[23514] in APO-L

home help back first fref pref prev next nref lref last post

Re: [APO-L] Security (Was Re: [APO-L] Question of posting...)

daemon@ATHENA.MIT.EDU (Christopher Stromberg)
Tue Feb 4 13:12:10 2003

Date:         Tue, 4 Feb 2003 09:56:52 -0800
Reply-To: Christopher Stromberg <cstrombe@stanford.edu>
From: Christopher Stromberg <cstrombe@stanford.edu>
To: APO-L@LISTSERV.IUPUI.EDU
In-Reply-To:  <002701c2cc6a$9b0faa50$a959ac80@isbdd.vcu.edu>

Brothers,

        This may seem slightly off topic, but I have been following this
discussion of posting stuff on the web, and I wanted to make a general
comment for all those chapters who want to post something "securely" on-line.

        As many have said here, nothing is totally secure.  That is not, however,
an excuse to ignore security concerns.  There are two ways to get yourself
hacked into.  The first is to be a high-profile target like the CIA, a
bank, or some other organization where there might be valuable information
available.  The other way is to be stupid about security and leave major
security holes open.

        Don't ask me why, but there are people out there that troll the Internet
simply to find insecure sites and hack into them.  I know this because back
in my college days I had a computer science major, so I got stuck with
maintaining my lab's computer system.  Now, we are talking less than 20
computers in a small lab in the Chemistry Department of a big
university.  About as low-profile as you can get.  We have been hacked into
more times than I care to count.  Computer security was basically
non-existent when I got the job, and I have been playing catch-up every
since (about 4 years now).  One thing that I am told is that, if you get on
a hacker's list of easy sites to break into, he will be back to try again.

        For those chapters setting up web sites with information that they don't
want widely distributed, I would advise extreme caution.  As many have
pointed out, we aren't hiding extremely valuable information, but if you
make your site easy to break into, it will be broken into.  Besides having
the problems of getting your information stolen, you can also open a site
up to distributing viruses and all sorts of other nasty stuff (again,
personal experience talking here).  And again, once you have been broken
into once, people are likely to come back looking for other holes.

        If you are going to maintain a chapter web-site with a "brother's only"
section, please be careful.  Some campuses have a way of setting this up
through their own security systems.  Since they are professionals, I would
strongly advise looking into this before you get started, as they are paid
to worry about security issues.  If such a resource is not available,
consider carefully what and how you are going to put on-line, and basically
assume that anything that you put up could be broken into.  If you aren't
too worried about what the information is, that's fine, go ahead and put it
up.  If you don't want to see the information widely distributed, then don't.

        I apologize for the length of this message, and that we seem to be beating
a dead horse here, but, as someone point out, many chapters are doing this,
and they may be opening themselves up to problems that they don't realize.

Chris Stromberg
Zeta Chapter
Stanford University

home help back first fref pref prev next nref lref last post