Penetration Testing mailing list archives

Re: Skype use obligation - Security x Productivity


From: M.B.Jr. <marcio.barbado () gmail com>
Date: Fri, 20 Jul 2007 19:00:18 -0300

On 7/19/07, Roland Dobbins <rdobbins () cisco com> wrote:

On Jul 18, 2007, at 7:33 AM, M.B.Jr. wrote:

> They do not have
> the certifications yet and the voip application use obligation may
> constitute one big barrier.

How?  I've never heard this argument before from anyone.  I think
it's a bogus argument.

I have mentioned how:
lacking transparency and bringing insecure technologies along with it.

> It all starts like that. Like:
> "yes sir, voip's great!"
> Then:
> "sir, why don't we provide our workforce with some voip enhanced
> mobile devices?
> check out this nice colored folder explaining it."

This kind of thinking is one of the main reasons that users don't
care about security - because instead of working to empower users to
do what they need to do in a secure manner, 'security' personnel
instead focus on trying to keep them from doing anything innovative
or productive.

I respect the commercial doctrine your company tries to sell and even
the productivity paradigms inside Cisco's engineers' minds but I think
you need to acknowledge some statistics before writing such.

Users' constitute the main concern of any corporative network.
They will never be so aware as they should and from that point on, we
would be about to discuss the human nature which in not my speciality
nor my goal within this thread.

Have a nice day,


-----------------------------------------------------------------------
Roland Dobbins <rdobbins () cisco com> // 408.527.6376 voice

        Culture eats strategy for breakfast.

                -- Ford Motor Company




------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/c/wf-spi
------------------------------------------------------------------------





--
Marcio Barbado, Jr.
==============
==============

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: