Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Security for the Paranoid
Mark Burnett, 2005-04-26

Paranoia is the key to success in the security world. Is it time to worry when other security professionals consider you too paranoid?

Comments Mode:
Security for the Paranoid 2005-04-26
norwegian
Security for the Paranoid 2005-04-26
Anonymous (5 replies)
Security for the Paranoid 2005-04-26
Anonymous
Security for the Paranoid 2005-04-27
Rickard Johansson (1 replies)
Re: Security for the Paranoid 2005-06-09
Anonymous
Security for the Paranoid 2005-04-27
Anonymous (1 replies)
Re: Security for the Paranoid 2005-05-25
Bradbury9
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-26
Anonymous (1 replies)
Security for the Paranoid 2005-04-27
Anonymous (1 replies)
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-26
Times Enemy <times@krr.org>
Security for the Paranoid 2005-04-26
styliee
Security for the Paranoid 2005-04-26
Jeroen Kemperman (2 replies)
Security for the Paranoid 2005-04-26
Anonymous (1 replies)
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Shadowkill
Security for the Paranoid 2005-04-26
Anonymous
Security for the Paranoid 2005-04-26
Anonymous (1 replies)
Security for the Paranoid 2005-04-26
Anonymous
Security for the Paranoid 2005-04-26
Anonymous
Security for the Paranoid 2005-04-26
Anonymous
know your enemy 2005-04-26
Anonymous
When Paranoia Annoys Ya 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Kron
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
dan@3-e.net
Security for the Paranoid 2005-04-27
Anonymous (1 replies)
Re: Security for the Paranoid 2005-06-23
Morris Cox
Answers and clarifications 2005-04-27
Mark Burnett (1 replies)
Thank you all, I enjoyed your comments. I wanted to answer some questions and clarify some points so as not to give the wrong idea about what I consider good security. I certainly don't think that stupid security is good security.

Sharing passwords with my wife - I don't share them but she has a method to gain access to my most sensitive passwords in an emergency. Locking out everyone is not prudent. It's by no means an issue of trust, its a matter of practice and policy.

Three Firewalls - 1. Hardware firewall on cable modem, 2. Better hardware firewall because cable modem firewall sucks, and 3. Personal firewall on each pc. Actually, it's four firewalls because the locked down VMWare box has a firewall too.

Five passwords for email - 1. Bios password on my laptop, 2. Syskey password to boot windows (for EFS), 3. Windows login, 4. Encrypted drive password, and 5. e-mail client password. Part of the reason for all this is because my e-mail is on the laptop I also travel with.

Cost/Benefit Ratio - Although I spend an significant amount of time on security, I don't necessarily recommend my clients take the same extreme measures. The cost/benefit ratio of me going to medical school to take care of my family is not justifiable, but to a medical doctor the cost/benefit ratio obviously makes sense. I am a security professional so the cost/benefit model for me is much different than for others. U.S. Secret Service agents are extreme with security so the U.S. President doesn't have to be.

Maybe good for work but not for home - I work at home.

Very long passwords - I will address this in a future column (and in a book later this year) but for now let me say that I can type them just as fast as anyone else with few errors and I always remember them the first day I choose them. They are hardly the burden that most people imagine.

"isn't describing his security setup on a public forum a security lapse" - Is it a security lapse or is it an elaborate paranoid attempt at misinformation? Or maybe I'm just so confident that I can tell everyone this and still know I'm secure.

"you are at 42% where the line is at 50%" - So you're saying I still have 8% of my sanity I can still blow on security? Great!

Same day hotfixes - This one was a little unfair because I am on the Microsoft program to beta test hotfixes, so I already know they work in my environment. I also write several reports and an article about hotfixes the day they come out so I know them pretty well by then. I do recommend testing hotfixes before you install them.




[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/320/31617#31617
Answers and clarifications 2005-04-28
Chatos Anonymous
sounds to be a reflection myself 2005-04-27
<visitbipin hotmail com>
Security for the Paranoid 2005-04-27
Anonymous
What OS are you using? 2005-04-27
Anonymous (1 replies)
What OS are you using? 2005-04-27
Zachary Palmer
Yet you use microsoft products? 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous coward
Security for the Paranoid 2005-04-27
ORBVS
Security for the Paranoid 2005-04-27
Anonymous (1 replies)
Re: Security for the Paranoid 2005-06-23
Morris Cox
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Stephen
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Forget TerraFly, use Google! 2005-04-27
Anonymous Bastard
Security for the Paranoid 2005-04-27
f1r3f1ght3r
Security for the Paranoid 2005-04-27
Anonymous Coward
Security for the Paranoid? 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
josh
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Autoversicherung
Not all that Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
JB kybrdcowboy@hotmail.com
the 50 character password 2005-04-27
Chirayu
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Windows? 2005-04-27
Anonymous (1 replies)
Windows? 2005-05-02
Anonymous
Security for the Paranoid 2005-04-28
SafeCracka
Security for the Paranoid 2005-04-28
cornhead
Security for the Paranoid 2005-04-28
ZeroXeal
Absolutely right, although... 2005-04-28
Dmitry Kirsanov
Security for the Paranoid 2005-04-28
Anonymous
Security for the Paranoid 2005-04-28
Anonymous
Security for the Paranoid 2005-04-28
Anonymous
Security for the Paranoid 2005-04-29
Anonymous
my password is my wife's name 2005-04-29
Anonymous
Due Dilligence vs. Effeciency 2005-04-29
Anonymous
Security for the Paranoid 2005-04-29
Anonymous (1 replies)
Security for the Paranoid 2005-05-02
Anonymous [Information Security Defender]
50-character password is overkill 2005-05-03
Anonymous (1 replies)
Security for the Paranoid 2005-05-06
Anonymous (1 replies)
Re: Security for the Paranoid 2006-05-25
Anonymous
Links for the Paranoid 2007-06-16
Anonymous
Security for the Paranoid 2008-02-17
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus