Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

If it wasn't for Newton, we wouldn't have to eat bruised apples.


computers / comp.os.vms / Re: Now you have way more things to worry about

SubjectAuthor
* Re: Now you have way more things to worry aboutPizza RAC
+* Re: Now you have way more things to worry aboutArne Vajhøj
|`* Re: Now you have way more things to worry aboutDavid Turner
| +- Re: Now you have way more things to worry aboutDavid Turner
| `* Re: Now you have way more things to worry aboutArne Vajhøj
|  `* Re: Now you have way more things to worry aboutDave Froble
|   `- Re: Now you have way more things to worry aboutArne Vajhøj
`* Re: Now you have way more things to worry aboutSimon Clubley
 +* Re: Now you have way more things to worry aboutabrsvc
 |`* Re: Now you have way more things to worry aboutDave Froble
 | +* Re: Now you have way more things to worry aboutSingle Stage to Orbit
 | |+* Re: Now you have way more things to worry aboutSimon Clubley
 | ||`* Re: Now you have way more things to worry aboutArne Vajhøj
 | || +- Re: Now you have way more things to worry aboutDave Froble
 | || `- Re: Now you have way more things to worry aboutDave Froble
 | |+- Re: Now you have way more things to worry aboutDave Froble
 | |`* Re: Now you have way more things to worry aboutScott Dorsey
 | | `- Re: Now you have way more things to worry aboutArne Vajhøj
 | +* Re: Now you have way more things to worry aboutPizza RAC
 | |`* Re: Now you have way more things to worry aboutDave Froble
 | | `* Re: Now you have way more things to worry aboutScott Dorsey
 | |  `* Re: Now you have way more things to worry aboutDave Froble
 | |   `* Re: Now you have way more things to worry aboutSimon Clubley
 | |    `* Re: Now you have way more things to worry aboutbill
 | |     `- Re: Now you have way more things to worry aboutSimon Clubley
 | `* Re: Now you have way more things to worry aboutTholen
 |  `- Re: Now you have way more things to worry aboutArne Vajhøj
 `- Re: Now you have way more things to worry aboutPizza RAC

Pages:12
Re: Now you have way more things to worry about

<u96hlu$1nmaj$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=28885&group=comp.os.vms#28885

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: club...@remove_me.eisner.decus.org-Earth.UFP (Simon Clubley)
Newsgroups: comp.os.vms
Subject: Re: Now you have way more things to worry about
Date: Tue, 18 Jul 2023 17:21:02 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 40
Message-ID: <u96hlu$1nmaj$1@dont-email.me>
References: <FTOdnaz9ad3evDX5nZ2dnZfqn_idnZ2d@supernews.com> <u8h6qk$2ib7e$1@dont-email.me> <99786f1d-5fcf-4d05-8e1d-1da8a18c5c05n@googlegroups.com> <u8i8nm$2m463$4@dont-email.me> <u90uo0$2oj$1@panix2.panix.com> <u918ug$qqvg$2@dont-email.me> <u9616d$1l42f$1@dont-email.me> <khnflpFc0opU1@mid.individual.net>
Injection-Date: Tue, 18 Jul 2023 17:21:02 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="e5854edd3a461fd57a3bfc9389ba88d9";
logging-data="1825107"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/hMFxEOxOpmYHLEP6DmQNuqd1YRdCrk9k="
User-Agent: slrn/0.9.8.1 (VMS/Multinet)
Cancel-Lock: sha1:qA67FRs81VpzYnqV7YZcC1hfBxc=
 by: Simon Clubley - Tue, 18 Jul 2023 17:21 UTC

On 2023-07-18, bill <bill.gunshannon@gmail.com> wrote:
> On 7/18/2023 8:39 AM, Simon Clubley wrote:
>> On 2023-07-16, Dave Froble <davef@tsoft-inc.com> wrote:
>>> On 7/16/2023 10:27 AM, Scott Dorsey wrote:
>>>> Dave Froble <davef@tsoft-inc.com> wrote:
>>>>>
>>>>> Thinking about it some more, isn't all security obscurity?
>>>>
>>>> No. Take physical security for instance. Everybody knows where the computer
>>>> center is. They just don't want to deal with the armed guards at the entrance.
>>>
>>> Well, one could hide the computers ...
>>>
>>
>> The heavily guarded computer centre is just for show.
>>
>> The real control system is a laptop behind a door accessible through an
>> unlocked janitor's closet. :-)
>>
>> Simon.
>>
>> PS: Let's see if anyone gets the reference...
>>
>
> Is it anywhere near Kansas?
>

It's an Evil Empress reference:

https://nift.firedrake.org/EEmpress.htm

The much more well-known Evil Overlord list is here:

http://www.eviloverlord.com/lists/overlord.html

Simon.

--
Simon Clubley, clubley@remove_me.eisner.decus.org-Earth.UFP
Walking destinations on a map are further away than they appear.

