Re: security


Subject: Re: security
From: Hollis R Blanchard (hollis+@andrew.cmu.edu)
Date: Wed Nov 15 2000 - 09:59:45 MST


On Wed, 15 Nov 2000, Zach Marano wrote:

> I know I shouldn't run everything on one machine but it's all I've got and
> besides nothing is that important here. This is all very experimental
> anyway.

This is a common misconception. "I don't have anything important" is not
an excuse for poor security.

For starters, attackers can use your machine to gain access to your other
machines, especially if it's on the same network, but also if you ever
connect to an important machine from your compromised one.

More importantly (pretending you don't have anything important anywhere),
your machine can be used to attack other machines around the world. That's
how denial of service works, and that's why you have a personal obligation
to me and everyone else connected to this network to keep your box as
secure as is feasible. :)

-Hollis



This archive was generated by hypermail 2a24 : Wed Nov 15 2000 - 10:00:16 MST