View Single Post
  #89   Report Post  
Posted to uk.d-i-y
Rod Speed Rod Speed is offline
external usenet poster
 
Posts: 40,893
Default Idle fun for net hackers..

Tim Watts wrote
The Natural Philosopher wrote
Tim Watts wrote
The Natural Philosopher wrote


exactly, An undetectable change that results in no detectable
activity by anyone in the whole universe is not a security risk.


You may have a "potentially detectable" change, but for any
practical detection mechanism, I feel fairly safe in asserting that
it could potentially be hacked so as not to leave a trace
*detectable by the detection mechanism".


Agreed, but then the second point kicks in, if its that invisible it cant do anything useful


It's an arms race - however many tripwires you put up, there's
always a way, no matter how improbable, that a change could be
effected that does not trip the tripwires.


No, it is not.


It's been demonstrated time and time again that everytime you put an
obstacle in the way of people who care, they will eventually defeat
it if determined enough.


Indeed, and that's why you don't rely on them not getting in: You
monitor inside to see if they have and keep a backup and lots of
audit trails.


And look at them.


So you KNOW they dont get in, or conversely, that they did.


OTOH to maintain a server on the internet that is virtually
impossible to hack is actually not hard. Its a lot harder to protect
an organisation or internet. To many variables and too many users.
BUT a server is a simple thing to protect.


And the integrity of your audit trails is guaranteed how exactly?


Plenty of obvious ways to do that.