I meant to say was integrity, not
authentication. 

| I don't want the IETF making security policy decisions for me, thank
| you very much, and putting auth/integ/confid in the stack seems a step
| in that direction.

	The stuff that exists today does not make policy decisions for
you (IMHO), but gives you tools for creating policies.

| > Raising the bar is a generally good thing, even if
| > you can't raise it high enough.
| 
| Agreed, as long as you don't get a placebo effect.
| "I've got crypto-on-the-wire, so I don't need (OTP|backups|an AUP)."
| 
| *shiver*

	You will get a placebo effect, and then it will wear off,
probably 5 to 10 years after it shows up.  So, will we be better off
with that placebo or the current one?  I think we'll be better off
with a crypto placebo in effect.  That placebo will show up whenever
we deploy (name new tool here.)

Adam
"I could swear the guy behind the counter said these bullets were
magic!"





Follow-Ups:
References:
Indexed By Date Previous: Re: Secure Email Client packages
From: Alvaro Redondo <merlin @ sevillaonline . com>
Next: Re: Borderware firewall...(if that's what you want to call it)
From: Jesse Whyte <jesse @ eac . com>
Indexed By Thread Previous: Re: IPSEC / IPV6 and Firewalls & Network Security
From: Mike Shaver <shaver @ neon . ingenia . ca>
Next: Re: IPSEC / IPV6 and Firewalls & Network Security
From: Ahmed Abd Allah Bakr El Sayed <m9500849 @ cse . rmit . edu . au>

Google
 
Search Internet Search www.greatcircle.com