Security through obscurity?!

> On the other hand, anyone who worked at the same shop for a long time knows
> how to "trick" its systems.

I used to work at a shop that used CLAS to manage passwords for the
mainframes and when reset were mailed out to the user's VM account. 
It was a trivial command to transfer those messages out of the users
RDR.  You can imagine the possibilities.

We've all heard it before:  Security is a business process not a program or OS.

As far a Microsoft and security, this is interesting:

http://news.com.com/Microsoft+meets+the+hackers/2009-1002_3-5747813.html

Gabriel

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to