Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
Security /

'Always on' programs pose an 'always on' threat

Related linksToday's breaking news
Send to a friendFeedback

Tolly archive

Try as they might to secure the enterprise - using firewalls, VPNs, intrusion detection and content filters - network managers are being defeated in droves . . . by their co-workers.

The dramatic surge in "always on" third-party programs running on corporate desktops has set the stage for unknown havoc. The programs range from distinctly nonbusiness peer-to-peer programs such as KaZaA - a Napster follow-on - to corporate remote access services such as ExpertCity's GoToMyPC.

These are not Trojan horses; they are legitimate services. Users download and install the client because they want the service. For network managers, though, such programs can create network performance headaches and set the stage for serious security breaches.

The KaZaA Media Desktop transforms a corporate desktop into a file server accessible worldwide. The default installation sets you up with a shared folder for the world to see.

While the primary content is MP3 audio, files are files. Should corporate files get into that folder, they are now available to the world. Users can assign any folder to which they have access to be indexed into the KaZaA system and thus free to the world. Imagine what a disgruntled employee could do "by mistake."

Even if the data is harmless, your corporate Internet link will get chewed up as users around the world grab files from that desktop. KaZaA is built to seek out the fastest machines and highest-speed connections as the preferred sources for downloads.

And what about the files your users bring in via KaZaA? So prevalent, apparently, are Trojans, viruses and SpyWare that the KaZaA home page advertises a recommended third-party utility, BullGuard, to defend your desktop. Scary.

KaZaA says its desktop software has been downloaded more than 119 million times. Chances are, it is already in your network. Time to start looking for it.

GoToMyPC, on the other hand, serves a legitimate corporate need - remote desktop access. It is built around a service provider model. And its architecture lets users bypass corporate firewalls.

Typically, firewalls are configured to look outside for trouble and assume that anything initiated from the inside is fine.

With GoToMyPC, an always-on client program residing on the desktop stays in constant contact with a GoToMyPC server. While the traffic load is not significant, there is a constant "heartbeat" between each client and the server. My network analyzer tells me so.

When the remote user wishes to access his desktop, he contacts the GoToMyPC service. After clearing two levels of password authentication, the target desktop appears.

From a system perspective, the session appears to be initiated from the unattended target PC so firewall authentication is not an issue.

The software works, I tried it. Because of the three-way nature of the architecture, benchmarking the speed was not possible.

While there is clearly no evil intention on the part of ExpertCity, I find it unsettling to have scads of corporate desktops in constant communication with a third-party service that, through its "mole," can determine how often your PC is busy, when you're in the office and so forth.

While the company offers packaged enterprise services, they don't offer an "opt out" for companies that don't want to let desktops in their domain use the service.

Network managers have to look within and start understanding the security and the performance implications of always-on code running on their desktops.

RELATED LINKS

Kevin Tolly is president and CEO of The Tolly Group. Reach him via e-mail at ktolly@tolly.com.

More Tolly on Technology columns

Australian airports to deploy body scanning technology 2/9/2010
Google teaming up with the NSA: should you be worried? 2/6/2010
EPIC files FOIA request over reported Google, NSA partnership 2/4/2010
Powered by Inform

NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.