home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.security.misc:2298 alt.comp.acad-freedom.talk:3778
- Path: sparky!uunet!cs.utexas.edu!sun-barr!ames!pacbell.com!pacbell!oracle!unrepliable!bounce
- Newsgroups: comp.security.misc,alt.comp.acad-freedom.talk
- From: mfriedma@uucp (Michael Friedman)
- Subject: Re: Security vs usefulness (was Re: reasons
- Message-ID: <1992Dec16.173049.19678@oracle.us.oracle.com>
- Sender: usenet@oracle.us.oracle.com (Oracle News Poster)
- Nntp-Posting-Host: appseq
- Organization: Oracle Corporation
- References: <1992Dec14.173636.10834@ncsa.uiuc.edu> <1992Dec14.211255.15839@lambda.msfc.nasa.gov> <1gkpsmINNn05@iraul1.ira.uka.de>
- Date: Wed, 16 Dec 1992 17:30:49 GMT
- X-Disclaimer: This message was written by an unauthenticated user
- at Oracle Corporation. The opinions expressed are those
- of the user and not necessarily those of Oracle.
- Lines: 45
-
- In article <1gkpsmINNn05@iraul1.ira.uka.de> s_titz@ira.uka.de (Olaf Titz) writes:
- >In article <1992Dec14.211255.15839@lambda.msfc.nasa.gov> palmer@Trade_Zone.msfc.nasa.gov writes:
- > ^^^^^^^^
- >You see that the following applies largely to government/military only?
-
- >>>The main job of security is to stop the user from getting his work
- >>>done.
-
- >>I disagree, security is not a win/lose scenario...granted when the
- >>security officer takes the easy way out when fixing a problem, the end
- > ^^^^^^^^^^^^^^^^
-
- >I really don't know about installations where the security people are
- >officers...
-
- Personally, I don't think that you know about any installation where
- there is any need for security, period.
-
- >>user usually loses functionality or useability. But when the careful
- >>security officer carefully considers the situation, there is almost
- >>always a win/win solution.
-
- >...but here (academic) every "security" effort has always been
- >inevitably a lose/lose situation. More hassle to deal with on one
- >side, less usability on the other.
-
- >You run into this as soon as you start thinking, "the less I allow to
- >the users the less damage can/will they do", which is wrong, imho.
-
- >But if the changes involve (e.g.) hiding an
- >entire subnetwork behind a firewall, this *does* affect the users. And
- >if you argue, "these particular users have all data they ever have to
- >deal with on their local machines and may not do anything else", well,
- >you're talking government, I'm talking academic. But we (academic)
- >have to live with people and OSs who confuse security and unusability,
- >too.
-
- Olaf, do you really believe that an academic site should put computers
- that students can access on the same network as the ones containing
- grades, financial data, and medical records without putting in major
- firewalls between the networks?
-
- --
- -------------------------------------------------------------------------------
- I am not an official Oracle spokesman. I speak for myself and no one else.
-