Re: XP(home) firewall good?

From: Gerald Vogt (vogt_at_spamcop.net)
Date: 05/16/04


Date: Sat, 15 May 2004 23:55:07 GMT

Tom McCune schrieb:
> Gerald Vogt <vogt@spamcop.net> wrote in news:66xpc.260660$e17.22342
> @twister.nyroc.rr.com:
>
>
>>That is certainly true as long as you want to install spyware, worms,
>>etc. And then again, as the user can turn off the firewall and program
>>running on your computer can do that, too. And there are tricks to
>>circumvent the outgoing "protection". So, properly shutting down all
>>unnecessary services that windows runs by default and the ICF will do
>>great. A browser that supports decent privacy settings helps, too, and
>>is much better than have one software trying to prevent the mess some
>>other software does.
>
>
> Yes, outgoing firewall protection is not a cure all, but is a helpful extra
> layer of protection. Layered protection is wise. I provide other helpful
> (certainly the "paranoids" among us would like even more) recommedations at
> http://www.mccune.cc/WindowsXP.htm

Well all commercial firewalls with that outgoing functions are very
complex, not easy to configure, have bugs, vulnerablilties and exploits
itself, with little added value that is not really necessary and can be
circumvented. What is the "extra layer of protection" to the "extra
layer of insecurity"? (That's one of the important lessons learned in
security service design and security evaluations: simple effective
measures are always better than highly complex stuff that nobody really
understands and that only add more problems...)

Gerald



Relevant Pages

  • Re: Is XP Firewall Sufficient?
    ... As you've indicated by your post, it (or any other software firewall) is only ... The first layer is a NAT router. ... AntiVirus protection. ... using Spybot S&D and HijackThis are here: ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Network Security Help Please
    ... I already have a fairly hardened system using Tiny Firewall Pro 6.0 on the ... > layer is necessary because no layer produces complete protection. ... Don't install software based ...
    (comp.security.firewalls)
  • Re: question about hardware firewall
    ... basic protection. ... protection - just as the outermost layer of protection. ... The first layer is your NAT router (hardware firewall). ...
    (comp.security.firewalls)
  • Re: Linksys router and Norton Internet Security
    ... I've been running Norton Internet Security ... >on the PCs for firewall and antivirus protection. ... >having Norton Internet Security (firewall component) on the PCs ... A NAT router is a good outer layer of defense. ...
    (comp.security.firewalls)
  • Presentation: Bypassing client application protection techniques with notepad
    ... Bypassing client application protection techniques ... Kerio Personal Firewall 4.0 ... Last years were revolutionary for network services infrastructure ...
    (NT-Bugtraq)