Re: end user security

Bryan Follins <asalh@MINDSPRING.COM> Wed, 10 October 2001 05:50 UTC

Received: from mailbag.cps.intel.com (mailbag.cps.intel.com [192.102.199.72]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA23028 for <run-archive@LISTS.IETF.ORG>; Wed, 10 Oct 2001 01:50:06 -0400 (EDT)
Received: from mailbag.intel.com (mailbag.cps.intel.com [192.102.199.72]) by mailbag.cps.intel.com (8.9.3/8.9.3/d: relay.m4,v 1.6 2000/11/24 22:10:56 iwep Exp iwep $) with ESMTP id WAA24682; Tue, 9 Oct 2001 22:36:10 -0700 (PDT)
Received: from MAILBAG.INTEL.COM by MAILBAG.INTEL.COM (LISTSERV-TCP/IP release 1.8d) with spool id 15019 for IETF-RUN@MAILBAG.INTEL.COM; Tue, 9 Oct 2001 22:36:09 -0700
Received: from smtp6.mindspring.com (smtp6.mindspring.com [207.69.200.110]) by mailbag.cps.intel.com (8.9.3/8.9.3/d: relay.m4,v 1.6 2000/11/24 22:10:56 iwep Exp iwep $) with ESMTP id WAA24678 for <IETF-RUN@mailbag.cps.INTEL.COM>; Tue, 9 Oct 2001 22:36:08 -0700 (PDT)
Received: from darlene (user-2ivfn4r.dialup.mindspring.com [165.247.220.155]) by smtp6.mindspring.com (8.9.3/8.8.5) with SMTP id BAA19692 for <IETF-RUN@MAILBAG.INTEL.COM>; Wed, 10 Oct 2001 01:34:03 -0400 (EDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Importance: Normal
Message-ID: <CGEPLPKOPPDHLCKOLCLNOEBBCDAA.asalh@mindspring.com>
Date: Tue, 09 Oct 2001 22:39:07 -0700
Reply-To: IETF-RUN <IETF-RUN@mailbag.cps.INTEL.COM>
Sender: IETF-RUN <IETF-RUN@mailbag.cps.INTEL.COM>
From: Bryan Follins <asalh@MINDSPRING.COM>
Subject: Re: end user security
To: IETF-RUN@mailbag.cps.INTEL.COM
In-Reply-To: <20011009215545.C32066@magenet.net>
Content-Transfer-Encoding: 7bit

Check out the documents on my website at www.readingwhitepapers.com
They may help.

Bryan

-----Original Message-----
From: IETF-RUN [mailto:IETF-RUN@MAILBAG.INTEL.COM]On Behalf Of Josh Rollyson
Sent: Tuesday, October 09, 2001 6:56 PM
To: IETF-RUN@MAILBAG.INTEL.COM
Subject: end user security

I'd like to suggest that a document is needed on the responsibilities
of end users to maintain secure systems.

Every day I deal with abuse from compromised systems on broadband
connections. The providers are usually too overwhelmed to take any action,
and the users were usually never informed of the risks, or of their
responsibility to insure their system isn't misused.

Typically, when you do get a response from the user, you find out that
it was a default <insert consumer operating system of choice here>
installation, and that they had services running that they weren't using,
that they had no idea they needed to keep updating things to stay secure,
they had no firewall or packet filter, essentially an open door to abusers.

Compromises of end user desktop computers can largely be stopped by basic
education and basic security practices. Yet most users never learn this
until its too late. While there is no magic bullet, users need to be
informed, preferably before their systems are connected to the global
internet, that there are certian things they must do to protect themselves
and more importantly, the rest of the internet.


--
Josh Rollyson
System Administrator - SOSDG/2Mbit.com
IRC Operator - efnet.vuurwerk.nl