Register

To become a member of ITProPortal Register here.

Already a member? Login here

Please register below. All we need is a valid email address and a password.

Please use a real email address as we need to email you to confirm your account.
Must be at least 6 characters long.

Benefits of joining ITProPortal:

  • Unlimited Access to Special Reports and White Papers
  • Exclusive offers and discounts
  • Free entry to all competitions
  • Access to beta sections of ITProPortal.com

Login to your account



Forgot your password?


Are disclaimers a security risk?

Are disclaimers a security risk?
  • Digg del.icio.us reddit Facebook

Analyst says disclaimers are bad because: Any standardized, boilerplate text is a godsend for a malicious network sniffer who's hell-bent on stealing your secrets.

Imagine you are trying to commit corporate espionage by tapping into an ISP's network and watching all the network packets go by. It would be like drinking from a fire hose: very difficult to select the packets containing email text from the organization you're targeting. However, if you knew that organization used a standard disclaimer, you could have your packet sniffer search for packets containing that text. It's likely it would pick up a very large proportion of the messages you're interested in.

Link here.

I disagree and admit to being somewhat baffled by this article. A bad guy can just as easily sniff for source IP, the From address, domain, etc.

And even if the message is encrypted, that data won't be because it needs to be cleartext in order to be sent — then you would get some of the details regardless of what is done to the message.

Posted by Alex Eckelberry on 21 March 2007

Tags: Windows