home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky alt.security:5371 comp.security.misc:2606
- Newsgroups: alt.security,comp.security.misc
- Path: sparky!uunet!pmafire!news.dell.com!swrinde!zaphod.mps.ohio-state.edu!sol.ctr.columbia.edu!The-Star.honeywell.com!umn.edu!sctc.com!smith
- From: smith@sctc.com (Rick Smith)
- Subject: Re: Help with handling SECRET data
- Message-ID: <1993Jan25.205229.12986@sctc.com>
- Organization: SCTC
- References: <1jpbtgINNrgd@news.cerf.net> <1k1e2eINNpbq@fido.asd.sgi.com>
- Distribution: us
- Date: Mon, 25 Jan 1993 20:52:29 GMT
- Lines: 15
-
- casey@anchovy.wpd.sgi.com (Casey Schaufler) writes about connecting
- a system with Secret classified information to the Internet:
-
- >Sounds like what you need is a B1 or CMW system to act as your gateway.
-
- The customary risk index analysis says you need at least a B3 system
- to enforce separation between garden variety Secret data and the
- unclassified users of the Internet.
-
- CMWs are essentially to keep honest people (i.e. folks with clearances
- of varying levels) from blundering across information they don't Need
- to Know. They can't protect against serious attacks, and aren't
- intended to keep the Uncleared away from really classified data. I
- once heard a CMW vendor identify an exploitable hole in their _design_
- at a public session at a security conference. Bleah.
-