CompuServe Messages

QM Security Hole?

    17-Mar-94 13:07:18
Sb: #145801-QM Security Hole?
Fm: Ron Webb 73633,1034
To: Syndesis 76004,1763
Was the "local network security firm" perhaps trying to sell a security product of some sort? Do they even know what QuickMail is? We've used QM's gateways for a couple of years, and although we're not particularly concerned about security here (most of our users have no passwords either), I don't think it's fair to say it's "full of holes". The security firm seems to think that QM dial-in gives outsiders complete access to the network. That's not true at all. It gives access to the E-mail system only, not to file servers or other machines. There is NO WAY a dial-in user could interfere with files or get at other devices on the network. Perhaps the guy is confusing QM with ARA. In my experience, I have noted only one security problem, and I'm not sure how it happened. We were experimenting with the modem init strings, and created a situation where a legitimate user could disconnect without actually logging out. The next person (potential hacker) who dialed in would resume the previous user's session without the need to log in or provide a password. But I don't think that could happen with a properly configured modem. QM's security is basic, in that it doesn't provide call-back or force users to use or change passwords. But it's not "full of holes". Unless your E-mail is full with super-sensitive information, or your company is a prime target for industrial espionage, I wouldn't worry about it. (Then again, if your friend's company felt it necessary to hire a "network security firm", maybe they fall into one of those categories.) – Ron