<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Aaron&#039;s Worthless Words &#187; convenience</title>
	<atom:link href="http://aconaway.com/tag/convenience/feed/" rel="self" type="application/rss+xml" />
	<link>http://aconaway.com</link>
	<description>It&#039;s possible that someone somewhere needs to see this.</description>
	<lastBuildDate>Fri, 10 Feb 2012 02:36:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.4</generator>
		<item>
		<title>Convenience versus Security</title>
		<link>http://aconaway.com/2009/12/01/convenience-versus-security/</link>
		<comments>http://aconaway.com/2009/12/01/convenience-versus-security/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 16:21:44 +0000</pubDate>
		<dc:creator>Aaron Conaway</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[convenience]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://aconaway.com/?p=392</guid>
		<description><![CDATA[I coworker sent over a link today that got me thinking about an old adage that I&#8217;ve been sharing for years.  The link actually has nothing to do with the philosophy but did trigger a random spewing of words from my brain. Here&#8217;s what I tell everyone.  When I deliver these lines, I usually picture myself as Socrates talking to a bunch of Greeks in togas. There&#8217;s a line.  On one end of the line is security; on the other end is convenience.  You have to figure out where the best place for your users/application/system/etc. to sit on the line to be both secure and convenient enough to function. I usually follow that up with an extreme example. What&#8217;s the most convenient configuration for a public webserver?  One solution would be to have it cabled to an Internet switch in front of a firewall with every network service enabled and all security software disabled in case it interferes with operation.  Quite convenient, but not very secure. What the most secure configuration?  The server is powered down, disassembled, all parts shredded to bits, and the bits put into a dozen different boxes that are shipped to the ends of the world.  [...]]]></description>
			<content:encoded><![CDATA[<p>I coworker sent over <a title="Cert.org - US-CERT Vulnerability Note VU#261869" href="http://www.kb.cert.org/vuls/id/261869">a link</a> today that got me thinking about an old adage that I&#8217;ve been sharing for years.  The link actually has nothing to do with the philosophy but did trigger a random spewing of words from my brain.</p>
<p>Here&#8217;s what I tell everyone.  When I deliver these lines, I usually picture myself as Socrates talking to a bunch of Greeks in togas.</p>
<blockquote><p>There&#8217;s a line.  On one end of the line is security; on the other end is convenience.  You have to figure out where the best place for your users/application/system/etc. to sit on the line to be both secure and convenient enough to function.</p></blockquote>
<p>I usually follow that up with an extreme example.</p>
<p>What&#8217;s the most convenient configuration for a public webserver?  One solution would be to have it cabled to an Internet switch in front of a firewall with every network service enabled and all security software disabled in case it interferes with operation.  Quite convenient, but not very secure.</p>
<p>What the most secure configuration?  The server is powered down, disassembled, all parts shredded to bits, and the bits put into a dozen different boxes that are shipped to the ends of the world.  Nobody&#8217;s going to get unauthorized access to that, but it&#8217;s not very convenient,  is it?</p>
<p>In both cases, being too far to one side actually interferes with functionality.  How long will it be before the convenient server get owned by a script kiddie and no longer functions?  How long before someone wants to access the secure server and finds it doesn&#8217;t function at all?  We should probably make a compromise, right?</p>
<p>This is nothing new.  We&#8217;ve all been saying this for years, right?</p>
<p>What&#8217;s my point?  I don&#8217;t think I have one, really.  I guess I just wanted to refresh this in everyone&#8217;s mind today.</p>
<div class="wp-about-author-containter-around" style="background-color:#ffffff;"><div class="wp-about-author-pic"><img alt='' src='http://1.gravatar.com/avatar/14352aa939196349e4b9f2a272ca5112?s=100&amp;d=&amp;r=G' class='avatar avatar-100 photo' height='100' width='100' /></div><div class="wp-about-author-text"><h3><a href='http://aconaway.com/author/jac/' title='Aaron Conaway'>Aaron Conaway</a></h3><p>I like to lean my head to the left, hit it with the palm of my right hand, and document what knowledge falls out.</p><p><a href='http://aconaway.com' title='Aaron Conaway'>Website</a> - <a href='http://aconaway.com/author/jac/' title='More posts by Aaron Conaway'>More Posts</a> </p></div></div>]]></content:encoded>
			<wfw:commentRss>http://aconaway.com/2009/12/01/convenience-versus-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

