Saturday, August 17, 2002

Courtesy of

MIT Technology Review: Firewall Follies. Simson Garfinkel. They don't make business systems significantly more secure. And by focusing attention on defending the perimeter, rather than on defending information assets within an organization, firewalls foster lax internal security practices that magnify the damage that insiders can inflict. [Tomalak's Realm]
(see also the following paragraph...)
What firewalls do accomplish, however, is this: they make the Internet more cumbersome to use. I recently visited a friend’s firm in New York and wanted to check my e-mail, so I plugged my laptop into a network jack in an unused office. Access denied: my PC wasn’t set up to work with the company’s firewall. So instead of reading my e-mail, I occupied myself by sniffing the traffic on the office network and probing for a way out. (Had I been inclined, I could have read everybody else’s e-mail—or done real damage.)
I was working at a client once, with a programmer seeking to develop a program that would send e-mail when a customer ordered literature. I was looking for an SMTP server, and so used nslookup to list the computers in the domain, looking for something called "FOOSMTP" or "MAILSERVER" or the like. (No such luck—this client, a heavy IBM user for years, had nearly meaningless strings for server names, PC names, usernames, etc.)

In any case, I had warned the programmer that trying to find an open port would probably alert network security. In a few moments, he got a call: his PC had initiated a dump of the DNS database; did he have a good explanation for what happened?
6:45:58 PM    


Currently subscribed to:
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. 0xDECAFBAD (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. A Blonde on Bioinformatics and Aromatherapy (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. a klog apart (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. A Man with a Ph.D. - Richard Gayle's Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Alexis Smirnov (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. b.cognosco (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Binnacle Notebook (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Blogging Alone (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Bloug (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Blur Circle (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. brentashley (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Brett Morgan's Insanity Weblog Zilla (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Bryce's Radio Experiments (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Burningbird (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Buzz (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Caveat Lector (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Column Two (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Curiouser and curiouser! (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. DeepFUN Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Dewayne Mikkelson and his Radio WebDog, Shadow (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. dive into mark (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. ernie/the/attorney (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. From the Desktop of Dane Carlson (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Gordon Weakliem's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Gotzeblogged (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Greg Reinacker's Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Gurteen Knowledge-Log (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Heal Your Church Web Site (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Hugh's ramblings (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Ian's Messy Desk (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. ideas (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. inessential.com (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Instructional Technology (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Intranet Focus Blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Irreproachably Honourable (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. James Strachan's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jarrett Interaction Design (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jeroen Bekkers' Groove Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jim McGee: Blogging (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Joel's Blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. John Patrick's Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. John Robb's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. JOHO the Blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jon's Radio (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. klogs (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Krzysztof Kowalczyk's Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Loosely Coupled weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. McGee's Musings (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Meerkat: An Open Wire Service (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. meryl's notes (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Michael Helfrich's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Paresh Suthar's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Paul Holbrook's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Peter Kress' Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. peterme.com (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. PopTech, The Blog.... (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Ray Ozzie's Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Roland Piquepaille's Technology Trends (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Roland Tanglao's Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Russell Beattie Notebook (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. s l a m (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Sam Gentile's Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Servlets.com Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Shellie Faraday's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Singularity (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Smart Mobs (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. snellspace (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. So many islands, so little time (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Steven's old weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. StickyString (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Tara Sue's Weblog News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. The Desktop Fishbowl (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. The Shifted Librarian (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. TheoBlogical Community (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. thought?horizon (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. tima thinking outloud. (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. tins ::: Rick Klau's weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Tomalak's Realm (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Tony Bowden: Understanding Nothing (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. toolbox (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Weblog Interop (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Weblog Updates in RSS (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Windley's Enterprise Computing Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Wrinkled Paper (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. xBlog: The visual thinking weblog | XPLANE (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Yager Radio (rss)

Here's how this works.