Re: [CentOS] security by obscurity [was: CentOS VPN server for iPhone]

2009-03-26 Thread Robert Moskowitz
Let me introduce myself: Robert Moskowitz, ICSAlabs, an Independent Division of Verizon Business Systems. Security IS my business and I am a bit of a 'maverick' even in the labs on my positions. ICSAlabs is the company that certifies products: Firewalls, malware, IDS, IPsec, SSLvpn, etc. Flor

Re: [CentOS] security by obscurity [was: CentOS VPN server for iPhone]

2009-03-26 Thread Joseph L. Casale
>I think that's a nice example of pervasive fallacious binary thinking, >combined with an old tired slogan that by all rights should be dead by now. Ok... >By the same token, we should not use firewalls, because they can be >circumvented by people who are skilled enough, nor use passwords, >be

[CentOS] security by obscurity [was: CentOS VPN server for iPhone]

2009-03-26 Thread Florin Andrei
Joseph L. Casale wrote: >> The non-standard port is a good trick, > > Here's just an opinion: Security by obscurity only > makes >you< feel good, it does nothing in reality. > Anyone sufficiently talented to hack a service in > order to gain root or do something useful would not > be fooled by tha