Re: Now you have way more things to worry about

<u9g27q$3pbh5$1@paganini.bofh.team>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=28965&group=comp.os.vms#28965

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: tho...@guess.net (Tholen)
Newsgroups: comp.os.vms
Subject: Re: Now you have way more things to worry about
Date: Sat, 22 Jul 2023 07:58:50 -0000 (UTC)
Organization: To protect and to server
Message-ID: <u9g27q$3pbh5$1@paganini.bofh.team>
References: <FTOdnaz9ad3evDX5nZ2dnZfqn_idnZ2d@supernews.com> <d90cc759-5b80-43b7-b290-d9d3d69974fcn@googlegroups.com> <u8gsp5$2h745$1@dont-email.me> <bb4d1c70-bbaf-48fc-bbc5-0de3fdf538a1n@googlegroups.com> <u8h6qk$2ib7e$1@dont-email.me>
Injection-Date: Sat, 22 Jul 2023 07:58:50 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="3976741"; posting-host="F7N6bJUEJ8Do9435fhKgGg.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team"; posting-account="9dIQLXBM7WM9KzA+yjdR4A";
User-Agent: Mime 1.0
Cancel-Lock: sha256:VGlvafxRGZPu6I0OMxy7ICpY6q8frh7Oo24lQ39RKLw=
X-Notice: Filtered by postfilter v. 0.9.3
 by: Tholen - Sat, 22 Jul 2023 07:58 UTC

Dave Froble <davef@tsoft-inc.com> wrote in
news:u8h6qk$2ib7e$1@dont-email.me:

> On 7/10/2023 9:04 AM, abrsvc wrote:
>>
>>>>> Then you have exploits that hit VMWare
>>> The same problem exists for Alpha emulators, even though it's an
>>> emulator and not virtualisation software. Also not probed anywhere
>>> near as much as the mainstream products.
>>
>> I can agree with Simon for a change... :)
>>
>> Most of the problems I have seen in terms of "break-ins" have been at
>> the host OS level and not problems with the emulators. I know of one
>> client that has had multiple intrusions with NO impact on the OpenVMS
>> system itself other than being inaccessible because of the network.
>> OpenVMS itself was not affected at all. I see the same issue with
>> the VMs. OpenVMS is not the problem here, only the underlying host.
>>
>> Dan
>>
>
> One of our customers got hit with a ransomware attack. Their WEENDOZE
> systems were toasted. Their VMS system was not touched.
>
> Now, yeah, lots of business now depends upon WEENDOZE systems. But,
> VMS ran their core business, and while annoyed by the loss on the
> WEENDOZE systems, the company was able to continue to receive orders
> and ship product.
>
> Maybe some may see things differently, but, to me, there is a vast
> difference between being annoyed, and losing the capability to
> continue to run the business. Consider the ramifications of losing
> all Accounts Receivable data. Cant collect money is a major hurt.
>
> Not saying VMS cannot be hacked, but, the reality is, they usually are
> not hacked.

When customers outsource their Windows admin responsibilities to India,
Brazil, or the Philippines, they should expect that sort of thing.

Windows isn't all that bad. If you perform due diligence and hardening
as you're supposed to, it's pretty solid, resistant even. Ransomware
exploits succeed because somebody screwed up, gave in to an internal
customer, and didn't do it.

The other major vulnerability is the design of the management network
that permits these remote admins into the environments where they
perform their tasks. Some of them are absolutely horrendous and provide
complete direct access from an offshore location. That should never
ever be permitted.

Re: Now you have way more things to worry about

<u9gl87$3qkl7$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=28972&group=comp.os.vms#28972

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: arn...@vajhoej.dk (Arne Vajhøj)
Newsgroups: comp.os.vms
Subject: Re: Now you have way more things to worry about
Date: Sat, 22 Jul 2023 09:23:19 -0400
Organization: A noiseless patient Spider
Lines: 30
Message-ID: <u9gl87$3qkl7$1@dont-email.me>
References: <FTOdnaz9ad3evDX5nZ2dnZfqn_idnZ2d@supernews.com>
<d90cc759-5b80-43b7-b290-d9d3d69974fcn@googlegroups.com>
<u8gsp5$2h745$1@dont-email.me>
<bb4d1c70-bbaf-48fc-bbc5-0de3fdf538a1n@googlegroups.com>
<u8h6qk$2ib7e$1@dont-email.me> <u9g27q$3pbh5$1@paganini.bofh.team>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 22 Jul 2023 13:23:20 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="b14f62fac46e348442f62463bf3caa56";
logging-data="4018855"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18UkC6oKf/Jq3fYAJaG296WD3WDx+DrQm8="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.13.0
Cancel-Lock: sha1:tCg8EqKmvaSMOdvwU4OGYxXVEoA=
In-Reply-To: <u9g27q$3pbh5$1@paganini.bofh.team>
Content-Language: en-US
 by: Arne Vajhøj - Sat, 22 Jul 2023 13:23 UTC

On 7/22/2023 3:58 AM, Tholen wrote:
> When customers outsource their Windows admin responsibilities to India,
> Brazil, or the Philippines, they should expect that sort of thing.
>
> Windows isn't all that bad. If you perform due diligence and hardening
> as you're supposed to, it's pretty solid, resistant even. Ransomware
> exploits succeed because somebody screwed up, gave in to an internal
> customer, and didn't do it.
>
> The other major vulnerability is the design of the management network
> that permits these remote admins into the environments where they
> perform their tasks. Some of them are absolutely horrendous and provide
> complete direct access from an offshore location. That should never
> ever be permitted.

Remote system administration (system management in traditional VMS
terminology) is a requirement today.

Servers are in cloud facilities, colocation data centers,
centralized data centers etc..

It is not possible to have people in the computer room.

And remote access is remote access - there is no difference
between 10 miles and 10000 miles.

Arne

Pages:12
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor