BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Port Scanning
- Subject: [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- Date: Sun, 4 Aug 2024 09:45:06 -0700
- In-reply-to: <CAJFsZ=o7btMacs-OqTB0908ehYkZCFGtupLkNi59C9K8XV6zKQ@mail.gmail.com>
- References: <5c43eee0-caaf-45d6-8fdb-273cb3d8ea6d@borg.org> <20240801172933.yqcdeki3ntkrrl2t@randomstring.org> <51804f85-9275-4d89-9dc2-86234cdb299b@borg.org> <20240801210627.bzw47tfmyxofcep3@randomstring.org> <82b0d41d-075d-496e-9e1f-ef1529623c38@borg.org> <20240801182824.4bf21319.Richard.Pieri@gmail.com> <f6d905fd-7886-4cf2-9b02-f6d89f60adf0@borg.org> <20240801214606.5bebc46a.Richard.Pieri@gmail.com> <20c3240d-184f-4c84-b4ed-7680ac5301bd@borg.org> <CAJFsZ=o7btMacs-OqTB0908ehYkZCFGtupLkNi59C9K8XV6zKQ@mail.gmail.com>
On 8/3/24 19:05, Bill Bogstad wrote: > What you are basically saying is that we need to write software that > has essentially 0 bugs. I'm saying we need to at least try. The measure of success isn't that there are 0 bugs, it is that that we are reducing the numbers of bugs. And at least eliminating the ones we know about! It isn't just "write software" but make decisions in designing larger systems that make them inherently secure. If the ops people discover the firewall has been off for a time, is that an occasion to turn it back on, or to panic? If it is the latter, then the firewall was a crutch and an excuse to build insecure stuff. Enter the modern CSO. If s/he discovers the firewalls were off for a week, that is an all out emergency. Because they are NOT just an extra protection. Quick, turn them on, and start sifting through the damage. Calm things down, so the CSO can get back to deciding among commercial products that help keep track of what assets a company has, because it is all so chaotic that there is no way of knowing from having *built* it. I like a quite I recently ran across from Peter Gutmann: ? Rule #1: Complexity of the enemy of security. But these days "best practices" is to build such godawful complicated systems that his rule must be perplexing to most people. -kb
- Follow-Ups:
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: daniel at syntheticblue.com (Daniel M Gessel)
- [Discuss] Port Scanning
- References:
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Port Scanning
- Prev by Date: [Discuss] Port Scanning
- Next by Date: [Discuss] Port Scanning
- Previous by thread: [Discuss] Port Scanning
- Next by thread: [Discuss] Port Scanning
- Index(es):