home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!pitt.edu!mgkst1
- From: mgkst1+@pitt.edu (Michael G Koopman)
- Newsgroups: comp.security.misc
- Subject: Re: Mail forging
- Summary: Informed users are your best security investment
- Keywords: mail, user awareness
- Message-ID: <9937@blue.cis.pitt.edu.UUCP>
- Date: 20 Nov 92 03:07:09 GMT
- References: <4225@bcstec.ca.boeing.com> <BxrJCL.9sC@mtholyoke.edu> <PC123.92Nov15191454@bootes.cus.cam.ac.uk>
- Sender: news+@pitt.edu
- Followup-To: poster
- Organization: University of Pittsburgh
- Lines: 42
-
- As a user not aware of many security issues since I have real work to
- do and almost a life therefore not enough time to read this newsgroup
- - OOPS gotta go.....
-
- If I recall where this began correctly the original issue concerned
- mail forgery by a cracker requesting that a user change her password.
- A site at which user's will naively change passwords based on an
- e-mail message has not kept up on enlightenment of the users. Any
- user should verify such a message in some way before acting on it.
-
- Naive users may be a system administrators worst security risk. By
- following this track it seems obvious that sys admins may consider
- more layers of faulty security code the right thing. As a user at my
- company I feel obliged to poke my head out of the foxhole to see if
- someone is coming, once in a while, at least. When "funny" things
- happen here the system administration is informed. The administrators
- need to have the experience to recognize which curiousities show the
- greatest potential for revealing security holes.
-
- There is more than one benefit to teaching users to "pester" root
- about unexpected occurrences. The "funny" things users notice which
- are not the result of unauthorized access are likely to be the result
- of user errors. Less user errors mean more productive systems which
- means sys admins get raises, right? Well, in a perfect world ....
-
- Make your users your allies.
-
- If your users know how the box is supposed to act they can tell you
- when it isn't doing what it should which ~might~ help flag
- impropriety. If the box (user activities included) is acting as it is
- supposed to act isn't the sys admin doing 90% of her job right,
- anyway? That additional 10% as deputy sheriff is just to prove you
- hate those bad guys, anyway. In the U.S. isn't the FBI supposed to
- keep the lines free from wiretaps and the like (with all of us good
- citizens' help, of course)? If you have significant security risks,
- e.g. interpol records, what the Henry Ford are you doing on publicly
- accessible nets? IMHO
- --
- Mike Koopman
- Concurrent Technologies Corporation phone: +1-814-269-2637
- 1450 Scalp Avenue telefax: +1-814-269-2666
- Johnstown, PA 15904 e-mail: koopman@server1.ctc.com
-