RDP: MS12-020 - stupid Secunia comment

I just read this article at Computerworld and was somewhat stunned by the comment from an "security expert" from Secunia:



However, the fact that RDP is disabled by default on Windows workstations limits the number of potential targets, so we shouldn't worry about the next Conficker, said Carsten Eiram, chief security specialist at Danish vulnerability research firm Secunia.

Ehmmm... OMG! I certainly hope this poor guy was not quoted correctly, because what it would mean is that a vulnerability, even critical, is not critical if it is not widely deployed. So, if a company has a telnetd running on the DMZ without no password restrictions it is fine, because it is just one server among maybe hundreds. I have no words for this stupidity and ignorance.

This sounds a lot like a guy I used to work with (he called himself a security analyst) and said we shouldn't worry about traffic in clear between two certain servers, since the CAT-5 between those server was so short. Or another time we wouldn't have to worry about securing a web server since the URL to the sensitive page "was so complicated and long". Needless to say this person is no longer working in the computer security field, as far as I know...




Comments

Popular posts from this blog

Overhead lines

R.I.P. Google Reader

Sweden 2 Australia