home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.dcom.modems:19823 alt.security:5346
- Newsgroups: comp.dcom.modems,alt.security
- Path: sparky!uunet!cs.utexas.edu!uwm.edu!linac!att!cbnews!cbnewsm!cbnewsl!att-out!pacbell.com!iggy.GW.Vitalink.COM!nocsun.NOC.Vitalink.COM!wsrcc!wolfgang
- From: wolfgang@wsrcc.com (Wolfgang S. Rupprecht)
- Subject: Re: Caller ID products?
- Message-ID: <C18s8F.1qI@wsrcc.com>
- Organization: W S Rupprecht Computer Consulting, Fremont CA
- References: <C0wu1q.GK0@wsrcc.com> <1993Jan18.172024.20690@ssc.com> <1993Jan19.160818.8276@crd.ge.com> <1993Jan20.172626.11028@bernina.ethz.ch> <1993Jan21.173344.4911@crd.ge.com>
- Date: Fri, 22 Jan 1993 06:19:27 GMT
- Lines: 40
-
- davidsen@ariel.crd.GE.COM (william E Davidsen) writes:
- [in reply to dialback modems -wsr]
- > There's no absolute security, you just start at a locked room with
- >armed guards, isolated power supply, magnetic shielding, and retinal
- >print ID of users entering the room. Then you work down the scale until
- >you get to something cost effective for your application.
-
- If one is not interested in security then one wouldn't try to use a
- dial-back modem to that end. If someone is using a dial-back modem that
- dials back on the same line then one is fooling themselves. There
- isn't any added security over the case were one just adds another
- password to the login process.
-
- > Callback makes it *harder* to get access to a system, not impossible.
-
- So does sticking a bandaid over your locks. A burglar can't
- manipulate the lock until the bandaid is removed. Dial-back is just a
- bandaid for modems.
-
- >It keeps the person who gets a number and password from getting in.
- >It means the cracker needs more info and expertise to get access.
-
- They already have the number. There is no added info needed. Its the
- same one that they just called. They just have to call back. The
- added password is a benefit however. One can get the added password
- without the dial-back baggage.
-
- >Rejecting something because it's not perfect is not something I
- >recommend, unless you can get something better which is still cost
- >effective. Doil-out only lines are a fairly large investment for the
- >typical users who isn't being attacked by trained, dedicated, and
- >well financed individuals.
-
- One only needs one extra line - the dial in line. It gets freed up
- rather quickly.
-
- -wolfgang
- --
- Wolfgang Rupprecht wolfgang@wsrcc.com (or) decwrl!wsrcc!wolfgang
- Snail Mail: 39469 Gallaudet Drive, Fremont, CA 94538-4511
-