Firewall Wizards mailing list archives

RE: Scare Me !!


From: "Jody C. Patilla" <jcp01 () ibm net>
Date: Tue, 15 Jun 1999 19:03:38 -0400

At 12:13 PM 6/13/99 -0400, Joseph Judge wrote:
supporting anecdotes:
- 102 of Fortune 500 have Internet "strike-back" capabilities
- the terrorists that hit the Lockerbie flight targetted that exact
flight due to the larger numbers of what appeared to be US govt folks
as discovered from hacking into a Saaber ticketing system

        I have a really hard time believing both of these "anecdotes".
I've worked with a fair number of Fortune 500 companies, and none of them
had a "strike-back" capability. Think about it - not only is there a
huge liability associated with such a concept, most large companies barely
have enough security staff to do what's absolutely necessary, let alone
"strike back" shenanigans. I know - I read the trade rag article a couple 
of months ago, about the unnamed company who allegedly sends staff armed
with baseball bats after hackers. I didn't believe it, and neither did a
lot of other reputable people in the field.

        I'd also find it alot more plausible that the Libyans who blew up
the Lockerbie flight got a passenger list (if they got one at all) through
good old social engineering, and not hacking.


- jcp




Current thread: