BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Port Scanning
- Subject: [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- Date: Sun, 4 Aug 2024 17:23:58 -0400
- In-reply-to: <fe454c27-b14b-4ae7-b025-48c2c2e0441d@borg.org>
- References: <5c43eee0-caaf-45d6-8fdb-273cb3d8ea6d@borg.org> <20240801172933.yqcdeki3ntkrrl2t@randomstring.org> <51804f85-9275-4d89-9dc2-86234cdb299b@borg.org> <20240801210627.bzw47tfmyxofcep3@randomstring.org> <82b0d41d-075d-496e-9e1f-ef1529623c38@borg.org> <20240801182824.4bf21319.Richard.Pieri@gmail.com> <f6d905fd-7886-4cf2-9b02-f6d89f60adf0@borg.org> <20240801214606.5bebc46a.Richard.Pieri@gmail.com> <20c3240d-184f-4c84-b4ed-7680ac5301bd@borg.org> <CAJFsZ=o7btMacs-OqTB0908ehYkZCFGtupLkNi59C9K8XV6zKQ@mail.gmail.com> <f56c3f03-6f8e-4e39-bb95-705111b0fbc6@borg.org> <822928a0-59d6-4e8c-8731-448452e98df7@syntheticblue.com> <fe454c27-b14b-4ae7-b025-48c2c2e0441d@borg.org>
On Sun, 4 Aug 2024 12:38:00 -0700 Kent Borg <kentborg at borg.org> wrote: > Rich Pieri <richard.pieri at gmail.com> wrote: > > > First, the original quote is, "[t]he worst enemy of security is > > complexity." > Okay. > > And I am quoting Peter Gutmann, circa now. I like his version better. Yes, well, it seems to me that you still aren't getting it. Peter is not saying that complexity is bad. What they are saying is that more complexity makes security -- the thing you do -- more difficult. But I disagree with the assertion as presented because it incorrectly suggests that complexity is the only enemy of security. Excessive simplicity also is an enemy of security. I think you are not stupid; I would not be writing this if I thought you were. I think you have a strongly polarized good/bad view of things. I think perhaps you have become jaded by the incessant reports of this or that company or hospital suffering a breach of customer or patient records or being locked out by ransomware because some C-suite executives wouldn't pay for good security practices, or because some security company cut corners and pushed an untested update onto an unsuspecting world on a Friday. I think your stubborn rejection of tried and proven security tools is not conducive to good security practices. You can't write security. You can't buy security and install it. Security is a process. It's something you do, something you practice, every day. As threats evolve, so too must security practices. Sometimes this means hiring expertise to help turn chaos into order. Sometimes we need new tools to help us organize and manage our large, complex environments. Sometimes we need new tools to protect against new threats when existing tools are insufficient. Adding appropriate expertise and proper tools does not make our environments more complex. They make our environments more understandable and more manageable and thus easier for us to keep secure. I previously mentioned that my employer is a Cortex (PaloAlto) customer. Initially deploying Cortex across every machine on our network was a lot of work but it's automated now (I have the Ansible play to prove it). But rather than making the environment more complex, Cortex has made it more understandable and more manageable. We have a centralized dashboard providing an overview of everything on our network. We have a 24-hour staffed SOC (systems operation center) monitoring this dashboard and with the ability to isolate any machine when suspicious or malicious activities are detected. Sometimes less is more. But when it comes to enterprise security, sometimes more is more -- as long as it's the right more. -- \m/ (--) \m/
- References:
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- From: daniel at syntheticblue.com (Daniel M Gessel)
- [Discuss] Port Scanning
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Port Scanning
- Prev by Date: [Discuss] Port Scanning
- Next by Date: [Discuss] Port Scanning
- Previous by thread: [Discuss] Port Scanning
- Next by thread: [Discuss] Port Scanning
- Index(es):