Dailydave mailing list archives

Re: time for my lil opinion poll


From: Florian Weimer <fw () deneb enyo de>
Date: Wed, 25 Apr 2007 19:58:20 +0200

* Chris Anley:

As an example, if the ILP system works solely at the TCP stream level,
then a network client or server could pause while transmitting packets,
and the host at the other end could measure the pauses. Or you could
leak one bit at a time, by establishing connections in odd or
even-numbered seconds.

The issues are much more mundane.  Companies usually don't want their
sales people to leak details about their products to the competition.
So they look for software that detects such leaks.  The problem: The
data to be protected is stored in an Excel spreadsheet -- and
disconnected operation is a must.

I expect that it's possible to detect the casual leaker, but
prevention is much harder (and might give too many clues to the
attackers). 8-/

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

I think you also need to list the names of some company officials,
such as the CEO.  And of course, you must archive your message for
five (or ten?) years as well if you think you're forced to add that
footer.
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: