| TIP: Click on subject to list as thread! | ANSI |
| echo: | |
|---|---|
| to: | |
| from: | |
| date: | |
| subject: | Re: encyption that is not encryption |
From: "Rich"
This is a multi-part message in MIME format.
------=_NextPart_000_00C7_01C5B954.1B741130
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
George's suggestion is a great example of bad use of encryption, =
something that is not encryption at all but simply complicated = obfuscation.
Rich
"Paul Ranson" wrote in message =
news:4328b57d{at}w3.nls.net...
Encrypting the registry would just mean at a simplest level running =
the=20
firewall configuration app and poking keystrokes at it rather than =
just=20
editing the registry. Keeping it hidden isn't rocket science.
Not running untrusted code would seem to be the first line of defence. =
And=20
having the firewall physically distinct a distant second. I don't see =
that=20
any local firewall significantly adds to my security, it just may =
alert me=20
to unauthorised activity. But then my router's firewall log does that.
Paul
"Geo." wrote in message =
news:432857bf$1{at}w3.nls.net...
> You are missing the point, step one is to get your evil.exe code =
onto my
> machine and run it.
>
> I don't have to have code executing on your machine to change your=20
> firewall.
> A simple javascript included in a pdf file and emailed to you or =
posted to=20
> a
> newsgroup should be enough to disable your firewall fire up tftp and
> download your evil.exe code and run it. (I don't really know if I =
can do=20
> all
> that in javascript but I'm just trying to describe a technique =
that's been
> used by countless hackers)
>
> Your firewall is useless against an attack where the firewall needs =
to be
> diabled before the evil.exe can be downloaded and run.
>
> Something as simple as encrypting the registry key data would =
prevent this
> or at least make it infinitely more difficult.
>
> Security is not an absolute, it's a shade of grey and the idea is to =
have
> your grey more white than black.. this sillyness definitely moves =
you
> towards black.
>
> Geo.
------=_NextPart_000_00C7_01C5B954.1B741130
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
George's
suggestion is a =
great example=20
of bad use of encryption, something that is not encryption at all but = simply=20
complicated obfuscation.
Rich
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)SEEN-BY: 633/267 270 5030/786 @PATH: 379/45 1 106/2000 633/267 |
|
| SOURCE: echomail via fidonet.ozzmosis.com | |
Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.