[56478] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Question concerning authoritative bodies.

daemon@ATHENA.MIT.EDU (Valdis.Kletnieks@vt.edu)
Sun Mar 9 14:35:59 2003

To: Jack Bates <jbates@brightok.net>
Cc: nanog@merit.edu
In-Reply-To: Your message of "Sun, 09 Mar 2003 13:09:14 CST."
             <00a101c2e66f$604b4860$624b4041@jackdell> 
From: Valdis.Kletnieks@vt.edu
Date: Sun, 09 Mar 2003 14:35:11 -0500
Errors-To: owner-nanog-outgoing@merit.edu


--==_Exmh_-1015405397P
Content-Type: text/plain; charset=us-ascii

On Sun, 09 Mar 2003 13:09:14 CST, Jack Bates said:

> There are private systems in use today like NJABL which act as centralized

private systems. Plural. Because..

> resources. I believe that it is possible to come to an agreement on a
> standardized test suit that can be used and what the variables concerning #
> of scans and how frequent should be set to. I'm not suggesting a full

Forgive my cynicism, but... you're saying this on the same mailing list where it's possible to
start a flame-fest by saying that ISP's should ingress-filter RFC1918 source
addresses so they don't pollute the net at large? ;)

I've been participating in the Center for Internet Security development of
security benchmarks - it was hard enough to get me, Hal Pomeranz, and the
reps from DISA and NSA to agree on standards for sites to apply *to themselves*.
There's a lot of things that I think are good ideas that I don't want other
sites checking for, no matter how well intentioned they are.

I'd just *LOVE* to hear how you intend to avoid the same problems that the crew
from ORBS ran into with one large provider who decided to block their probes.
Failing to address that scenario will guarantee failure....


--==_Exmh_-1015405397P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQE+a5dvcC3lWbTT17ARAg5ZAJ0ci7aeFLa6fmhoUuUXNQgdZYc9yACgsuV6
noMckSKx25U+1uoYy2lU6Hk=
=Z8+E
-----END PGP SIGNATURE-----

--==_Exmh_-1015405397P--

home help back first fref pref prev next nref lref last post