Firewall Wizards mailing list archives
Re: VPNmadness gets more support;
From: "Paul D. Robertson" <paul () compuwar net>
Date: Fri, 11 Feb 2005 19:07:45 -0500 (EST)
On Tue, 8 Feb 2005, Dave Piscitello wrote:
And the alternative is, "send everything in clear text?", or the ever- popular, "don't connect!" Pure drivel.
"Don't connect" isn't pure drivel, it's the first consideration you should make. There is no reason that many operational infrastructure networks, like parts of the power grid need to be susceptible to worm traffic when they're mostly composed of production embedded systems.
It seems that all this report confirms is that, given choices for identity and authentication, people will always choose poorly. The reason VPNs come under fire is that they've been overhyped and as a result, what the technologies actually do accomplish is undermined by the unrealistic expectations any "panacea" accrues.
Along with blanket deployments where VPN access == full network access. Client to network VPNs should almost always limit access. </blanket statement> Paul ----------------------------------------------------------------------------- Paul D. Robertson "My statements in this message are personal opinions paul () compuwar net which may have no basis whatsoever in fact." _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- VPNmadness gets more support; R. DuFresne (Feb 03)
- Re: VPNmadness gets more support; Kevin Sheldrake (Feb 05)
- Re: VPNmadness gets more support; R. DuFresne (Feb 05)
- Re: VPNmadness gets more support; Dave Piscitello (Feb 11)
- Re: VPNmadness gets more support; R. DuFresne (Feb 11)
- RE: VPNmadness gets more support; Tina Bird (Feb 12)
- A few sql 2000 related questions Mike LeBlanc (Feb 12)
- RE: A few sql 2000 related questions Paul Melson (Feb 14)
- Re: VPNmadness gets more support; R. DuFresne (Feb 11)
- Re: VPNmadness gets more support; Kevin Sheldrake (Feb 05)
- Re: VPNmadness gets more support; Paul D. Robertson (Feb 11)
- Re: VPNmadness gets more support; Frederick M Avolio (Feb 12)
- Re: VPNmadness gets more support; Steven M. Bellovin (Feb 14)
- Re: VPNmadness gets more support; ArkanoiD (Feb 14)
- Re: VPNmadness gets more support; Marcus J. Ranum (Feb 14)
- Re: VPNmadness gets more support; George Capehart (Feb 12)
- Re: VPNmadness gets more support; Paul D. Robertson (Feb 19)