Re: Opinions Welcom on One Security Problem
Posted in 1997
Igor I. Lisyansky wrote: > > Hello All! > > 1) Can systems based on emulation of trusted connections in a very heterogeneous environment be considered > reasonably secure for corporate use? Simple answer: NO > 2) Is it safe to create a special hidden login for the Web server, allowing it access server user passwords > stored in non-encrypted form, en claire? Simple answer: NO > 3) Are trusted connections safe enough on the machines where macro language supporting programs, mailing > software and Internet browsers are widely used? Define *trusted connections* But again NO > 4) Is it safe to use Web components implementing the trusted connections, both native and emulated? > Depends, however short answer is no it depends on how you do this. Bad software is written by those who refuse to think about their work. For a more indepth discussion, lets take this offline (e-mail) so that I can go more in depth. mikey at segel dot com -Mikey -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif ***************************** Due to AGIS's Refusal to Act Responsibly We are blocking all of their domains at the packet level. This block will exist until AGIS modifies their policies to conform to existing RFCs and net community standards. We encourage all ISPs and domain holders to do the same. *****************************