Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
When networks fail, hams to the rescue
Alliance to promote Windows-managed Macs in enterprise
Lockheed Martin gets $89 million to converge DoD distribution networks
Clothes don't make this man: Sweatshirt helps nail Citibank card scammer
Microsoft readies new try for Yahoo
Gartner: Seven cloud-computing security risks
Autonomy, Endeca rate among top enterprise search vendors
Barracuda countersues Trend Micro in patent case
Mozilla's Firefox 3 sets geeky world record
Microsoft SharePoint popularity comes with issues
IBM mainframe acquisition raises antitrust concerns
Diary of a deliberately spammed housewife
Report: Tech giants forming 'patent troll' alliance
Trojan lurks, waiting to steal admin passwords
California enacts cell-phone driving ban
/

Portable firewall circumvention

Today's breaking news
Send to a friendFeedback

Advertisement:


A few months ago, I put a new 10G-byte disk drive in my Macintosh 2400 laptop. That expanded the original capacity of the computer to the point where I could carry the basic business data for much of Harvard wherever I went - if I had a mind to do that and if the university was dumb enough to let me do it. Sounds unlikely, but all too many businesses let their traveling executives do things that are just about that dumb.

Businesses spend tens of thousands of dollars to install and operate firewalls to protect their corporate secrets from Internet intruders. But in doing so, too many seem to think that installing the firewall somehow magically makes all security problems disappear. There are a number of reasons why this borders on self delusion.

Every study that looks at the perpetrators of effective (if that is a reasonable word to use) network-based intrusion shows the majority are insiders, or outsiders working with inside help. Because firewalls do not keep out people who are already inside, they are of limited assistance in these cases. Installing firewalls also tends to make users and sometimes network managers so complacent that they forget the basics of good network security, such as using good passwords or physical token-based authentication.

This does not mean organizations should forego the use of firewalls, but it does mean they should not assume firewalls are some sort of magic pill that cures stupidity.

Firewalls certainly do not cure the stupidity of corporate executives carrying piles of corporate and often private secrets in plain-text files on their laptops and palmtops. A lot of information tends to pile up on these machines: copies of old e-mail, spreadsheets of budgets, proposals for changing corporate direction or for new products, even auto-logon scripts for dialing in when on the road.

There might be more effective ways to find out what is going on in a corporation than to steal the CEO's laptop, but it would take me a while to think of one.

For a while there have been products around to keep laptops from booting without entering a password, plugin card or serial port attachment, but these can be circumvented by moving the disk drive to another computer.

There is also software that lets the user encrypt files on the disk, but the reliability of this software depends on the reliability of the user taking the time and trouble to do the encryption every time - and not writing the password on the laptop case. The only safe ways to carry corporate secrets on a laptop is to not do so or encrypt the whole disk, and there are products to perform that function. In the end, it is cheaper to lose the data due to a forgotten password than reveal the secrets to the wrong person.

Disclaimer: Harvard's business is not curing stupidity, it is nurturing intelligence. The above is my own too-full disk.

RELATED LINKS

Bradner is a consultant with Harvard University's University Information Systems. He can be reached at sob@sobco.com

What do you think? Jump into nwfusion.talk and start a thread.

More 'Net Insider columns

Read more Scott Bradner via our Gibbs & Bradner weekly e-mail newsletter.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.