Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-23-2008, 01:27 PM
marlow.andrew@googlemail.com
Guest
 
Posts: n/a
Default should I encrypt over a private network?

Suppose a company has 2 sites, A and B, one is primary, the other is
secondary for DR reasons. A and B are separated significantly
geographically. Both A and B use a SAN for their data. A and B are
connected by a private network. The SAN data is replicated between A
and B over this private network using some replication product. My
question is, "should I be worried about the fact that the SAN
replication product does not do encryption?". When I raised these
concerns the answer I was given was "its a private network so its not
a problem". I am still not sure. Maybe I'm paranoid but I thought most
security jobs were inside jobs and this is made easier if the data
going over the wire is always in plaintext. But then again, data sent
around the LAN using NFS is not encrypted either.

Regards,

Andrew Marlow

Reply With Quote
  #2 (permalink)  
Old 05-23-2008, 01:49 PM
Anne & Lynn Wheeler
Guest
 
Posts: n/a
Default Re: should I encrypt over a private network?


marlow.andrew@googlemail.com writes:
> Suppose a company has 2 sites, A and B, one is primary, the other is
> secondary for DR reasons. A and B are separated significantly
> geographically. Both A and B use a SAN for their data. A and B are
> connected by a private network. The SAN data is replicated between A
> and B over this private network using some replication product. My
> question is, "should I be worried about the fact that the SAN
> replication product does not do encryption?". When I raised these
> concerns the answer I was given was "its a private network so its not
> a problem". I am still not sure. Maybe I'm paranoid but I thought most
> security jobs were inside jobs and this is made easier if the data
> going over the wire is always in plaintext. But then again, data sent
> around the LAN using NFS is not encrypted either.


in the mid-80s, there were claims that the corporate internal network
had over half of all the link encryptors in the world (basically any
link leaving corporate premise had to be encrypted) ... this was
about the time that the size of arpanet/internet finally exceeded
the internal network (which had been larger from just about the
beginning until sometime mid-85) ... misc. posts mentioning internal
network:
http://www.garlic.com/~lynn/subnetwork.html#internalnet

in that period there was a story about a foreign consulate location, in
one of the major city, apparently was chosen because it had line-of-site
of a large microwave communication antenna array for major cross-country
communication. there were comments that a lot of foreign government
espionage was heavily intertwined with industrial espionage.

slightly earlier, in the early part of the 80s ... was looking at
deploying dial-up access into the corporate network for both (actually
major expansion for) home access (since i've had dial-up access at home
since mar70) and hotel/travel access. a detailed study found that hotel
pbx rooms were frequently especially vulnerable ... and as a result
encryption requirement was extended to all dial-up access ... which
required designing and building a custom encrypting dial-up modem for
these uses.

a lot of the internet hype seems to have distracted attention from both
other forms of external compromises as well as internal attackers.

Reply With Quote
  #3 (permalink)  
Old 05-26-2008, 09:26 AM
Ertugrul =?UTF-8?B?U8O2eWxlbWV6?=
Guest
 
Posts: n/a
Default Re: should I encrypt over a private network?

marlow.andrew@googlemail.com wrote:

> Suppose a company has 2 sites, A and B, one is primary, the other is
> secondary for DR reasons. A and B are separated significantly
> geographically. Both A and B use a SAN for their data. A and B are
> connected by a private network. The SAN data is replicated between A
> and B over this private network using some replication product. My
> question is, "should I be worried about the fact that the SAN
> replication product does not do encryption?". When I raised these
> concerns the answer I was given was "its a private network so its not
> a problem". I am still not sure. Maybe I'm paranoid but I thought most
> security jobs were inside jobs and this is made easier if the data
> going over the wire is always in plaintext. But then again, data sent
> around the LAN using NFS is not encrypted either.


The network is only being private in that selected people are given
access to it -- so much for the theory. In practice, the network is
just as open as all geographically diffused networks. Someone may
install wiretaps or even just connect to the network like all others.

