funsec mailing list archives

Re: This sounds like a security disaster just waiting to happen...


From: Rich Kulawiec <rsk () gsp org>
Date: Sun, 3 May 2009 06:19:49 -0400

On Wed, Apr 29, 2009 at 03:33:53PM -0700, Steve Pirk wrote:
After I got up off the floor laughing at the who's on first beauty of the 
above logic chart, it hit me that this probably would not be limited to 
"internet" cached data, but possibly all internal web data as Rich says. 
Right away I thought of ACL content (auth/auth) that is web based within a 
company tagged "your eyes only" that could be cached.

Quick, how many apps do _not_ use windows domain based auth/auth to 
determine who is allowed to see content. Ick. This would be bad where I 
work.

Yeah, alright, so I had low blood sugar when I wrote that. ;-)  

---Rsk
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: