funsec mailing list archives

Re: I wrnd u abt ths ...


From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Fri, 19 Jun 2009 12:10:03 +1200

Michael Graham wrote:

... or you're going to have to start treating your
user space as inherently hostile.

Gee -- you don't do that already?

The IT environment we have designed and foisted (well, actually, mainly 
swallowed lock, stock and barrel without hardly as much as a "HTF can 
that be a good idea?") on our users means the only sensible approach 
has always been to assume that...

A really big part of the current problem set (and URL shortening 
services are just one rather good example of this) is that major (or 
wannabe major) service providers you have absolutely no control of (and 
almost as much influence over), NEVER apply this kind of thought 
process to whatever jack-ass idea they are trying to make their next 
million from...



Regards,

Nick FitzGerald


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: