We definitely have had problems with network security. Some
blame for our problems must go to my predecessor and myself, but
much also goes to Sun for not having a very secure OS.
I have been facility manager at UW-Madison for about 18 months. We
have a mixed environment, Brukers (AM, AC, WP) and two Varian Unity's.
Having a Bruker background, I had a lot to learn on the Unity's.
Unfortunately, I learned most about the SunOS after we were invaded by
hackers that caused problems country-wide in Jan-Feb 95. Our Sun's had
gapping holes in the OS that let the hackers install password
sniffing and use our machines as FTP routers (they may have been
doing more, but these two we found). It took me well
over 50 hours of work to clean up the workstations, and with the
help of our computer center on campus, install 24 patches (about
half bug fixes, about half for security) to our current SunOS
4.1.3_U1.
I can give you more details if you wish, but let me summarize
with the following:
1. If you have Sun's, and are inexperienced as a manager of this
OS (as I was!!), beware. You should get comfortable with the OS
before connecting the systems up.
2. If you have SGI's, the security issues are less, so you're
probably ok.
3. Being on the net is great. Although I spent a lot of time
learning how to make our systems secure, I've never really considered
taking them off the net. However, we do have a PC network (Novell)
that is on its own net, and I have installed only a simple ftp
server on it that serves ok. Even though I like being on the
net, I do not allow non-console root logins, restrict su priviledges,
do not allow cross-mounting to
any machine that is not directly under my control, and carefully
control passwords and remote usage, in addition to the patches
mentioned previously.
Hope this helps; the main message is to not take security issues
too lightly. Unfortunately, the world is not as simple as we
might wish. I don't think there's any reason to not connect to
the net, but it's a good idea to make sure you have the right
setup in place before doing so.
Charles G. Fry
Director-Magnetic Resonance Facility
Department of Chemistry
University of Wisconsin-Madison
Madison, WI 53706
Tel: 608-262-3182
email: fry@chem.wisc.edu
>Cathy writes:
>
>Currently, our NMR facility is not connected to the network. We only have our
>spectrometers and workstations on a local network. I am thinking of hooking
>up to the outside world, but was wondering if there are any good reasons why
>I shouldn't do this.
>The previous facility director here did not feel it was a good idea to
>connect to the
>outside world for security reasons, however, I feel it is worth the risk for the
>convenience of easy access to data files. Has anyone experienced any problems
>because they were on the network. I would greatly appreciate any comments.