[23509] in APO-L

home help back first fref pref prev next nref lref last post

Re: [APO-L] Security (Was Re: [APO-L] Question of posting...)

daemon@ATHENA.MIT.EDU (Derek J. Cashman)
Tue Feb 4 11:31:52 2003

Date:         Tue, 4 Feb 2003 11:29:35 -0500
Reply-To: "Derek J. Cashman" <derek.cashman@vcu.edu>
From: "Derek J. Cashman" <derek.cashman@vcu.edu>
To: APO-L@LISTSERV.IUPUI.EDU
In-Reply-To:  <3F21F8F1.5112EE87.002124AA@cs.com>

> .htaccess isn't secure because there are people out there with packet
> sniffers, and it's trivial for them to capture the information as it
comes
> across their pipes.  SSL is the most workable scenario because it
encrypts
> the data, is a standard, and is reasonably easy to set up.

While I'm sure this is a very interesting and exciting discussion about
computer network security on the web, let's put this into context and
think how this really applies to Alpha Phi Omega. Like Brother Finder
already pointed out, we're not the CIA protecting valuable espionage
data, or First Union National Bank protecting all of their account
information. The data that we're interested in protecting is mainly some
documents that we wish to make more readily available to all of our
members, without putting them in a publicly-accessible website.

While there are those that are professional network administrators in
their daytime jobs (and apparently quite a few of them online in APO),
that are going to tell you all the gory details of every single loophole
in a computer network, and argue why this type of security protocol is
more secure than this one, I think we have to look more closely at the
actual likelihood that some of these security loopholes will be
exploited in the fraternity. I mean, frankly, if I was a hacker, I
really wouldn't be concerned with hacking into apo.org - I'd probably
set my sights on cia.gov or visa.com or something such as that,... If I
was a spammer looking for addresses, I probably wouldn't be sniffing
packets trying to gain access to some organization's htaccess directory
- there's far better and easier sources to get email addresses!

Of course, I'm not trying to criticize the network administrators and
such. They've got jobs to do and they get paid big money (albeit
probably not enough) to make sure that hackers don't get into the
businesses' computers that aren't supposed to be there and such. What I
think APO needs is some really basic web security that would create
subsections of the national website for various levels of membership.
And I'm not just talking about the Board Policy Manual anymore. There's
quite a few other documents and information that we could make available
to chapters & staff on the website that we may not necessarily want in
the public section. Also, simply looking at the documents page on
apo.org, that lists all the documents available, there's a few in there
that might be better served if they were in a CHAPTER ONLY section as
well. The national technology committee (or whatever it's called), may
actually consider looking into exactly how much information is on the
apo.org website, and how it's organized, and might look into ways to
reorganize things into a BROTHERS ONLY and/or a STAFF ONLY section, and
then leave the public section out for the general public to get an idea
what we're doing and such,...



  _____

Derek J. Cashman (derek.cashman@vcu.edu)
Technology & Electronic Communications (TEC) Coordinator
Alpha Phi Omega; Region III
Graduate Student, Department of Medicinal Chemistry
MCV Campus of Virginia Commonwealth University

  _____

"A Drug is any substance which, when injected into a rat, produces a
publishable, scientific paper."

home help back first fref pref prev next nref lref last post