Security Basics mailing list archives

RE: Mac X-Server Security Questions...


From: "Brad Berson" <brad.berson () bytebrothers org>
Date: Thu, 7 Apr 2005 14:31:46 -0400

Why I would need file sharing?  Nah, I don't.  Customer did!  Not using
VPN was surely a combination of comfort, laziness and naivety on their
part.

OK, first post in retrospect was too vague re workstation versus server.
I looked it over.  I intended to state X-Server vs. simply OS-X and
clearly I screwed up.  I was trying so hard to establish a proper
context that I missed a most important point.  Damn.

Yes, I'm blaming the users.  Perhaps I'm being mean, and perhaps it's an
inflection that grows out of this whole hippy free love attitude that
seems to revolve around that user base, and that I'm projecting that
onto my viewpoint over their computer habits.  But it's not totally
un-substantiated.  I'm simply bewildered after taking to folks who think
there's absolutely nothing wrong with the setup.  Seriously.  I walk
into an office full of unprotected PCs and I'll get sheepish "yeah, we
know, we just never got around to it" responses, but I walk into an
office full of unprotected Macs and get this "what's wrong, everyone's
busy hacking Windows, aren't they?" response.  It makes my head spin.
So the result?  "Yes [customer], 99% ARE busy hacking Windows, but today
YOU are the lucky statistical aberration!  As a prize, you get to pay my
company to redesign your network, install firewalls, rebuild your
servers, and re-educate all your users!"

I don't mind the money but the complacency simply shocks me.  Then
again, maybe it's just too much to ask, to expect anyone without degrees
in CompSci /and/ CrimPsy to know any better.

I'll check those NSA guides.  Your help IS greatly appreciated!

-Brad

---------------------------------------------------------------------------
Earn your MS in Information Security ONLINE
Organizations worldwide are in need of highly qualified information security
professionals.  Norwich University is fulfilling this demand with its MS in
Information Security offered online.  Recognized by the NSA as an
academically excellent program, NU offers you the opportunity to earn your
degree without disrupting your home or work life.

http://www.msia.norwich.edu/secfocus_en
----------------------------------------------------------------------------


Current thread: