Letters to the Editor
-
Re: Re: @gordon
I agree that it is unlikely that someone, posing as the Colonel, broke into CENTCOM's network and sent the message.
I also agree that it is unlikely, but not as unlikely, that someone got into salon.
I'm not going to scan either network (I like Cuba, but I don't want to live there), but I will say that I think that compared to CENTCOM, salon is probably made of Swiss Cheese. I would wager that CENTCOM's mail servers are not directly on the internet, and that there is some sort of MILNET <-> X29 <-> INET gateway in place. Salon's IDS or firewalls are only as clever as the people running them, minus the amount of usability the users (internal and external) require of the network and its services.
But what is possible and likely are two different things. I would not, as an administrator, be comfortable with saying "well, our network is secure so I know the email isn't fake." That's what we call in the industry "famous last words."

