Firewall Wizards mailing list archives

Re: Screening Outgoing Mail for Content and other things


From: cfb <cfb () ocn21 kdd-ok ne jp>
Date: Fri, 07 Aug 1998 13:12:52 +0900

Joseph S. D. Yao wrote:
And hand screening won't find everything, either.  An encrypted message
can look like a perfectly innocent anything.

This may sound odd, but what about now allowing plaintext out, instead
requiring encryption that assigns responsibility.  Java Rings for all
and signature verification at the gateway!  People might be less likely
to ship out confidential information if they know the message won't just
slip out semi-anonymously lost in bulk traffic.  An external or
secondary gateway could decrypt for the reset of the world.  It will
doesn't address the issue of double encryption or steganography, but
archiving signature verification and MD5 fingerprinting might help in
establishing a chain of evidence.  Anyone who has played around with the
freely available steganographic tools out there knows the extent of the
content analysis problem.  I think a finger print/signature archive
combined with a interaction circle (overlayed with a list of valid
customers) would produce some interesting results.

Generally speaking when you restrict, users (especially malicious users)
become innovative.  I am reminded of a tech. that needed to get a
Solaris patch (required to do his job) across a firewall which blocked
ftp.  He ended up embedding the patch in a web page and getting it
across the firewall this way.  He also ended up getting in trouble for
his little "solution".  As for auditing phone bills and PBX carrier
blocking, that's what cellular phones are for (you know, the new phones
with IR PC connectivity... no messy cables laying about).

FOD for though....



Current thread: