Firewall Wizards mailing list archives

RE: Newspaper Article about Cable Modem security


From: Robert Graham <robert_david_graham () yahoo com>
Date: Mon, 1 Nov 1999 13:58:35 -0800 (PST)

--- "Keller Dennis (DDSP)" <dkeller () ddc dla mil> wrote:
But your average home user does not think about security.  Should your local
ISP provide a level of security?  No (and this will be hotly debated) but
they *should* provide information on the risks and solutions.

I find it interesting that the conversation centers around the concept of what
the ISP *should* do, as if it has some moral obligation. Usually, such claims
of moral obligations run counter to economic practicalities. ISPs charge razor
thin margins, and any attempt to be nice to users results in dramatically
increased costs. ISPs would like to be nicer to customers, but to do so would
require charging customers more, and customers aren't willing to pay more. It's
easy to blaim the ISP for being money grubbing capitalists, but the reality is
that customers get what they pay for.

For example, @Home (and some other ISPs) block incoming port 139 at their
routers. Engineers think this is free, because it is trivial configuration in
their routers. However, tech support people experience the costs as people call
up complaining that they can't share files with their friends. Such filtering
also generates bad will from customers who think of this as evil big-brother
tactics, and that @Home is really blocking port 139 because they don't want
people sharing their MP3 files and sapping the bandwidth.

It can easily take 15-minutes with a customer just to figure out the problem is
related to port 139. A typical conversation starts out with "Hello, I'm paying
$40/month for Internet access from you company but it doesn't work. If I can't
get it to work today, I want my money back".

Education doesn't work either. Most ISPs already explain about "File and Print
Sharing" and security risks. Again, @Home is a good example. They started
filtering port 139 because customers wouldn't listen. AOL is another example,
they hit customers over the head with message such as "never reveal your
password" or "never run a program someone e-mails to you", but customers do it
anyway. I talked with one AOL customer that explained why he ran a program that
appeared to come from AOL-support via an e-mail, even though he had been told
that AOL-support would never send him a program via e-mail (standard soc-eng
attack).

I think engineers have really no comprehension how ignorant users are. We are
all such experts now, and we forget how we were when first exposed to computers
(i.e. when the power switch itself is a struggle). Remember that half the
Internet users are still at that stage. Moreover, we like computers for their
own sake, whereas most users are interested in other things, and only use
computers as a tool (i.e. have no interest in learning what the security
dangers are). 

It's easy to criticize the ISPs for not caring, but spending a few weeks answer
support calls should cure you of that notion.





=====
Robert Graham
"Anxiously awaiting the millenium so I can start programming
dates with 2-digits again."
__________________________________________________
Do You Yahoo!?
Bid and sell for free at http://auctions.yahoo.com



Current thread: