OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
NFR Wizards Archive: Re: Screening Outgoing Mail for Content

Re: Screening Outgoing Mail for Content


Peter Jeremy (peter.jeremyauss2.alcatel.com.au)
Thu, 6 Aug 1998 07:59:42 +1000


On Thu, 06 Aug 1998 03:39:18 +1000, Wilson Roberto Afonso <wilsonzaz.com.br> wrote:
>On the other hand, if you are paranoid/determined enough, you might just
>block whatever you cannot screen. So, binary attachments are out, just
>as uuencoded files etc.
That would be a logical starting point.

It still wouldn't catch text-based steganography. Just because a
message appears to be a discussion of the relative merits of different
baseball pitchers (or whatever) doesn't mean that it doesn't also
contain the companies master keys (or whatever).

> Might still not be a 100% safe without hand screening, though.
I'm not sure even hand screening would catch the above. You'd need to
move to the next level - have someone re-write all incoming/outgoing
mail to change the wording/phrasing etc.

I don't believe there is any technological means by which you can stop
someone smuggling information in or out of an organisation.

Peter

--
Peter Jeremy (VK2PJ)                    peter.jeremyalcatel.com.au
Alcatel Australia Limited
41 Mandible St                          Phone: +61 2 9690 5019
ALEXANDRIA  NSW  2015                   Fax:   +61 2 9690 5247



This archive was generated by hypermail 2.0b3 on Sat Jul 17 1999 - 07:11:39 CDT