So indeed, your worries aren't unfounded. Usually it's best to encrypt
the link using your VPN product of choice, like OpenVPN.


Regards,
Ertugrul.


--
http://ertes.de/


Reply With Quote
  #4 (permalink)  
Old 05-27-2008, 01:01 PM
marlow.andrew@googlemail.com
Guest
 
Posts: n/a
Default Re: should I encrypt over a private network?

Ertugrul Söylemez wrote:
> marlow.andrew@googlemail.com wrote:
>
> > Suppose a company has 2 sites, A and B, one is primary, the other is
> > secondary for DR reasons. A and B are separated significantly
> > geographically. Both A and B use a SAN for their data. A and B are
> > connected by a private network. The SAN data is replicated between A
> > and B over this private network using some replication product.


> The network is only being private in that selected people are given
> access to it


No, not in this case. I should have been clearer. It is private
because there is dedicated circuitry. It really IS a private network,
NOT a VPN.

> In practice, the network is
> just as open as all geographically diffused networks. Someone may
> install wiretaps or even just connect to the network like all others.


I was worried about breaches originating via inside jobs. Since the
circuitry is private no-one else can connect to it easily. Wiretaps
are still a possibility.

>
> So indeed, your worries aren't unfounded. Usually it's best to encrypt
> the link using your VPN product of choice, like OpenVPN.


This is not a VPN. My understanding (and I am a beginner here) is that
all VPNs use encryption as std.

-Andrew Marlow

Reply With Quote
  #5 (permalink)  
Old 05-27-2008, 02:07 PM
Ertugrul =?UTF-8?B?U8O2eWxlbWV6?=
Guest
 
Posts: n/a
Default Re: should I encrypt over a private network?

marlow.andrew@googlemail.com wrote:

> > > Suppose a company has 2 sites, A and B, one is primary, the other
> > > is secondary for DR reasons. A and B are separated significantly
> > > geographically. Both A and B use a SAN for their data. A and B are
> > > connected by a private network. The SAN data is replicated between
> > > A and B over this private network using some replication product.

> >
> > The network is only being private in that selected people are given
> > access to it

>
> No, not in this case. I should have been clearer. It is private
> because there is dedicated circuitry. It really IS a private network,
> NOT a VPN.


This isn't sufficient for a network to be private.


> > In practice, the network is just as open as all geographically
> > diffused networks. Someone may install wiretaps or even just
> > connect to the network like all others.

>
> I was worried about breaches originating via inside jobs. Since the
> circuitry is private no-one else can connect to it easily. Wiretaps
> are still a possibility.


Not only are wiretaps a possibility, but anyone who manages to
comprehend the circuitry can connect to it. Unless the link is
encrypted, the network is considered public from the point of view of
security.


> > So indeed, your worries aren't unfounded. Usually it's best to
> > encrypt the link using your VPN product of choice, like OpenVPN.

>
> This is not a VPN. My understanding (and I am a beginner here) is that
> all VPNs use encryption as std.


No, a VPN (virtual private network) is just a network inside of another
network. Traditionally it was an emulation of a private network with a
private address space inside of a public network like the internet.
It's a purely virtual construct. Naturally it's a good layer to also
add encryption and authentication.


Regards,
Ertugrul.


--
http://ertes.de/


Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
wireless router password security RS alt.computer.security 9 05-12-2008 12:43 AM
Alan Parkington FUCKED it up again Simon Templar aus.comms.mobile 50 02-09-2008 06:44 PM
Doctor Who's security & encryption FAQ v21.4 newsmanis@yahoo.com.au alt.computer.security 0 10-10-2007 09:34 PM
Re: Setting up network - run wizard or not? John Navas alt.internet.wireless 2 11-29-2006 02:15 PM
Question about cryptography and public/private keys Erich Kohl alt.computer.security 7 11-11-2006 02:12 PM


All times are GMT. The time now is 12:05 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45