BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Port Scanning
- Subject: [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- Date: Sun, 4 Aug 2024 11:21:31 -0400
- In-reply-to: <CAJFsZ=o7btMacs-OqTB0908ehYkZCFGtupLkNi59C9K8XV6zKQ@mail.gmail.com>
- References: <5c43eee0-caaf-45d6-8fdb-273cb3d8ea6d@borg.org> <20240801172933.yqcdeki3ntkrrl2t@randomstring.org> <51804f85-9275-4d89-9dc2-86234cdb299b@borg.org> <20240801210627.bzw47tfmyxofcep3@randomstring.org> <82b0d41d-075d-496e-9e1f-ef1529623c38@borg.org> <20240801182824.4bf21319.Richard.Pieri@gmail.com> <f6d905fd-7886-4cf2-9b02-f6d89f60adf0@borg.org> <20240801214606.5bebc46a.Richard.Pieri@gmail.com> <20c3240d-184f-4c84-b4ed-7680ac5301bd@borg.org> <CAJFsZ=o7btMacs-OqTB0908ehYkZCFGtupLkNi59C9K8XV6zKQ@mail.gmail.com>
On Sat, 3 Aug 2024 22:05:49 -0400 Bill Bogstad <bogstad at pobox.com> wrote: > I think it is basically because the industry has convinced itself > that bugs are inevitable and there is no way to mitigate those bugs > becoming security problems. Back in the 90s, I found security > fascinating; but when I realized that nobody had any interest in > actually doing anything more than dealing with this week's problem, I > decided that wasn't a career path I wanted to follow. It's not that nobody has that interest. It's that perfect security is impossible either in the physical world or the digital realm: the attacker always has the advantage over the defender. We do what we can think of to prevent compromise but we understand that the attackers can try all of the things we *didn't* think of or the tiniest of mistakes we make. So we also do what we can to detect, contain and mitigate compromise. It's very much whack-a-mole, solving the endless string of this week's problem. Sometimes it takes a catastrophe like the Titanic disaster or the XZ tools disaster to get problems addressed. What is most important is that we learn from the mistakes that lead to these disasters, and build on top of that knowledge. -- \m/ (--) \m/
- Follow-Ups:
- [Discuss] Port Scanning
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Port Scanning
- References:
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Port Scanning
- Prev by Date: [Discuss] Port Scanning
- Next by Date: [Discuss] Port Scanning
- Previous by thread: [Discuss] Port Scanning
- Next by thread: [Discuss] Port Scanning
- Index(es):