Re: Bypassing Personal Firewalls

From: Johan Verrept (jove@exelsys.be)
Date: 02/23/03

  • Next message: alias@securityfocus.com: "Re[2]: PHPNuke SQL Injection / General SQL Injection"
    Date: Sun, 23 Feb 2003 21:13:42 +0100
    From: Johan Verrept <jove@exelsys.be>
    To: Shaun Clowes <shaun@securereality.com.au>
    
    

    Shaun Clowes wrote:

    > Why do you believe that the responsibility of protecting users from
    > themselves should be bourne by the operating system? People who are
    > using Personal Firewall systems may indeed want to be protected in
    > this fashion but I suspect that for most people this is a non issue.

    Actually, this has little to do with protecting a user from himself,
    this has to do with protecting one process from another. How do you
    trust any process you have running if malicious code could have embedded
    itself and you have no way of detecting this?

    > When all is said and done, if malicious code can run under your user
    > ID then everything you do is compromised, I can't see much point in
    > giving ourselves a false sense of security.

    Perhaps not. But do you see a good reason to allow any process this much
    power over another unrelated process? If this kind of power is needed by
    one process over another, it should be implemented implicitly in both
    processes or the process should run under superuser UID.

    regards,

        J.



    Relevant Pages

    • Re: CIA, NSA contractor admits to leaking secret programs
      ... It had a pretty good way of protecting the operating system from other programs, but had one weakness called Master Mode Entry. ... I speculated at the time that it would be interesting to create a small program that exploited two MME commands, ... It would have been easy to create a program that repeatedly spawned an image of itself and whose sole function was to go to sleep for a random amount of time. ...
      (soc.retirement)
    • Re: User Permissions for Microsoft Games
      ... It isn't anything against the games, but a matter of protecting the ... operating system from changes which users who might not know what they're ... Microsoft Windows MVP/Tablet PC ...
      (microsoft.public.windowsxp.games)
    • Re: [SLE] Re: Computer resets spontaneously
      ... DC is easy (for AC you have to consider power factor, ... protecting itself and the equipment. ... There is a reason for it however: you can not make fuses fast enough to ...
      (SuSE)
    • Re: UPS for 2 PCs
      ... Is this any good for protecting 2 PCs from surges / spikes and enabling a ... tidy shutdown after a power failure? ... Andy / Dave, ... A couple of DC adaptors attached to the UPS melted and excreted ...
      (uk.comp.homebuilt)
    • Re: Microsoft Java almost gone in Vista
      ... thing is "C doesn't molly-coddle you, it gives you all the power, if you mess up that's your fault" - but I don't believe that's the whole story - I think protecting against programmer error, to some extent, is useful. ...
      (comp.lang.java.programmer)