« Pay it forward tip of the day | Main | Pay it forward security tip #3 »

August 03, 2006

OK, maybe not a genius, but not a bad guy

Last week I wrote about going to Black Hat and among other presentations, I wanted to see Ofir Arkin of Insightix present.  This was the one that was going to show how every NAC solution can be bypassed by a determined hacker.  I was pretty hard on Ofir in this post and an earlier post.  I have always tried to call them as I see them and if I am wrong, be big enough to say so.  In this case I am not saying I was particularly wrong, but I think Ofir and I have more in common about our views on NAC than we disagree on.  It also appears that Ofir may have been misquoted or taken out of context in some of the articles I read about him.

Yes, the gist of bypassing the DHCP based solutions was the static IP or spoofed IP or MAC address.  He also showed how ARP twiddling  is easily evaded.  However, I think the gist of Ofir's presentation was pointed to the Cisco NAC methodology.  Their L2 and L3 quarantine and testing is just not a very secure way of implementing NAC with lots of weaknesses according to Ofir.  I do not disagree with Ofir on these points.  Ofir and I also agree that a well implemented 802.1x NAC offering is probably one of the best ways to implement NAC.  The problem is finding enough customers with 802.1x capable networks.  So Ofir though stating some obvious drawbacks to some methods of NAC, was right on in other points.  Another point of his presentation, was that there is no common criteria of what NAC is and how it does it.  All in all, it was a good presentation.  An important point is that NAC is not really geared towards stopping the determined hacker, but rather the inadvertant polluter. 

I had a chance to speak to Ofir afterwards.  Though he had read my blog and was upset that I did not reach out to him first (note to self, next time, reach out and give them a chance to explain), after our talk I think we had a good meeting of the minds.  I have invited him to be a guest on my podcast one week and we can talk about NAC further.  Looking forward to it.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/547509/5581259

Listed below are links to weblogs that reference OK, maybe not a genius, but not a bad guy:

» The Daily Incite - August 4, 2006 from Security Incite: Analysis on Information Security
August 4, 2006 Good Morning: Back in the ATL after my quick Black Hat jaunt. Why are folks surprised by the amount of press coverage that Black Hat received, even from the mainstream media? There was real content there and it was controversial. What [Read More]

Comments

Search

Lijit Search

disclaimer

  • The views and opinions expresed here are those of myself only and in no way represent the views or positions or opinions of my employer, Latis Networks, Inc. d/b/a StillSecure or anyone else.

Forbes.com

StillSecure, After all these years, the podcast

  • Podlogo

Currently Reading

  • Conn Iggulden: Genghis: Birth of an Empire

    Conn Iggulden: Genghis: Birth of an Empire
    I have always been drawn to stories of Genghis Khan. How was he able to take a primitive people and conquer most of the world? What did the Mongol culture have that enabled this. This is the first of a trilogy on the life of the great Khan. It is great, easy reading and gives a great picture into the life and times of GK. (****)

Read Recently

Blog powered by TypePad
Member since 10/2005