Blabbermouths in a moment. The dunderhead part is the essential message of a post this morning by security expert Bruce Schneier, who passes along a conversation between a customer and his ISP regarding the transfer of a domain name. The gist was that the ISP rep wouldn’t conduct the transaction until the request had been filed by the customer on official company letterhead, which the customer did not have … until he created some while the two talked.
Problem solved.
“The idiot ISP guy doesn’t realize how easy it for anyone with a word processor and a laser printer to fake a letterhead,” Schneier writes. “But what this story really shows is how hard it is for people to change their security intuition. Security-by-letterhead was fairly robust when printing was hard, and faking a letterhead was real work. Today it’s easy, but people — especially people who grew up under the older paradigm — don’t act as if it is. They would if they thought about it, but most of the time our security runs on intuition and not on explicit thought.”
Comments on the post offer amusing variations on the theme. A couple of gems:
“I’ve had that before – a company wouldn’t accept a scanned document by e-mail for security reasons, wanted it by fax instead. Printed out the scanned document and faxed it to them – no problems :-)”
And …
“I have a similar experience with a popular 5-letter U.S. company that sells network equipment. Because I am purchasing from an Asian country, I had to sign some documents promising not to use it for nuclear warfare. Before they can approve my purchase I have to show them a Web page with a company profile. Since we are a startup we didn’t have a Web site. They insisted, so I said I’ll just post a dummy Web site. They stopped bugging after that.”
Hmmm, 5-letter U.S. company that sells network equipment: Now who could that possibly be?
Yes, security by letterhead has gone the way of security by obscurity … although, in the case of the latter, there are exceptions — especially when we’re talking about talking about security. Blogger/security expert Jeff Hayes spells out one of them in a recent post about a conversation he had in a sports bar with a fellow whose job is protecting the physical assets of a large accounting company. The guy couldn’t stop talking about his job … and in an alarmingly specific manner. Writes Hayes:
“Ground rule number one for security employees: keep security systems, designs, technologies, policies and procedures confidential. Spouses, girl/boyfriends, family and friends don’t need to know the details.”
Ground rule number two: Ground rule number one need not be printed on company letterhead.




