Re: too many firewalls?

From: Arthur Hagen (art_at_broomstick.com)
Date: 11/30/04


Date: Tue, 30 Nov 2004 09:51:39 -0500

Wolfgang Kueter <wolfgang@shconnect.de> wrote:
> Arthur Hagen wrote:
>
>> Oh, but it can be useful for other purposes, like blocking
>> semi-naughty programs from calling home every time they're started,
>> or for logging ip activity.
>
> Words like 'semi-naughty' are senseless when we talk about security.

Not really. Programs from large and otherwise trusted vendors who do an
E.T. are better off blocked. This includes vendors like Adaptec, Apple,
Adobe, Veritas and many others. Even though you may trust these companies,
do you really trust everybody at their marketing department?

>> Of course, real malware will have no problems disabling a software
>> firewall, especially not if you run as an administrator (which is
>> what many people do, because so much software won't work otherwise).
>
> Therefore they are of some worth only for the person/company who
> sells them.

You jump to conclusions -- your "therefore" lacks any substantiation at all.

Software firewalls most definitely can be useful, but are not the holy grail
of security, and often are worse than nothing in that they lull users into a
false sense of security. That doesn't mean that they don't have useful
purposes too.

-- 
*Art


Relevant Pages

  • Re: Getting viewstate value from readonly textbox in .NET2 (VB)
    ... My datepicker served two purposes. ... It was to prevent security hacks. ... SubmitDisabledControls property to enable them just before postback. ... the other workarounds that Rick is using for id fields used on ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Getting viewstate value from readonly textbox in .NET2 (VB)
    ... OK...after doing much reading, I just decided to leave the ... My datepicker served two purposes. ... It was to prevent security hacks. ... SubmitDisabledControls property to enable them just before postback. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: OpenSSL Hacks
    ... a security protocol is worrisome and potentially harmful (to ... the purposes of the protocol). ... code problems are a sign that no adequate review (security or ... If you're going to rely on certification, ...
    (sci.crypt)
  • Re: Heirs seeking insurance values
    ... #a living trust and one requirement written into the trust is that they each ... #get a safe to hold them ... You still have to value it as part of the estate for court purposes. ... When I claimed my Dads watch, after he died, I had to have it appraised so the ...
    (rec.guns)
  • Re: Classic Log ON Prompt
    ... > COmputer set to show Classica log on Prompt when starting for security ... > purposes. ... comp starts and shows desktop. ... What is missing. ...
    (microsoft.public.windowsxp.security_admin)