Re: Re: [Micronet] Upgrades and Security Requirements

From: John Wuorenmaa <johnww_at_uclink.berkeley.edu>
Date: Thu Jun 24 2004 - 14:09:16 PDT

Chris brings up an interesting scenario. How many of the network attached
computers/devices on campus only need access to local resources, ie not the
broader Internet? Could the Minimum Security Standards Policy be changed
to differentiate between the two types of computers. Maybe under Chris's
scenario he could have all his "data acquisition" machines behind their own
cheap $30 NAT Firewall that only allowed communication to and from a
supported machine. If that's not feasible, how difficult would it be to
segregate those machines to their own "anything goes" subnet at the
building/data closet level that is not connected to the rest of
campus? Could the University benefit from a separate campus-wide network
that these unsupported machines lived on? Just a thought.

John Wuorenmaa
BLC

>Roy,
>
>it is not such a simple thing to just get rid of old equipment. In my
>case, I have 30 Macs used as data acquisition computers with associated
>cabling and interface boxes. Our life cycles are very long due to the
>high expense of changing systems. Our last set of Macs ran from 1996 to
>2003 with almost no maintenance (aside from a floppy drive failure). We
>had to replace them as they were just getting worn out from abuse. We
>just got through "upgrading" last year but we are continuing to use Mac
>OS9 as our software no longer supports our cards in OS10. We do not need
>the latest, greatest, fastest for our purposes so we are not compelled to
>keep up with a 3 year replacement cycle.
>
>Our data acquisition computers need network access as that is the only
>efficient way to get data off the computers. Floppy disks dont cut it anymore.
>
>I found it beneficial to lag behind the curve, especially with a mac, as
>no one was bothering to write virus' or trojans for these old, slow,
>sparse computers.
>
>Now it seems we are being forced to upgrade not because of our needs but
>rather the desires of others. We have neither the funds nor the man power
>to do this on a continuous basis (we have no dedicated IT person). At the
>same time, my computers have never been blocked due to any abuses.
>
>It is nice to say that we should all just upgrade and keep up with the
>Joneses but we do not have this kind of money without affecting our
>teaching mission. As far as I know, we do not have a budget to replace
>these computers and my plan was to keep them for another 5 years in their
>current configuration. Now I'm between a rock and a hard place. Upgrade
>or get blocked. Either way, the students lose.
>--
>Chris Kumai

------------------------------------------------------------------------
The following was automatically added to this message by the list server:

For information about MAGNet, its meetings and events, and its
mailing list, including information on subscribing and unsubscribing,
see the MAGNet Web site at <http://magnet.berkeley.edu/>.
Received on Thu Jun 24 14:16:55 2004

This archive was generated by hypermail 2.1.8 : Thu Jun 24 2004 - 14:16:55 PDT