RE: Any ongoing effort to port /etc/rc.d/pf_boot, /etc/pf.boot.conf from NetBSD ?




I'm not sure the average user _really_ is worried enough
about that half a second period on boot. But I DO know there
will be people locking themselves out from far-away remote
hosts (on updates, for instance) if this becomes the default.

That is pretty much guaranteed. Murphy will always find a way to f*ck up a
reboot and simultaneously cause the 2611 on the console port to halt and
catch fire.

If punters want a default block, IMHO it doesn?t get much easier than using
the mac_ifoff(4) kernel option discussed earlier on in the week, they can
tweak the pf startup to twiddle the relevant sysctl appropriately at the
right moment in time.

In order to salve the consciences of those who know naught but tick boxes,
and more importantly make them STFU and annoy someone else.

Perhaps a codicil to the FreeBSD pf.conf manpage, detailing the mac_ifoff
approach as a wholly unsupported solution for 'default block' to satisfy the
anally retentive.


Greg

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Messed UP IR Remote control [UK] - Update
    ... > I have a Windows XP MCE setup with the RC6 remote control and the ... > doing any of these updates - that way I could roll back any changes. ... > that I now have a driver for "Microsoft eHome Infrared Transceiver" ...
    (microsoft.public.windows.mediacenter)
  • Re: Group Policy - Pushing out Software
    ... I know the way we access users machines using Remote Desktop ... remotely, log on as them and do updates, without ... life easy for 2 administrators keeping 80 users machines updated. ... packages to specific profiles only. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Messed UP IR Remote control
    ... > I have a Windows XP MCE setup with the RC6 remote control and the OVU4003/00 ... > However I then got overexuberant in installing optional updates via Windows ... > Interface Devices" look identical to the previous working configuration. ...
    (microsoft.public.windows.mediacenter)
  • Re: automatic update on Mac OS X
    ... Since VNC will not applay updates, and is just for remote controlling the ... Sebastian ...
    (Security-Basics)
  • Re: Within C, how can I check if other computers (Linux) are up
    ... The remote systems are ... > and the remote systems might be behind a NAT (Network Address Translation) ... you can send ICMP ECHO packets and watch for ICMP ECHO-REPLY. ... protocols) for hosts guaranteed to be on the same network, ...
    (comp.sys.sgi.misc)