It is truly amazing how human nature prevails. As much as we try to change, rule and regulate human behavior, there are examples in every field.
It is a known fact that when tax rates increase about a certain threshold, revenues begin to drop as evasion becomes more common place. The fiercest regimes are usually the ones that fall quicker.
But this blog is not supposed to be about sociology or politics, but about technology and management and in reality the issue that prompts me to write this time is the obsession of some IT Security departments to implement every single possible "best practice" as security measures. Two-factor authentication is one and the most common version is the security token, so this guarantees the unbreakable duet: something you know (the password) and something you have in your possession (the token). So when you put these together you have successfully authenticated yourself. This is not a new concept and it has been used ancestrally, just remember the stories that verse about tattoos or moles, passwords and objects that would identify a king, a priest, or a knight.
Changing passwords and setting up rules to construct valid and secure passwords is also a good idea, the problem arises when these rules restrict dramatically the number of words the user can choose and effectively remember. When combined with a stringent requirement for changing them too frequently together with a strict no re-use policy, these policies can be counter productive as they make it almost impossible for the user to commit multiple and random letter/number combinations to memory.
I see this trend quite often, where most users have to identify themselves with a "THREE-FACTOR" authenticate method: The Token, the Password and the piece of paper where they wrote down the password and how to login.
Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts
Monday, August 23, 2010
Sunday, February 22, 2009
Why a Proxy makes sense (as a security device for exploring the web)
The Proxy is the ultimate security device, and I am going to make my case by an analogy. Let's say I need to go to some dangerous place, for example, my Inlaw's or my younger daughter's room (translate this into any treacherous place).
The safest alternative is to not go.
The next best thing, is to send someone else, Right? This is exactly what a proxy is designed to do and there are things that are possible in the virtual world. A proxy
can:
For this to work, the proxy also does some other things -besides having to be a heckuva robust machine-, to know:
On the other side proxies are not perfect, they CANNOT do all you can do. They usually don't speak all protocols, they give you a watered-downed version of the experience in some cases and on top of that, they have to know all your stuff to properly impersonate you and they will know all the nasty places where you want to go...
The safest alternative is to not go.
The next best thing, is to send someone else, Right? This is exactly what a proxy is designed to do and there are things that are possible in the virtual world. A proxy
can:
- Perfectly impersonate you
- Transmit the whole experience to you, safely
For this to work, the proxy also does some other things -besides having to be a heckuva robust machine-, to know:
- It has to know where NOT to go
- It has to know what not to touch, eat (or open, execute) and how to get rid of some stuff
On the other side proxies are not perfect, they CANNOT do all you can do. They usually don't speak all protocols, they give you a watered-downed version of the experience in some cases and on top of that, they have to know all your stuff to properly impersonate you and they will know all the nasty places where you want to go...
Subscribe to:
Posts (Atom)
