BP Exposing 18,000 Laptops To The Internet
By Daniel Miessler on February 22nd, 2006: Tagged as Information Security | Security
…in order to “secure” them.
Link: BP takes 18,000 laptops off LAN
Something is either wrong with this story, i.e. it’s been taken out of context, or the guy who did this is completely insane.
The guy is basically saying that the only way to test for resistance to attack is to expose yourself to it directly. While that might sound cool, it’s utterly foolish. This to me is like testing a car’s safety features by driving on the wrong side of the road.
Think about layered security — defense in depth. You don’t “harden” systems by removing the most important layers of security. And the fact of the matter is that when (not if) something bad happens, the guy who did this is going to lose his job. Imagine being audited in this configuration.
“Yeah, we decided to just sit outside the firewall and expose ourselves the latest zero-day attacks directly. It’s the only way to be safe.”
The auditors are going to have a field day with this guy. But that’s assuming this even happened; I’m inclined to believe this has been blown out of proportion and isn’t really as bad as this piece says it is. It’s just too radical, and I don’t see it getting past even the most cursory glance at the idea at a large corporation.