Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Microsoft rights management server alternatives |
|---|---|
| Date: | Mon, 22 Nov 2004 14:58:04 -0500 |
I agree... the biggest failure in the technology is the remaining
weekness to Ananlog attacks such as taking a picture of protected
content on a screen. I cant even say that I personally totaly buy into
this technology but for some groups in the company I work for, this
technology is ideal and satisifies a regulatory need that exists. No one
technology is the holy grail for securing your environment. What we have
are many small pieces that you put together to come up the most complete
solution possible.
As far as copy in paste to a document, If you choose the right
technique for rights managed content, you can also protect content that
is copied from one doc to another while also keeping a running audit
trail of how the document is being accessed no matter where it goes. I
believe this technology has a long way to go but we are seeing a fine
start.
Just as a
-----Original Message-----
From: Jimi Thompson [mailto:jimi.thompson@gmail.com]
Sent: Saturday, November 20, 2004 1:23 AM
To: Thompson, Tichard
Cc: Lists; focus-ms@securityfocus.com
Subject: Re: Microsoft rights management server alternativeses.
The DRM stuff is all a seriously bad joke that's been played out on
management. You still have to TRUST the people that work there. If I
can display it on my screen, no matter what else fails I can get my
nifty camera and take a photograph of the document or whatever I'm not
supposed to be able to pass around. If I can play it through my
speakers or headphones, I can whip out my trusty old casette recorder
and tape it. Where's your DRM then? Neither of these are
particularly high-tech approaches and are well within the reach of the
average schmoe.
Further more, if I have sufficient rights to open a document, let say
that I copy and paste from the contents of your DRM document into a
new document. How do you track the rights to that? It's better to
be loyal to your employees so that they are loyal to the company and
don't want to sell you out to begin with. More software isn't going
to fix that.
2 cents,
On Thu, 18 Nov 2004 14:06:11 -0500, Thompson, Tichard
<tichard.thompson@pharma.com> wrote:
Checkout LiquidMachines which is a stand alone product and also works with an existing RMS infrastructure. Also look at Authentica. Their solutions are a lot better as well as being a lot more
expensive.
T.J CISSP -----Original Message----- From: Lists [mailto:sakaba@alexandria.cc] Sent: Friday, November 12, 2004 7:30 PM To: <focus-ms@securityfocus.com> <focus-ms@securityfocus.com> Subject: Microsoft rights management server alternatives Hi everyone, I am looking into rolling out a solution like microsoft rights server that can encrypt files and assign decrypt rights. I know of Hibun in Japan as well by Hitachi and was wondering if anyone was using
anything
else. Regards, sakaba
------------------------------------------------------------------------
---
------------------------------------------------------------------------
---
------------------------------------------------------------------------ ---
------------------------------------------------------------------------ ---
-- Thanks, Jimi --------------------------------------------------------------------------- ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-Disclosure] IPFront - Release, Hernan Racciatti |
|---|---|
| Next by Date: | RE: Microsoft rights management server alternatives, Derek Schaible |
| Previous by Thread: | Re: Microsoft rights management server alternatives, Joshua Feek |
| Next by Thread: | RE: Microsoft rights management server alternatives, Derek Schaible |
| Indexes: | [Date] [Thread] [Top] [All Lists] |