[8816] in Commercialization & Privatization of the Internet
Re: VERY serious $ Business now done on Internet
daemon@ATHENA.MIT.EDU (Erik E. Fair" (Your Friendly Postm)
Sun Dec 5 22:00:53 1993
From: "Erik E. Fair" (Your Friendly Postmaster) <fair@apple.com>
In-Reply-To: <931205183146.f1b@SDG.DRA.COM>
To: com-priv@psi.com
Date: Sun, 05 Dec 93 19:00:20 -0800
To underscore Sean Donelan's point - there is a private T1 link between
Apple and IBM AWD in Austin, TX, and you can bet that we're not using
AppleTalk or SNA over it: it's TCP/IP, all the way. All we did was
connect our respective perimeter networks together; the same security
arrangements that keep the rest of the Internet out of our internal
networks, keeps IBM out too (and vice versa). I would be surprised to
find that we're the only ones doing this sort of thing.
However, it is also important for me to *strongly* echo Dave Farber's
point on network security: the aforementioned T1 has a link-level
encryptor on it, mostly for IBM's peace of mind - Apple generally
trusts its leased line providers, but I would *never* trust an Internet
network service provider similarly; I understand the technology well
enough to know that it would expose us too much. If we ever decide to
run internal or otherwise sensitive data through the sections of the
Internet where that is permitted, you can bet that, at minimum, the
data portion of those IP packets will be encrypted.
The thing that appalls me thoroughly is that the security folks who I
talk to in the IETF seem to be completely unwilling to even talk about
prophylactic measures, which, while understood to be inadequate in and
of themselves, do raise the ante for a potential attacker. They want
their crypto-nirvana, and while I want one too (maybe theirs and maybe
not - I'm still not sure on how I want the support structure to come
about), I want to shore up the levees now, with whatever is on hand,
before the river overwhelms us, rather that wait, six feet under, for
the Army Corps of Engineers to build a wonderful new flood control
system.
And since I'm on a roll here - one more group of folks to take a whack
from me: the systems vendors. I see almost no work on replacing the
standard TCP/IP applications with secured versions of same (encrypted
telnet sessions, PEM, etc), unless we all pay *extra* for it. Some of
them are waiting for others to do the work (like waiting for OSF DCE,
before doing the Kerberos integration work that everyone will need to
do). To top it off, most of their systems come configured insecure
(accounts without passwords, etc), which leaves me with a terrible
problem: trying to make sure that every one of these systems is secured
before it goes online. Given that each "UNIX" systems vendor has its
own proprietary extensions ("SMIT happens!"), this is a nasty M by N
problem.
There's almost no point in talking about those "operating systems"
where the hardware MMU isn't used to protect "kernel" code &
variables; as a friend of mine is wont to say about the challenge of
attacking such a system, "it's like kicking puppies."
As much as I detest the litigious nature of American society, it may
take a large tort judgement against someone like Sun or IBM before they
accept appropriate responsibility, and act. I do not mean act by
providing patches for known bugs - I mean working with (or pushing, as
necessary) the IETF to define standards for secured application
protocols in the Internet, and then putting real effort behind quick
and through implementation of those standards, and then *bundling* that
software with their systems. Clearly, the Internet Worm incident of
1988 didn't wake 'em up.
Erik E. Fair apple!fair fair@apple.com
P.S. Dr. David Clark of MIT LCS has also been trying to raise the
security alarm in the context of the greater Internet. If he
comes to your neck of the woods to give a talk, go & listen!