home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: alt.security
- Path: sparky!uunet!cis.ohio-state.edu!zaphod.mps.ohio-state.edu!wupost!uwm.edu!linac!att!cbnewsi!cbnewsh!cbnewsh.cb.att.com!wcs
- From: wcs@anchor.ho.att.com (Bill Stewart +1-908-949-0705)
- Subject: Re: A Solicitation for Opinions
- Organization: Sorceror's Apprentice Cleaning Services, Ltd.
- Date: Fri, 6 Nov 1992 05:24:46 GMT
- Message-ID: <WCS.92Nov6002446@rainier.ATT.COM>
- In-Reply-To: johan@blade.stack.urc.tue.nl's message of 5 Nov 92 15:53:59 GMT
- References: <6035@tuegate.tue.nl> <Bx6oLy.L7z@minerva1.bull.it>
- <1992Nov4.153248.12490@ulysses.att.com> <6183@tuegate.tue.nl>
- Sender: news@cbnewsh.cb.att.com (NetNews Administrator)
- Nntp-Posting-Host: rainier.ho.att.com
- Lines: 24
-
- In article <6183@tuegate.tue.nl> johan@blade.stack.urc.tue.nl (Johan Wevers) writes:
- smb@ulysses.att.com (Steven Bellovin) writes:
- >Assuming, of course, that you can trust their answers... That's the
- >thing -- I regard computer break-ins, especially those that are done
- >for ``fun'' or ``knowledge'' as a manifestation of ethical issues. Given
- >that, by default I do not trust the offenders. I'm willing to be
- >persuaded otherwise, but the burden of proof is on them, not me.
-
- This is bullshit: you can check the answers by an expert. Most security
- holes are just overlooked by experts, but they're certainly capable to
- see whether something is a hole or not when they're pointed at.
-
- Steve *is* an expert :-) Besides, if you're a Bad Guy,
- one valuable technique is to get a privileged person to try something,
- and leave something around to watch them while they do it.
- If they're only a pseudo-expert, that may give you root,
- but even if they're a real expert, you may still benefit from seeing what
- they try, or what they don't try, or what they explore before they try
- the suggestion you gave them....
- --
- # Pray for peace; Bill
- # Bill Stewart 908-949-0705 wcs@anchor.att.com AT&T Bell Labs 4M312 Holmdel NJ
- # Nov 12 - Anniversary of Indonesian massacre in East Timor, 1991
- # Indonesia first invaded in 1975, and about 1/3 of the people have been killed.
-