nanog mailing list archives

Re: Barracuda Networks Spam Firewall


From: "Christopher X. Candreva" <chris () westnet com>
Date: Tue, 18 May 2004 15:48:28 -0400 (EDT)


On Tue, 18 May 2004 Valdis.Kletnieks () vt edu wrote:

So your auditor wouldn't mind if you kept an unencrypted list of credit card
numbers on a DMZ box, because if somebody hacks the box they can gather those
over time? :)

This is hardly the same thing. E-mail addresses are public, credit card numbers aren't. Email addresses can be gotten by brute-force checking fairly easily without even cracking the machine. card numbers can't.

What would your auditor think about your secondary MX being used as a DOS amplifier because it sends out thousands of bogus bounces to forged addresses ?

==========================================================
Chris Candreva  -- chris () westnet com -- (914) 967-7816
WestNet Internet Services of Westchester
http://www.westnet.com/


Current thread: