RE: QualysGuard

From: DeGennaro, Gregory (Gregory_DeGennaro@csaa.com)
Date: Mon Aug 30 2004 - 11:24:40 EDT


This is completely true.

Again, you have to accept the risk that the data at Qualys can either be
compromised or viewed by Qualys. Yes, I am sure that the data is quite
safe. However just like data vaults which in a sense Qualys is a data
vault, they do have a copy of your encryption keys and therefore there
is a chance that they can view your data or your data could be
compromised by an elite cracker or through an inside job by either a
disgruntle employee or in error.

Someone brought up the fact that your local machine can be cracked too.
This is very true, however you are in complete control of your data and
if you do encryption correctly with proper passwords, offline key
escrow, back-ups, and fire proof safes, your data will most likely be
more secure than at Qualys.

However if you feel that Qualys is safe, you do not need a risk
acceptance, and you have the budget, then Qualys is a very reliable,
portable, and useful tool.

Qualys does offer demonstration packages, perhaps you should contact a
Qualys account manager to see for yourself and determine if this is the
right product for you.

As for my careful team, we will stick to devices and services that are
completely under our control.

This my opinion and I am sure that other professionals will share their
opinion's as well.

Regards,
 
Greg DeGennaro Jr., CISSP, CCNP
Systems Engineer

-----Original Message-----
From: Eric Danso [mailto:edanso@myblackberry.com]
Sent: Wednesday, August 25, 2004 5:05 PM
To: Haseeb Chaudhary; 'Eric Danso'; pen-test@securityfocus.com
Subject: RE: QualysGuard

Thanks for the info

the one thing that i wanted to verify is I heard through
other users that Qualys is a distrbuted solution where the
reports are all stored at a database at Qualys. This
allows you to get reports anywhere but I'm not sure what
value you get from that. I can set up a webserver and
allow certain users to view the reports.

Is this true.??

------------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. All of our class sizes are
guaranteed to be 12 students or less to facilitate one-on-one interaction
with one of our expert instructors. Check out our Advanced Hacking course,
learn to write exploits and attack security infrastructure. Attend a course
taught by an expert instructor with years of in-the-field pen testing
experience in our state of the art hacking lab. Master the skills of an
Ethical Hacker to better assess the security of your organization.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
-------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:02 EDT