Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.laptops > #182

Proper security (Was Re: Oh, God)

From wrat@panix.com (the wharf rat)
Newsgroups comp.sys.laptops
Subject Proper security (Was Re: Oh, God)
Date 2011-05-03 20:25 +0000
Organization Public Access Networks Corp.
Message-ID <ippoc4$l49$1@reader1.panix.com> (permalink)
References <55a0fff7-e1b7-499f-865c-b6ee68cddc37@r4g2000prm.googlegroups.com> <ionn5v$v0i$1@dont-email.me> <ip4tvm$lhj$3@reader1.panix.com> <ipd2n4$d0t$1@dont-email.me>

Show all headers | View raw


In article <ipd2n4$d0t$1@dont-email.me>,
Ryan P. <rdeletepaque@wi.rr.comm> wrote:
>>
>> 	How do you run 2K or XP and not be administrator?  Well, I suppose
>
>  That's why most people don't do it.  Proper security policy would 
>involve you logging out of your regular user account, and logging on as 
>an administrator, doing what you need to do, and then logging off and 
>back on to your user account.

	Proper security includes not causing so much pain that your
policies drive users to non-compliance.  If security prevents work from 
being done 50% of your users will not do any work, and the other 50% will
ignore policy.  100% of the security team will have monster.com as their
home page.

	Windows security is not proper security because to maintain good
posture requires that you dispense with getting anything useful done.
(I'm talking about consumer desktops here.  They're actually very good on
the server side.)  Any organization that deliberately chooses to annoy and
antagonize users to convince 3rd party developers to use a different file 
system layout needs to get their glass navels  polished.

>
>  Yes, its annoying to have to switch accounts in order to change screen 
>resolution or install (or uninstall) anything, but its far more secure.

	It's much LESS secure because people will not perform actions required 
for adequate security (such as software updates) and because people will work
around the roadblock by exploiting ways to elevate their priveleges or 
disregard permissions.

	Perfect security causes 0 pain to legitimate users and 100% pain
to intruders.  You're suggesting that a guard dog that bites everybody is
OK because you can always throw steaks at it until you can sneak by.

---

	I once worked for an agency that would not allow their computers to
connect to any network but one they'd vetted, would not allow you to change
settings on their computers, required staff members to travel extensively,
and required staff members to use electronic systems to work and communicate
while traveling.  See the problem?  Was this good security or not?

Back to comp.sys.laptops | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-16 15:57 -0700
  Re: Oh, God-- What To Do Now? Pen <nospam@spam.none> - 2011-04-16 19:22 -0400
    Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-16 17:51 -0700
      Re: Oh, God-- What To Do Now? retsuhcs@xinap.moc (Mike S.) - 2011-04-17 01:30 +0000
      Re: Oh, God-- What To Do Now? Bob Villa <pheeh.zero@gmail.com> - 2011-04-17 05:47 -0700
        Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-17 17:30 -0700
  Re: Oh, God-- What To Do Now? BJ <backroadjunkie@sbcglobal.net> - 2011-04-17 04:26 -0500
    Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-17 17:22 -0700
      Re: Oh, God-- What To Do Now? Pen <nospam@spam.none> - 2011-04-17 20:45 -0400
      Re: Oh, God-- What To Do Now? "~misfit~" <sore_n_happy@nospamyahoo.com.au> - 2011-04-18 21:05 +1200
        Re: Oh, God-- What To Do Now? Charlie Hoffpauir <invalid@invalid.com> - 2011-04-18 11:35 -0500
      Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-20 06:55 +0000
        Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-21 17:20 -0700
          Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-25 22:49 +0000
  Re: Oh, God-- What To Do Now? "Ryan P." <rdeletepaque@wi.rr.comm> - 2011-04-17 10:14 -0500
    Re: Oh, God-- What To Do Now? Ron <ryon@dslnorthwest.net> - 2011-04-17 17:57 -0700
      Re: Oh, God-- What To Do Now? "Ryan P." <rdeletepaque@wi.rr.comm> - 2011-04-18 19:10 -0500
        Re: Oh, God-- What To Do Now? schotty456_at_gmail_dot_com@foo.com (schotty456) - 2011-04-19 15:29 +0000
          Re: Oh, God-- What To Do Now? Bob Villa <pheeh.zero@gmail.com> - 2011-04-19 09:31 -0700
          Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-20 07:02 +0000
      Re: Oh, God-- What To Do Now? "BillW50" <BillW50@aol.kom> - 2011-04-19 12:00 -0500
        Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-20 07:09 +0000
          Re: Oh, God-- What To Do Now? "Ryan P." <rdeletepaque@wi.rr.comm> - 2011-04-20 17:36 -0500
            Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-25 22:52 +0000
              Re: Oh, God-- What To Do Now? "Ryan P." <rdeletepaque@wi.rr.comm> - 2011-04-28 20:02 -0500
                Re: Oh, God-- What To Do Now? "Joel Koltner" <zapwireDASHgroups@yahoo.com> - 2011-05-02 12:49 -0700
                Proper security (Was Re: Oh, God) wrat@panix.com (the wharf rat) - 2011-05-03 20:25 +0000
                Re: Proper security (Was Re: Oh, God) Robert Sneddon <fred@nospam.demon.co.uk> - 2011-05-05 13:14 +0100
      Re: Oh, God-- What To Do Now? lmarco@panix.com (Lou Marco) - 2011-04-20 06:58 +0000
  Re: Oh, God-- What To Do Now? dg <david.goodnow@gmail.com> - 2011-04-21 18:35 -0700

csiph-web