OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-Disclosure] blocking SkyPE?

Valdis.Kletnieksvt.edu
Date: Mon Jan 24 2005 - 23:13:36 CST


On Tue, 25 Jan 2005 10:05:23 +0700, Alain Fauconnet said:

> I would certainly not call our users a legion of techies (sometimes I wish
> they'd be more techies than they are). Setting up a VPN would require
> having control of a box outside of our campus, which is not likely for
> the vast majority of them. Even if some can still get through,
> blocking 80+% of the current SkyPE users is good enough for me.

For those of you playing along at home, the actual requirement to set up a VPN
is merely that they know somebody who has control of a box outside the campus
(or even know where to find a tunnel broker). And Alain is probably quite
correct that even that lower standard will stop 80% and be sufficient for his
needs.

But you need to remember the difference, in case you need *better* than 80%,
and your users are either more clued or they know more clued people.....

How to give the firewall admin indigestion: Do your dirty work via IPv6, and
use a V6-over-V4 tunnel broker to get out to your remote site... :)

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFB9dV/cC3lWbTT17ARApkgAJ42wdsKrpmX9EL9mOT7JTS/7dPqqgCgmVW4
Jl/JAfLr335/92fY3sDzG1g=
=1dN9
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html