Security Incidents mailing list archives
Re: Novarg
From: Matt Curtin <cmcurtin () interhack net>
Date: Thu, 29 Jan 2004 18:31:06 -0500
"Greg A. Woods" <woods () weird com> writes:
No, the _best_ defense against viruses and worms, especially the e-mail borne ones, is to not allow your users to run known vulnerable software in the first place.
[...]
Any user stupid enough to jump through all the hoops which would be necessary to manually execute an attachment deserves what they get.
This isn't likely stupidity, but in fact ignorance. Thus the need for training. [This is the end of my remarks directed to Greg; the rest is much more general, for all of us, including myself. Yes, I talk to myself frequently.] People make mistakes. Software fails. We should design our systems understanding these truths, so that when either condition takes place, we handle the condition as gracefully as we can. Yes, I hate Microsoft "LookOut!" as much as anyone else, but the problems that we're facing are much more complex. People have improper expectations -- that they should be able to sit in front of something and without having invested three minutes into understanding the tool or the task, start Doing Stuff. This is utter nonsense. We do have much better software available -- I use Gnus -- but these systems that are more sophisticated, make users more productive, and treat data with the proper level of safety will require more user training than those that try to figure out what the user really wants, thus "helpfully" doing things like automatically opening attachments, executing macros, and the like. People cannot be expected to understand something if no one has taken the time to explain to them that the lowest cost of entry or the most shallow learning curve is only the beginning, and ultimately a very small part of the experience of using something over a lifetime. If we're so very clever and The Users are so very stupid, why is it that we, who ultimately control all of this crap, cannot keep it from biting us in the butts? Bitching about users solves nothing. We need to shut up and do something productive. Articulating requirements that include security requirements and refusing to allow software that fails to meet them is a good start. But ultimately, unless we help people to see things differently, to try to understand what they're doing before they attempt it, we're just dealing with one kind of problem, while leaving unaddressed another. -- Matt Curtin, CISSP, IAM, INTP. Keywords: Lisp, Unix, Internet, INFOSEC. Founder, Interhack Corporation +1 614 545 HACK http://web.interhack.com/ Author of /Developing Trust: Online Privacy and Security/ (Apress, 2001) --------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- Novarg sloppy seconds (Jan 28)
- Re: Novarg Jonathan A. Zdziarski (Jan 28)
- Re: Novarg James Riden (Jan 28)
- Re: Novarg Jim Zajkowski (Jan 28)
- Re: Novarg Nick FitzGerald (Jan 29)
- Re: Novarg Greg A. Woods (Jan 28)
- Re: Novarg Jonathan A. Zdziarski (Jan 28)
- best defense (was: Re: Novarg Meritt James (Jan 29)
- Re: best defense (was: Re: Novarg Greg A. Woods (Jan 30)
- Re: Novarg Matt Curtin (Jan 30)
- Re: Novarg Matt Curtin (Jan 29)
- Re: Novarg Jonathan A. Zdziarski (Jan 28)
- RE: Novarg - Stopping .Zip Files Tom Milliner (Jan 28)
- Re: Novarg - Stopping .Zip Files Keith W. McCammon (Jan 28)
- Re: Novarg - Stopping .Zip Files Alvin Mills (Jan 30)
- RE: Novarg - Stopping .Zip Files jamesworld (Jan 28)
- Re: Novarg - Stopping .Zip Files Bill Pennington (Jan 28)
- RE: Novarg - Stopping .Zip Files Timmothy Posey (Jan 30)
- Re: Novarg - Stopping .Zip Files Alvin Mills (Jan 30)
- Re: Novarg - Stopping .Zip Files Keith W. McCammon (Jan 28)
- Re: Novarg Dave Laird (Jan 28)
- RE: Novarg Wayne S. Ackley (Jan 28)
