Re: PAB Re: site security

Marc Hurst (mhurst@fastlane.ca)
Fri, 20 Feb 1998 10:25:04 -0500 (EST)


Wow,

I think I actually agree with Perry on something. Is it going to be gratis?

On Fri, 20 Feb 1998, Perry E. Metzger wrote:

>=20
> I would suggest that perhaps the CORE equipment should be located at
> the PAIX, which has excellent internet connectivity and top
> security. If this is desired, I could contact Paul Vixie on behalf of
> CORE.
>=20
> Perry
>=20
> "Robert F. Connelly" writes:
> > Dear Kent:
> >=20
> > I add one small item to your recommendations.
> >=20
> > Son Duane immediately proposed something like Lojack. I understand you=
can b
> uy
> > a crown with a transmitter in it from the "Spy shop" in the New York ai=
rport.
> =20
> > (Also a list of dentists willing to install it!)
> >=20
> > Wouldn't it be nice to be able to see just where the units are going?
> >=20
> > Regards,
> > BobC=20
> >=20
> >=20
> > At 05:54 PM 2/18/98 -0800, Kent Crispin wrote:
> > >On Wed, Feb 18, 1998 at 12:15:21PM -0800, Dave Crocker wrote:
> > >> Folks,
> > >>=20
> > >> In light of the breakin and theft, I thought a little harder about s=
ite
> > >> security.=A0 I had thought that Best was dandy.=A0 No question they =
are popular
> > >> and I know their operation in Mountain View quite well.=A0 I assume =
S.F. is
> > >> the same.=A0 Card keys, locked cages, hallway window into the room f=
or
> > >> staffers to view.=A0=20
> > >>=20
> > >> On the other hand, visual control is not constant or even heavy.
> > >>=20
> > >> So I just called Exodus and heard a notably different description of
> > >> security features.=A0 They have all the stuff Best can claim.=A0 In =
addition
> > >> (though I don't know if there are differences in the quality of the
> > cages...):
> > >>=20
> > >> 1.=A0 24 hour guard.=A0 You get the card key each time from the guar=
d, rather
> > >> than carrying it will you, and must sign in, showing photo id.
> > >>=20
> > >> 2.=A0 Equipment coming in or going out is logged.
> > >>=20
> > >> 3.=A0 Cameras on the access.=A0 (Pretty sure Best doesn't have this.=
)
> > >>=20
> > >> All 3 of these points make for much stronger security than Best has.
> > >>=20
> > >> Might be worth considering.=A0 I haven't checked other providers.
> > >
> > >Under the circumstances, I see several choices, in order of preference=
.
> > >
> > >=A0=A0=A0=A0=A0=A0=A0 1) Get Best to improve their security -- they ma=
y want to do
> > >=A0=A0=A0=A0=A0=A0=A0 that after this incident, because really, it cou=
ld have
> > >=A0=A0=A0=A0=A0=A0=A0 happened to any of their customers.=A0 Given the=
value of the
> > >=A0=A0=A0=A0=A0=A0=A0 equipment there, 24 hour attendance is not a lux=
ury, it is a
> > >=A0=A0=A0=A0=A0=A0=A0 necessity (I was under the impression that Best =
supplied this,
> > >=A0=A0=A0=A0=A0=A0=A0 but obviously there are gaps.)
> > >
> > >=A0=A0=A0=A0=A0=A0=A0 I would think that Best might want to seriously =
rethink their=20
> > >=A0=A0=A0=A0=A0=A0=A0 security posture -- this could have been a bomb,=
instead of=20
> > >=A0=A0=A0=A0=A0=A0=A0 a theft.=A0 If they won't seriously improve, the=
n I don't think=20
> > >=A0=A0=A0=A0=A0=A0=A0 there is any choice but to...
> > >
> > >=A0=A0=A0=A0=A0=A0=A0 2) ...move to someplace like Exodus.=A0 Our secu=
rity auditors,
> > >=A0=A0=A0=A0=A0=A0=A0 if they are worth anything at all, should make t=
his point
> > >=A0=A0=A0=A0=A0=A0=A0 strongly, and I don't think, if we are serious, =
that we will
> > >=A0=A0=A0=A0=A0=A0=A0 have any choice but to follow their recommendati=
ons.=A0=A0 We=20
> > >=A0=A0=A0=A0=A0=A0=A0 have an excuse -- our final production configura=
tion is=20
> > >=A0=A0=A0=A0=A0=A0=A0 contingent on our security audit, we could say.
> > >
> > >=A0=A0=A0=A0=A0=A0=A0 3) implement our own security measures (install =
alarms,=20
> > >=A0=A0=A0=A0=A0=A0=A0 cameras, etc, hire a security guard).=A0 This is=
a distant,=20
> > >=A0=A0=A0=A0=A0=A0=A0 distant, third.=A0 To be effective it would stil=
l have to=20
> > >=A0=A0=A0=A0=A0=A0=A0 involve Best.=A0 We could do this, but it would =
be a denial of=20
> > >=A0=A0=A0=A0=A0=A0=A0 reality, IMO.
> > >
> > >--=20
> > >Kent Crispin, PAB Chair "No reason to get excited",
> > >kent@songbird.com the thief he kindly spoke...
> > >PGP fingerprint:=A0=A0 B1 8B 72 ED 55 21 5E 44=A0 61 F4 58 0F 72 10 65=
55
> > ><http://songbird.com/kent/pgp_key.html>http://songbird.com/kent/pgp_ke=
y.html
> > > =20
>=20