On Tue, Jun 7, 2011 at 12:54 PM, Kevin Lundy <[email protected]> wrote:
> I asked how confident they were that the initial intrusion had absolutely
> been eliminated.  The response was that they had mounted one of the largest
> forensic and security review of a company ever ...

  And you're trusting them because...?

  If you cannot audit all aspects of the design and implementation of
a system, don't use it.

  If you cannot generate your own crypto key material, don't use it.

  Security through obscurity, propitiatory solutions, etc., *ARE NOT
SECURE*.  This has been demonstrated over and over again; RSA is
simply the latest -- and possibly biggest -- pooch screw to come to
public attention.

  They should be able to have their entire network up for anonymous
FTP without it impacting *your* security one iota.  If they can't,
they are lying to you.  It's that simple.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

Reply via email to