1998-08-21 - RE: your mail

Header Data

From: “Brown, R Ken” <brownrk1@texaco.com>
To: “Brown, R Ken” <bbt@mudspring.uplb.edu.ph>
Message Hash: b655e849b28b55e530b20a5df4e58d4b5fbcc29ba6bafcba3296e57994964051
Message ID: <896C7C3540C3D111AB9F00805FA78CE2013F8379@MSX11002>
Reply To: N/A
UTC Datetime: 1998-08-21 05:54:49 UTC
Raw Date: Thu, 20 Aug 1998 22:54:49 -0700 (PDT)

Raw message

From: "Brown, R Ken" <brownrk1@texaco.com>
Date: Thu, 20 Aug 1998 22:54:49 -0700 (PDT)
To: "Brown, R Ken" <bbt@mudspring.uplb.edu.ph>
Subject: RE: your mail
Message-ID: <896C7C3540C3D111AB9F00805FA78CE2013F8379@MSX11002>
MIME-Version: 1.0
Content-Type: text/plain

> Bernardo B. Terrado[SMTP:bbt@mudspring.uplb.edu.ph]
> About the firewall configuration thing, is it our system or 
> others system  (I mean other servers)?
> And another thing, are you in favor of what I just did, 
> I meqan sending my Information.(commnets)

I assume a firewall is meant to keep your network safe from
damage, whether  accidental or caused by hackers. crackers,
criminals, spies or well-meaning friends and relations 
testing your security.

One of the really really basic rules about security is that
your operational arrangements should be  kept secret.
(NB that is *not* the same as saying that crypto algorithms 
should be secret or that security software source code should
be secret, although NSA & GCHQ will say that it is...)

If there are people who like to hack NT web servers
for fun or profit (I couldn't possibly comment) 
then posting details of your setup on an NT 
admin mailing list is an open invitation. 
The silliest thing to do is to say what fix level your OS 
is at, and that you haven't installed the hotfixes
because that saves potential hackers a lot of time.

Imagine you were worried about being burgled when you 
went on holiday (vacation in the USA :-)   You might ask
online if anyone recommended particular locks or
other security measures. But to say what locks you already
had on what doors might be dodgy. To say that you had a 
particular lock but you had lost the key and therefore 
never used it would be crazy. And to  say what days you were 
going to be away would be asking for it.