[23504] in APO-L

home help back first fref pref prev next nref lref last post

Re: [APO-L] Question of posting National Board Policy Manual online

daemon@ATHENA.MIT.EDU (John Grossi)
Tue Feb 4 08:08:42 2003

Date:         Tue, 4 Feb 2003 13:08:31 +0000
Reply-To: jgrossi@attbi.com
From: John Grossi <jgrossi@attbi.com>
To: APO-L@LISTSERV.IUPUI.EDU

> Not to put a damper on this, but .htaccess is not a secure solution,
> just like Telnet or FTP aren't secure.

No solution is completely secure, it's the nature of computers. As a General
at Fort Huachuca once stated to me a number of years ago the ONLY way to
secure a computer is to cut all cables coming out of the CPU; encase it in
cement; and sit a private with a gun on it. What we have these days are
solutions that make a break in less probable, but don't delude yourself that
"you're secure". Your biggest point of failure in any computer system isn't
the technology, but the people using it. If security is too tight people will
intentionally circumvent it.

Personally if people wanted a "secure solution", SSL with client side certs is
probably the "best" solution. Secure enough the random people won't crack it
for amusement value, but not so secure that the users circmvent it for their
conveinence.

Another thing that should be clear is the nature of "the net".

Once the net gets it's fingers on your information it doesn't let go. So
if people post "it" to a news group, or to a listserv, e-mail it via any
large ISP, or put it in a shared directory, it's pretty certain it's still
there. As an example when I was working at BBN we had complete backups of
email and systems dating to the 1960s as recently as last year. So if it
heads out on to the net in *any* form be certain that it is permanently
recorded and a court of law can find it.

> If the information is considered wholly confidential, we should either
> make it a request-only situation (information on hardcopy), or go all
> the way and implement SSL.

If the information is wholly confidential it should be a request only
situation on paper. Any computer technology has security holes, it's the
nature of the beast.

> This will keep the security controls AND the
> information safe from people with packet sniffers.

dude, the only real secure solution is to leave it on paper.

>
> With the concerns about security that have been popping up lately, I
> don't think it's appropriate to use a solution that gives, at best, a
> false sense of security.

Let me make it clear... there is no such thing as complete computer security.
It's just a matter of staying one step ahead while remaining such that your
users don't throw your security model out the window because it's inconveinent.

-John

home help back first fref pref prev next nref lref last post