Firewall Wizards mailing list archives
Re: Re: Flawed Surveys [was: VPN endpoints]
From: "Paul D. Robertson" <paul () compuwar net>
Date: Wed, 1 Sep 2004 20:34:42 -0400 (EDT)
On Wed, 1 Sep 2004, Bruce B. Platt wrote:
How appropriate for this thread. Who wants to admit in a survey that they aren't doing what is needed to stay secure?
Surprisingly enough, there are people who will. A lot of it depends, I think, upon the goal of the survey- things people have a vested interest in the outcome of seem to get straighter answers than things where the information doesn't seem to have a direct benefit- or maybe it's something else, but I've done some limited test surveys[1] specifically about security inside an organization (not blind either) where the results varied a little between respondents in a company, but where they admitted where things were weak.
Referring to your blaster comments, why don't we just start plotting reverse lookups of probes from infected outward-facing machines, or spewers of virus laden mail and then use that data to create a db of "insecure" organizations. (ad hoc definition of an insecure organization.)
The issue with the probe stuff is that I could start spewing spoofed packets to make my competitors look bad. However, I'm all up for a good listing of probes, spam and worms by company. Depending on the terms and wiggle stuff, I might be willing to host it- I'll have to think about the potential liability downsides first though.
Take that, then survey executives from those firms and other firms with small numbers of outward-directed probes or virus transmissions. There is an operational definition of insecurity stated above which can be compared to survey results. Perhaps this gets around the self-selected issue as well as some others.
Might be worth spinning up a network-admin-based f'd company type site too- maybe start building a club to beat some of the more irresponsible companies into submission... Paul [1] Non-scientific, poor question format, covered in brown polish. Never used the results, other than to see how my views of the organizations differed with the IT staff. ----------------------------------------------------------------------------- Paul D. Robertson "My statements in this message are personal opinions paul () compuwar net which may have no basis whatsoever in fact." probertson () trusecure com Director of Risk Assessment TruSecure Corporation _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: Flawed Surveys [was: VPN endpoints], (continued)
- Re: Flawed Surveys [was: VPN endpoints] Paul D. Robertson (Sep 01)
- Re: Flawed Surveys [was: VPN endpoints] Marcus J. Ranum (Sep 01)
- Re: Flawed Surveys [was: VPN endpoints] Paul D. Robertson (Sep 01)
- Re: Re: Flawed Surveys [was: VPN endpoints] Christopher Hicks (Sep 01)
- Re: Re: Flawed Surveys [was: VPN endpoints] Bruce B. Platt (Sep 01)
- RE: Re: Flawed Surveys [was: VPN endpoints] Tina Bird (Sep 01)
- Re: Re: Flawed Surveys [was: VPN endpoints] Bruce B. Platt (Sep 01)
- RE: Re: Flawed Surveys [was: VPN endpoints] Tina Bird (Sep 01)
- Re: Re: Flawed Surveys [was: VPN endpoints] Bruce B. Platt (Sep 01)
- Wired article on the scientific method Tina Bird (Sep 01)
- Re: Re: Flawed Surveys [was: VPN endpoints] Paul D. Robertson (Sep 01)
- Re: Re: Flawed Surveys [was: VPN endpoints] Crispin Cowan (Sep 01)
- Re: Re: Flawed Surveys [was: VPN endpoints] Adam Shostack (Sep 03)
