Educause Security Discussion mailing list archives

Re: Vetting New Devices


From: Harry Hoffman <hhoffman () IP-SOLUTIONS NET>
Date: Wed, 3 Apr 2013 12:52:32 -0400

Wow, that's a really interesting case (about the wireless devices)!
Do you have a make/model to do facilitate research?


Cheers,
Harry

On 04/03/2013 11:20 AM, David Gillett wrote:
  We don't have residences, so Harry's actual question is moot in our case.

  HOWEVER, when I saw the Subject: header, I immediately thought of some of the stuff that staff and faculty install 
without consulting us.  Some of it comes configured as an access point "out of the box", often apparently without the 
purchaser's knowledge (or understanding)...  And some of those play nasty tricks like incrementing their wireless MAC 
address every 60-90 seconds, apparently in an attitude I've taken to calling "90-pound gorilla mode", where they just 
kind of kick sand in the face of our "official" campus wireless services.  IF we made such purchases go through a 
vetting process, they wouldn't pass....

David Gillett, CISSP CCNP
Sr Security Engineer
Foothill-De Anza College District




Current thread: