Spam that delivers a pink slip; Antiphishing fighters take on malware; Mismatched job titles; Big Brother gets virtual; Richard Stiennon’s open letter to Check Point CEO Gil Shwed; Automating change
Thwarting the attack
Regarding “Spam that delivers a pink slip”: Of course, implementing SPF rules in the DNS zone and SPF filter at the gateway will completely eliminate this attack from ever working, because the sender will never be from a valid IP address. SPF rules do not have to be applied to all e-mail for this to be effective; it only needs to be applied to the receiving domain. Then the only way e-mail from the local domain may enter from the outside is if the outside machine is registered as a valid sender for that domain.
Armand Welsh
AVP, Information Security
State Street IMS
Irvine, Calif.
Never surrender
Regarding “Antiphishing fighters take on malware”: We try and try, but phishers won’t cry!
Good initiative. All are. We mustn’t give up. But…there will never be the one-and-only solution against the cutting-edge scientists on the bad guys’ payroll. The crooks will make a small change of the malicious code and this good move will lead to just nothing.
William Palmborg
President
SecuraSystem
Madison, Miss.
Title match
“Mismatched job titles” hit home with me on a number of levels. However David Foote’s comments about network engineers/administrators/architects/technicians surprised me. Maybe it’s just the market I’m in, but in general I see a wide variety in what people mean when they use the term “network.” For some people it’s strictly routers/firewalls/switches, for other people it’s systems (servers, hardware), for others it’s applications (messaging, Citrix). I also haven’t seen consistency in the second half of the job title — I’ve been an engineer (which in Canada is a protected term), analyst, specialist and I’m starting a new job soon where I haven’t even bothered to learn my title. I do hope the trends of skill-based compensation make their way north, though.
Sean Walberg
Winnipeg, Canada
A virtual life
Regarding Mark Gibbs’ BackSpin column, “Big Brother gets virtual”: The IRS will have arrived when it can put a lien on your virtual house in your favorite Massively Multiplayer Online Role-Playing Game and take real tax payments in virtual gold, copper and silver. Do you have to file capital loss when your virtual house is taken over by a group of online thugs? Does the FBI get involved when crimes against your virtual character happen over state lines?
The states could follow suit by charging sales tax when you sell that third-level magical sword. Wonder if the lawyers will get into this? Consider the lawsuits when lawyers find out their client’s virtual character was killed and all possessions taken. Would there be tax credits for virtual children?
Daren Mehl
Apple Valley, Minn.
Checking up
Regarding Richard Stiennon’s open letter to Check Point CEO Gil Shwed: With all due respect to Stiennon, the problem in security is not in the network – it’s the integrity of the endpoints. If the integrity of end points is questionable, enforcement within the network is useless.
Check Point should be investing more in beefing up its endpoint integrity solution (perhaps as an add-on to its ZoneAlarm firewall) and not just buying up hardware-based platforms such as Crossbeam.
Sanjay Sawhney
Cupertino, Calif.
I think Richard Stiennon’s open letter to Gil Shwed is right on the money. However, it would not be a stretch to use both the health check and user identity coupled with other attributes such as location and security alert levels to make the decision on whether a particular access is allowed or not.
The one place where I differ is the use of virtual LANs for customization of what the user gets to access. Why use a coarse-grained Layer 2 construct when you have much finer-grained mechanisms available that do not need network reconfiguration? The enforcement point needs to be able to enforce logical collection of resources without resorting to VLANs.
Sanjay Uppal
San Jose
Managing change
“Automating change” misses an opportunity to show how mature mainframe change management/version control systems are. I believe change management was founded in the mainframe technology environment, thus making it the model for change and configuration management in non-centralized PC (desktop and server-based) and midrange computer processing environments. The mainframe still manages 80% of the critical data processing applications running in corporate America. The highly developed change management techniques within the mainframe have greatly contributed to its success as a stable and secure processing platform.
Jim Bandinelli
Buffalo, N.Y.




