Firewall Wizards mailing list archives

Re: MISSI X31 results


From: Alfred Huger <ahuger () silence secnet com>
Date: Wed, 8 Oct 1997 10:16:29 -0600 (MDT)


I'm glad the NSA posted the reviews.  The only bones I have to pick with the
site ( http://missi.ie.org/ ) is the age of the versions posted.  I'd also
like to see an Altavista report, since I deal with quite a few sites that
have those also.

Hmm, I suppose you could write them and ask. The reports (as have been
pointed out) are a little dated. I am not sure what the mandate of the X31
group is. But if it's a full time Firewall evaluation team then maybe we
can hope for the Altavista Firewall to be evaluated. 


Hmm...Come to think about it, I'd like to see their evaluation process
posted, so the rest of us can generate/challenge similar reports.


What did they leave out of their testing procedure that you would like
displayed? It looked fairly full featured to me.

It stands to reason that for Government use, using a foreign-made product
for security purposes has got to make the NSA to pause and reflect, "is this
_really_ such a good idea?".  It goes against all doctrine in their security
briefings.

I am not sure this is accurate. Your military uses a number of crypto
machines developed here in Canada, as well as other tools. On top of that
both your intelligence and military communities use vulnerability
assesment tools developed in Canada. Israel if anything holds more
political signifigance than Canada does on Capitol Hill. Count the
lobbiests.

I was told the report was complete OVER TWO MONTHS AGO, whereas the other
vendor reports were immediately posted.  I'm much happier about the response
you got, much better than what I got: "the results are now classified and we
will not be posting them on any public Web server".  - Or - Me: "I've heard
from .mil source <insert conspiracy theory here>".  X31: "We can't discuss
the issues.  Refer to your existing .mil source for details."  (Um, yea,
that helps...)  :(


I like the response I got much better than the one you recieved :> Not
being an American tax payer I find it difficult to take umbrage at your
gov't slapping classified ratings on studies such as this. Of course I can
see where it would bother you.


/****************************************************************************
Alfred Huger                                    http://www.secnet.com/ballista
Project Director                                ahuger () secnet com
Secure Networks Inc. (SNI)
*****************************************************************************/



Current thread: