[93855] in North American Network Operators' Group
Re: Security of National Infrastructure
daemon@ATHENA.MIT.EDU (Mark Foster)
Fri Dec 29 18:12:21 2006
Date: Sat, 30 Dec 2006 12:10:14 +1300 (NZDT)
From: Mark Foster <blakjak@blakjak.net>
To: Peter Corlett <abuse@cabal.org.uk>
Cc: nanog@nanog.org
In-Reply-To: <BFE272A5-DCAD-478B-8970-ECEBF2B4B97B@cabal.org.uk>
Errors-To: owner-nanog@merit.edu
On Fri, 29 Dec 2006, Peter Corlett wrote:
>
>> Why is it that every company out there allows connections through their
>> firewalls to their web and mail infrastructure from countries that they
>> don't even do business in. Shouldn't it be our default to only allow US
>> based IP addresses and then allow others as needed? The only case I can
>> think of would be traveling folks that need to VPN or something, which
>> could be permitted in the Firewall, but WHY WIDE OPEN ACCESS? We still
>> seem to be in the wild west, but no-one has the b@lls to be braven and
>> block the unnecessary access.
>
> I assume you want this:
>
> http://geekculture.com/joyoftech/joyarchives/446.html
>
> Most "unnecessary access" I see seems to be coming from US-based IP addresses
> anyway. A Great Firewall Of USA would certainly reduce the amount of spam I
> get :)
>
Hear Hear!
It'd be amazing how much easier my mail handling life would be if I could
blindly drop *.comcast.net without worrying about collateral damage.
(Some years ago I had to ring an ISP in the US - and i'm in NZ - and ask
them by _phone_ why they appeared to be filtering connections from here to
their web server, despite the fact we were one of their customers. Turns
out that they had inbound filters applied to 202/8. Whoopsie?)
Mark. (Its the Internet, not the USofA-net. Damnit!)