Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Results, Not Resolutions
Bruce Schneier and Adam Shostack , SecurityFocus 2002-01-24

A guide to judging Microsoft's security progress.

Comments Mode:
Results, not Resolutions 2002-01-24
Anonymous
Results, not Resolutions 2002-01-24
Gary McGraw
Results, Not Resolutions 2002-01-24
David Litchfield (2 replies)
Results, Not Resolutions 2002-01-24
davep (at) pitt (dot) edu [email concealed] (1 replies)
Results, Not Resolutions 2002-01-25
Nicholas Harring
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-24
Anonymous (1 replies)
Results, Not Resolutions 2002-01-24
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
No SOAP? How do you do remote procedure calls over the web? 2002-01-25
Anonymous (6 replies)
No SOAP? How do you do remote procedure calls over the web? 2002-01-25
Anonymous
IIOP and CORBA are not tunneled over HTTP solely to bypass firewalls.

Those firewalls are there for a reason! Obviously, the firewall can't protect from actively malicious tunneling through HTTP, but widespread use of SOAP will open up whole new classes of security problems when every VB or Java 'programmer' makes SOAP calls with no thought to the trustworthiness of the channel and remote agent.

Widespread RPC is the kind of thing that must be carefully designed and implemented to minimize these problems. Fast-tracking it past IT security professionals by trying to pass it off as a previously accepted protocol is not conducive to this.

Security will suffer until people upgrade their simple layer 3 firewalls to do layer 7 introspection, making them more complicated and less secure.

Perhaps before you accuse others of speaking beyond their knowledge, you should consider the limits of your own.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/315/10140#10140
Your Homework! 2002-01-25
Anonymous
Well, to conclude: Use Java, M$ 2002-01-25
Anonymous (1 replies)
Well, to conclude: Use Java, M$ 2002-01-25
Trithemius (1 replies)
Well, to conclude: Use Java, M$ 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
BMaximus
SOAP Recommendation is Silly 2002-01-25
Anonymous (1 replies)
SOAP Rec is correct 2002-01-26
Anonymous
Almost right on the compensation 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Chris
Regarding macros in documents... 2002-01-25
Anonymous
Things getting out of hand here? 2002-01-26
Toni Heinonen
Microkernel smog 2002-01-27
Grumpf
Inaccuracies and crazy talk 2002-01-28
Anonymous
Results, Not Resolutions 2002-01-28
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus