Security Basics mailing list archives
RE: Citrix Web Interface - VPN - public computer...secure??
From: "Chris R. Smith" <csmith () sunshinesavingsbank com>
Date: Fri, 11 Jul 2008 10:31:26 -0400
With GoToMyPc you have one time passwords for security, but not sure about sniffers. Chris R. Smith * VP of Information Technology * csmith () sunshinesavingsbank com www.sunshinesavingsbank.com 1400 E. Park Avenue * Tallahassee, FL 32301 * (850) 219-7302 or Toll-Free (800) 468-3993 NOTICE OF CONFIDENTIALITY: This e-mail message and its attachments (if any) may contain confidential and privileged material for the sole use of the intended recipient(s). If you are not the intended recipient of this message, you are hereby notified that any unauthorized review, use, retention, disclosure, dissemination, distribution, or copying of this communication, or any of its contents, is strictly prohibited. Delivery of this message to any person other than the intended recipient is not intended to waive any right or privilege. If you have received this message in error, please promptly notify the sender by reply e-mail and immediately delete this message from your system. Opinions, conclusions and other information in this message that do not relate to the official business of Sunshine Savings Bank shall be understood as neither given nor endorsed by it. -----Original Message----- From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of K. Brian Kelley Sent: Thursday, July 10, 2008 11:11 AM To: Don Joly; security-basics () lists securityfocus com Subject: Re: Citrix Web Interface - VPN - public computer...secure?? Public computers? I wouldn't consider that safe. One just has to do a Google search on Kinkos and GoToMyPC to see why. With a public computer there is absolutely no guarantee of any sort of reasonable precautions such as up-to-date AV. If you were using Citrix Access Gateway you could do some level of endpoint analysis, but that's not the case with CSG. K. Brian Kelley, CISA, MCSE, Security+ Contributing Author: How to Cheat at Securing SQL Server 2005 Regular Columnist, SQLServerCentral.com and SQL Server Standard Magazine http://www.truthsolutions.com/ http://blogs.sqlservercentral.com/brian_kelley/default.aspx ----- Original Message ---- From: Don Joly <fuwmanchew () live com> To: security-basics () lists securityfocus com Sent: Wednesday, July 9, 2008 11:17:02 PM Subject: Citrix Web Interface - VPN - public computer...secure?? We have a Citrix Secure Gateway that some of our employees use for web VPN access from home. The Citrix Gateway provides users with published applications and desktops and has a valid SSL Cert. We have policies that all must sign agreeing to have some type of firewall enabled, OS patches and anti-virus software up to date. The policy also states that no user is to connect to the Citrix Gateway from a "public computer" or from a public hot spot. I've been asked if we could change this policy to allow connections from public computers and hot spots but I'm not sure how secure this would be. Would this be considered safe to allow this type of access? Why or why not? Thanks, Don _________________________________________________________________ The i'm Talkaton. Can 30-days of conversation change the world? http://www.imtalkathon.com/?source=EML_WLH_Talkathon_ChangeWorld ______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________ ______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________ ______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________
Current thread:
- Citrix Web Interface - VPN - public computer...secure?? Don Joly (Jul 10)
- Re: Citrix Web Interface - VPN - public computer...secure?? ॐ aditya mukadam ॐ (Jul 11)
- Message not available
- Re: Citrix Web Interface - VPN - public computer...secure?? ॐ aditya mukadam ॐ (Jul 11)
- Message not available
- Re: Citrix Web Interface - VPN - public computer...secure?? ॐ aditya mukadam ॐ (Jul 11)
- Re: Citrix Web Interface - VPN - public computer...secure?? Gleb Paharenko (Jul 11)
- Re: Citrix Web Interface - VPN - public computer...secure?? Robert Taylor (Jul 11)
- <Possible follow-ups>
- Re: Citrix Web Interface - VPN - public computer...secure?? infolookup (Jul 11)
- Re: Citrix Web Interface - VPN - public computer...secure?? K. Brian Kelley (Jul 11)
- RE: Citrix Web Interface - VPN - public computer...secure?? Chris R. Smith (Jul 11)
- Re: Citrix Web Interface - VPN - public computer...secure?? Wilson (Jul 14)