<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Schools Battle Proxies</title>
	<atom:link href="http://jonsnetwork.com/2008/05/schools-battle-proxies/feed/" rel="self" type="application/rss+xml" />
	<link>http://jonsnetwork.com/2008/05/schools-battle-proxies/</link>
	<description>Network Security News, Analysis and Ephemera</description>
	<lastBuildDate>Fri, 15 Jan 2010 17:44:55 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jon Robinson</title>
		<link>http://jonsnetwork.com/2008/05/schools-battle-proxies/comment-page-1/#comment-627</link>
		<dc:creator>Jon Robinson</dc:creator>
		<pubDate>Thu, 29 May 2008 15:51:32 +0000</pubDate>
		<guid isPermaLink="false">http://jonsnetwork.com/?p=130#comment-627</guid>
		<description>&lt;p&gt;Hi Chris,  When I say I think monitoring works better than filtering, I&#039;m talking about getting users to comply with the AUP and to start behaving well on the network.  I don&#039;t think anyone should ditch the filter.  I just think they should be realistic about what it does.  They all have holes in them and you can get a better picture of AUP violations with better monitoring. &lt;/p&gt;

&lt;p&gt;You bring up an excellent point with the malicious code subject.  That is probably the main reason to filter right now.  Look at &lt;em&gt;all&lt;/em&gt; sites for dangerous code rather than just looking at the URL from an AUP point of view.  The malicious code risk is way low on the radar of schools in my experience.  Many of the filters they use are not equipped to deal effectively with that risk.  What I said was mainly targeted at schools (my main customers) that rely on their filter to do something that monitoring can do better in my experience.  It&#039;s mainly psychological: a video camera that lets you know you are being watched vs a fence that needs to be jumped over. &lt;/p&gt;

&lt;p&gt;About the palo alto thing...that is totally based on hearsay from all three companies and totally qualitative based on my experience.  I could be totally wrong.  Fine, I&#039;ll go do some homework and find out the right answer.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi Chris,  When I say I think monitoring works better than filtering, I&#8217;m talking about getting users to comply with the AUP and to start behaving well on the network.  I don&#8217;t think anyone should ditch the filter.  I just think they should be realistic about what it does.  They all have holes in them and you can get a better picture of AUP violations with better monitoring. </p>

<p>You bring up an excellent point with the malicious code subject.  That is probably the main reason to filter right now.  Look at <em>all</em> sites for dangerous code rather than just looking at the URL from an AUP point of view.  The malicious code risk is way low on the radar of schools in my experience.  Many of the filters they use are not equipped to deal effectively with that risk.  What I said was mainly targeted at schools (my main customers) that rely on their filter to do something that monitoring can do better in my experience.  It&#8217;s mainly psychological: a video camera that lets you know you are being watched vs a fence that needs to be jumped over. </p>

<p>About the palo alto thing&#8230;that is totally based on hearsay from all three companies and totally qualitative based on my experience.  I could be totally wrong.  Fine, I&#8217;ll go do some homework and find out the right answer.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Christofer Hoff</title>
		<link>http://jonsnetwork.com/2008/05/schools-battle-proxies/comment-page-1/#comment-620</link>
		<dc:creator>Christofer Hoff</dc:creator>
		<pubDate>Thu, 29 May 2008 06:11:02 +0000</pubDate>
		<guid isPermaLink="false">http://jonsnetwork.com/?p=130#comment-620</guid>
		<description>&lt;p&gt;Jon:&lt;/p&gt;

&lt;p&gt;I&#039;m wondering about your last paragraph.  &lt;/p&gt;

&lt;p&gt;What if you&#039;re not just interested in &quot;accountability&quot; but also protecting against malicious drive-by client-side attacks?&lt;/p&gt;

&lt;p&gt;Monitoring is important, but how do you reconcile AUP violations against legitimate sites doing illegitimate things if compromised?&lt;/p&gt;

&lt;p&gt;Were you suggesting that monitoring can replace filtering?&lt;/p&gt;

&lt;p&gt;Also, how did you establish that Palo Alto does MITM/SSL proxy the fastest?&lt;/p&gt;

&lt;p&gt;Thanks,&lt;/p&gt;

&lt;p&gt;Hoff&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Jon:</p>

<p>I&#8217;m wondering about your last paragraph.  </p>

<p>What if you&#8217;re not just interested in &#8220;accountability&#8221; but also protecting against malicious drive-by client-side attacks?</p>

<p>Monitoring is important, but how do you reconcile AUP violations against legitimate sites doing illegitimate things if compromised?</p>

<p>Were you suggesting that monitoring can replace filtering?</p>

<p>Also, how did you establish that Palo Alto does MITM/SSL proxy the fastest?</p>

<p>Thanks,</p>

<p>Hoff</p>]]></content:encoded>
	</item>
</channel>
</rss>
