logo       

Re: time for my lil opinion poll: msg#00052

security.dailydave

Subject: Re: time for my lil opinion poll

* Chris Anley:

> As an example, if the ILP system works solely at the TCP stream level,
> then a network client or server could pause while transmitting packets,
> and the host at the other end could measure the pauses. Or you could
> leak one bit at a time, by establishing connections in odd or
> even-numbered seconds.

The issues are much more mundane. Companies usually don't want their
sales people to leak details about their products to the competition.
So they look for software that detects such leaks. The problem: The
data to be protected is stored in an Excel spreadsheet -- and
disconnected operation is a must.

I expect that it's possible to detect the casual leaker, but
prevention is much harder (and might give too many clues to the
attackers). 8-/

> NGS and NGSSoftware are trading names of Next Generation Security
> Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
> 4BF with Company Number 04225835 and VAT Number 783096402

I think you also need to list the names of some company officials,
such as the CEO. And of course, you must archive your message for
five (or ten?) years as well if you think you're forced to add that
footer.


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise