On Mon, May 08, 2000 at 05:13:52PM -0500, Ed Carp wrote:
( writes:

> > Security truism: if someone *really* wants in, s/he will get in. And
> > there isn't anything you can do about it.

> All you can do is slow them down hopefully long enough to figure out who they are, and try to limit the damage.

        And detect them...

        Security in depth. Rings of security with alarms and traps
in between. If they are going to break in, make THEM be perfect in
finding each and every hole and avoiding each and every trap. Any
single failure on their part should result in detection. The arguements
that you should have perfect applications or perfect operating systems
or perfect perimeter defenses are all bullshit. They all leave you
vulnerable to single points of failure. The only way to turn the tables
on attackers it to make them vulnerable to single points of failure
and keep yourself protected by overlaping layers of defense.

> > We are Linux. Resistance is an indication that you missed the point.

> "We are Pentium of Borg. Division is futile. You will be approximated."
