BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Port Scanning
- Subject: [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- Date: Sun, 4 Aug 2024 14:27:40 -0400
- In-reply-to: <f56c3f03-6f8e-4e39-bb95-705111b0fbc6@borg.org>
- References: <5c43eee0-caaf-45d6-8fdb-273cb3d8ea6d@borg.org> <20240801172933.yqcdeki3ntkrrl2t@randomstring.org> <51804f85-9275-4d89-9dc2-86234cdb299b@borg.org> <20240801210627.bzw47tfmyxofcep3@randomstring.org> <82b0d41d-075d-496e-9e1f-ef1529623c38@borg.org> <20240801182824.4bf21319.Richard.Pieri@gmail.com> <f6d905fd-7886-4cf2-9b02-f6d89f60adf0@borg.org> <20240801214606.5bebc46a.Richard.Pieri@gmail.com> <20c3240d-184f-4c84-b4ed-7680ac5301bd@borg.org> <CAJFsZ=o7btMacs-OqTB0908ehYkZCFGtupLkNi59C9K8XV6zKQ@mail.gmail.com> <f56c3f03-6f8e-4e39-bb95-705111b0fbc6@borg.org>
On Sun, 4 Aug 2024 09:45:06 -0700 Kent Borg <kentborg at borg.org> wrote: Security is not a state. It's an iterative process. I originally wrote a lot of tearing down of straw-man assertions like firewalls failing open (they don't: they fail closed so there is no access in or out and therefore there is no damage). But instead I deleted almost all of that to focus on this: > I like a quite I recently ran across from Peter Gutmann: > > ? Rule #1: Complexity of the enemy of security. Two errors here. First, the original quote is, "[t]he worst enemy of security is complexity." This is an admonition to design systems to be no more complex than is required of them. Which is a good general design philosophy. A corollary is that just because *you* don't understand it doesn't mean that the people who do understand it are unable to keep it secure. "Most people" don't need to know the difference between a Layer 3 firewall and a Layer 7 firewall any more than they need to know how heat catalyzes chemical reactions in batter to make fluffy pancakes. Second, it was Bruce Schneier who wrote this. https://www.schneier.com/essays/archives/1999/11/a_plea_for_simplicit.html -- \m/ (--) \m/
- References:
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- Prev by Date: [Discuss] Port Scanning
- Next by Date: [Discuss] Port Scanning
- Previous by thread: [Discuss] Port Scanning
- Next by thread: [Discuss] Port Scanning
- Index(es):