[cap-talk] Bill Frantz HP challenge (was: Re: [Confused deputies in hybrid systems (was: Loss of control))

Karp, Alan H alan.karp at hp.com
Thu Feb 7 19:43:35 EST 2008


Bill Frantz wrote:
>
> I admit that I don't know how HP management is likely to answer this
> question. It seems reasonable to have a policy that the data is
> only accessed from inside the HP campuses to minimize the dangers of
> shoulder surfing.

A connection via the VPN is considered to be inside the firewall regardless of the location of the machine.  Setting up the connection requires two-factor authentication.  In addition, the HP Intranet supports Network Access Control, which tests the state of the machine (virus signatures, software firewall) before granting access.  Avoiding shoulder surfing is covered in the Business Conduct Guidelines.

________________________
Alan Karp
Principal Scientist
Virus Safe Computing Initiative
Hewlett-Packard Laboratories
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp




More information about the cap-talk mailing list