<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=ISO-8859-1">
<META NAME="Generator" CONTENT="MS Exchange Server version 6.0.5762.3">
<TITLE>RE: [Full-Disclosure] [OFFTOPIC] Zone Alarm</TITLE>
</HEAD>
<BODY>
<!-- Converted from text/rtf format -->
<P><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">worse than HTML email... Exchange</FONT>
</P>
<P><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">*eep*</FONT>
</P>
<P><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">I have mixed emotions about making ppl understand security. Users are rather stupid by nature.</FONT>
<BR><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">Otherwise, I wouldn't have a job. </FONT>
</P>
<P><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">I think however, having them use the software and equipment, making natural, and letting them </FONT>
<BR><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">watch the news and read the magazines, and talk to the clients about "oh, that worm/virus/hack,</FONT>
<BR><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">didn't affect us.</FONT>
</P>
<P><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">I cannot make users understand why they need to change passwords. They argue and whine and </FONT>
<BR><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">cry alot, but they do change those passwords.</FONT>
</P>
<P><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">My wife, my family are not tech savvy folks. But they humor me and they take precautions, then </FONT>
<BR><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">they patiently listen to their friends and collegues complain about virii, ftp and irc servers they were</FONT>
<BR><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">unwittingly running on thier systems. Then I get to overhear my family say things like "well why don't </FONT>
<BR><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">you have a Router/Firewall thingy... it works for me"</FONT>
</P>
<P><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">9out of 10, that silly little NAT on the linksys is enough to ward off penetrations to home computers, for</FONT>
<BR><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">home manual non-reading users.</FONT>
</P>
<P><FONT COLOR="#0000FF" SIZE=2 FACE="Arial">Ferrari?!? Um, need a son, or another admin... I don't even own a car *grin*</FONT>
</P>
<BR>
<BR>
<UL>
<P><FONT SIZE=2 FACE="Arial">----------</FONT>
<BR><B><FONT SIZE=2 FACE="Arial">From:</FONT></B> <FONT SIZE=2 FACE="Arial">Schmehl, Paul L</FONT>
<BR><B><FONT SIZE=2 FACE="Arial">Sent:</FONT></B> <FONT SIZE=2 FACE="Arial">Wednesday, June 4, 2003 6:44 PM</FONT>
<BR><B><FONT SIZE=2 FACE="Arial">To:</FONT></B> <FONT SIZE=2 FACE="Arial">Robert J. Liebsch; Michael Reilly; Kurt Seifried</FONT>
<BR><B><FONT SIZE=2 FACE="Arial">Cc:</FONT></B> <FONT SIZE=2 FACE="Arial">Ben Tyson-Norrman; full-disclosure@lists.netsys.com</FONT>
<BR><B><FONT SIZE=2 FACE="Arial">Subject:</FONT></B> <FONT SIZE=2 FACE="Arial">RE: [Full-Disclosure] [OFFTOPIC] Zone Alarm</FONT>
</P>
<P><FONT FACE="Chicago">>-----Original Message-----</FONT>
<BR><FONT FACE="Chicago">>From: Robert J. Liebsch [</FONT><U><FONT COLOR="#0000FF" FACE="Chicago"><A HREF="mailto:rliebsch@stoneyamashita.com">mailto:rliebsch@stoneyamashita.com</A></FONT></U><FONT FACE="Chicago">] </FONT>
<BR><FONT FACE="Chicago">>Sent: Wednesday, June 04, 2003 6:45 PM</FONT>
<BR><FONT FACE="Chicago">>To: Michael Reilly; Schmehl, Paul L; Kurt Seifried</FONT>
<BR><FONT FACE="Chicago">>Cc: Ben Tyson-Norrman; full-disclosure@lists.netsys.com</FONT>
<BR><FONT FACE="Chicago">>Subject: RE: [Full-Disclosure] [OFFTOPIC] Zone Alarm</FONT>
<BR><FONT FACE="Chicago">></FONT>
<BR><FONT FACE="Chicago">></FONT>
<BR><FONT FACE="Chicago">>I have on asbestos underwear, so I am prepared for your flames... </FONT>
<BR><FONT FACE="Chicago">></FONT>
<BR><FONT FACE="Chicago">You should be, since you're using HTML email. :-)</FONT>
<BR><FONT FACE="Chicago">></FONT>
<BR><FONT FACE="Chicago">>However, Because security is inconvenient does not make it </FONT>
<BR><FONT FACE="Chicago">>irrelevant. You do have your car serviced? You do go see a </FONT>
<BR><FONT FACE="Chicago">>doctor regularly? You do perform maintenance to your home?</FONT>
<BR><FONT FACE="Chicago">> ....don't you? </FONT>
</P>
<P><FONT FACE="Chicago">Yes, but I don't expect my 20 year old daughter to jump in my Ferrari</FONT>
<BR><FONT FACE="Chicago">and drive it safely either. She drives the Honda Civic, and after she's</FONT>
<BR><FONT FACE="Chicago">got some experience under her belt and has gone to driving school *then*</FONT>
<BR><FONT FACE="Chicago">I'll consider giving her the keys to the Ferrari.</FONT>
</P>
<P><FONT FACE="Chicago">I'd rather have an inexperienced user behind a PFW any day than expect</FONT>
<BR><FONT FACE="Chicago">them to understand and *properly* implement NAT *and* a firewall. I'd</FONT>
<BR><FONT FACE="Chicago">rather have them introduced to the concept of security in a way that</FONT>
<BR><FONT FACE="Chicago">they understand than to shove it down their throats with technology they</FONT>
<BR><FONT FACE="Chicago">don't comprehend and can't possibly use correctly.</FONT>
</P>
<P><FONT FACE="Chicago">Paul Schmehl (pauls@utdallas.edu)</FONT>
<BR><FONT FACE="Chicago">Adjunct Information Security Officer</FONT>
<BR><FONT FACE="Chicago">The University of Texas at Dallas</FONT>
<BR><FONT FACE="Chicago">AVIEN Founding Member</FONT>
<BR><U><FONT COLOR="#0000FF" FACE="Chicago"><A HREF="http://www.utdallas.edu/~pauls/">http://www.utdallas.edu/~pauls/</A></FONT></U>
</P>
<BR>
<BR>
</UL>
</BODY>
</HTML>