Firewall Wizards mailing list archives

Re: firewall-wizards Digest, Vol 64, Issue 3 phishing


From: Dave Piscitello <dave () corecom com>
Date: Mon, 15 Apr 2013 13:53:07 -0400

Cloud is simply the current incarnation of server (LAN/farm, data
center, virtualization...). I really don't see that the security
issues have changed all that much (evolved maybe), or approaches to
solving them.

Look at us. We are in the "Lather, rinse, repeat" business. I recently
quoted firewall-wizards threads from 2007 on DDoS in an article. We
were discussing a 2000 SANS report encouraging egress address
filtering.

Still comes down to willingness to spend, will to execute. Too little of both.

On Sat, Apr 13, 2013 at 12:26 AM, Marcus Ranum <mjr () ranum com> wrote:
I suspect that few on this list are comfortable with this scene. The
pump is there for many because it's keeping the ship afloat while we
patch and re-think how to prevent future hull breaches. Part of
re-thinking is coming up with better monitoring (of hull integrity)
and AWS; part is raising competencies among crew, and part is raising
security awareness among passengers. All of these require the
captain's approval and the captain has to empower the officers.


Meanwhile, many of the ship-builders have staked their oars and declared
that they will never go to sea again, but - of course - their customers are
welcome to try out the very inexpensive "cloud ship" offering that "ought to
work just fine." More or less. Have a nice trip.

mjr.

--
Marcus J. Ranum         CSO, Tenable Network Security, Inc.
                        http://www.tenable.com


_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: