home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Network Computing Blog
SPECIAL EVENT BLOGS:
BrainShare 2008

IMMERSION CENTER BLOGS:
Network Access Control
Virtualization
Application Performance Optimization
Data Center
Data Privacy
802.11n
SOA/Web Services

MORE TOPCS:
Security
Wireless
Application Infrastructure
Collaboration
Network and Systems Management
Network Infrastructure
Storage and Servers
Enterprise Applications
Business Strategy
Personal Technology
Podcasts
NWC Inc
NWC Labs
Techno-Oddities

MORE GREAT BLOGS
Ars Technica
bMighty
Boing Boing
Geek.com
InformationWeek
IT Toolbox
TechCrunch



Security Blog

April 27, 2007
Skip a security check, do not pass go, go directly to suspension
By Jordan Wiens

A University of Portland student was suspended for writing a program to bypass the Cisco Clean Access NAC system on campus. Apparently this incredibly dangerous activity is a Patriot Act violation. Or, at least, it is if you believe the letters being sent out by the administration at UP who seem to be confusing "skipping security checks" and "hack into a licensed product"

First, let me mention that I work as a Senior Security Engineer at the University of Florida. I spend 40hrs a week (at least!) dealing with exactly the same type of threats that the folks at the University of Portland deal with and strongly understand the value of NAC in protecting such a difficult network to defend. I should mention that what I write here is obviously not in any way official UFL policy or opinion. I've never been concerned by methods to evade NAC. People who are capable of evading NAC are not the users you're trying to protect from compromise by ensuring they're secure anyway. Deal with the vast majority of users who need NAC for their own protection and the protection of the network and don't worry about the few smart enough to actually evade it.

UP's reaction was not proportionate to the issue. From what's been posted online of the policies and reactions the administrative staff has had to the incident ([1] [2] [3] [4] ), somebody seriously over-reacted. Let's put it this way -- what the program that Mr. Maass wrote did was essentially make his computer look like a PDA. Or a game-system, or any other network device besides those supported by the version of CCA at UP. He didn't hack in without using a username and password, or steal anyone else's account. He didn't attack the CCA system itself with any exploit at all.

That's not to say he didn't handle it poorly. And his actions probably should be a violation of campus policy even if it wasn't when he did it (UP: add some language about "attempting to evade security measures meant to protect the network" and you're done). But suspension? The letter to the local newspaper mentions that there were no less than 19 other lesser sanctions that could have been taken in this instance (see [3] above). A suspension is ridiculous.

It's also odd the way that other students at UP who possessed the program are having action taken against them. One uses a Mac and couldn't even use the program if he wanted to and yet is still having sanctions taken against him. If all it takes is a program that can be used to evade security, they'd better take action against every student, faculty, and staff on that campus running a web browser (most of them, I would imagine). A browser and a little knowledge is all the weapon you need to hack most websites. Better crack down on butter knives and forks in the cafeteria too while you're at it.

Of course, maybe I'm only taking this position because not too many years ago I showed my own little brother how to evade an early version of CCA on his campus merely by changing his User-Agent string to resemble a Mac (that technique has long since stopped being an effective way to bypass CCA, but there are still many others and always will be in a system where you're trying to get trusted responses from an untrusted system).

Thanks Alan for mentioning the article from Tim Greene that brought this to my attention.

-- Posted at 01:44 PM in Security





This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
IWKBTN
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek ReportsInformationweek MagazinebMightyByte and SwitchDark ReadingDigital Library
Intelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. Dobbs
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoSoftware ConferenceNoJitterMobile Connect
Black HatGTECEnergy CampMashup CampStartup CampCloud Connect
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungCable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoOptical ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev Pro
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights