Re: Outpost firewall prob when shutting down PC (XP SP2)



Leythos <void@xxxxxxxxxxx> wrote:
In article <4nlbsvFakbroU1@xxxxxxxxxxxxxx>, usenet-2006@xxxxxxxxxxxxxxxx
says...
Leythos <void@xxxxxxxxxxx> wrote:
No, the entire point was, on a default installation, is there
anything that protects a user better than the Windows Firewall.

Of course there is. Not using an account with admin privileges for
day-to-day work for instance.

I understand that, but, unless you've been asleep for the last 10
years, most every home user running Windows is running as a local
admin, not to mention all the small businesses that are also running
as either a domain admin or a local admin on a workstation.

Which is exactly what needs to be changed.

You won't get users to change their settings, to change that they
use an Administrator account, etc... At least not for most of them.
So, it stands, can ZoneAlarm and other products protect a user more
than Windows Firewall can?

No.

Besides, if you can get them to install %SOFTWARE%, why do you
believe you couldn't get them to use restricted accounts?

Because they will have problems running applications as limited users
- QuickBooks, POGO games, some reporting tools, many online FPS
games...

You DID notice the boatloads of people popping up here and elsewhere
having problems caused by running personal firewalls, didn't you?

The simple fact is that as long as Microsoft installs with users as
admins, with the inability to run common apps unless an administrator
level account, etc... users are going to be exposed to all sorts of
threats.

Most applications can be run as normal user nowadays. Most applications
that can't can be configured to run as normal user by minor changes to
file or registry ACLs. All you need to do is create a freakin' normal
user-account.

Windows Firewall COULD have been a proper firewall, blocking
in/outbound PORTS, ignoring applications, and providing a real-time
interface to show traffic, but, as it is, it fails to protect user at
anything other than a very basic level, and is less protection than
most of the major PFW solutions on the market.

*sigh*

One more time: as long as an application is run by an admin user there
is NO way ANY software (not the Windows Firewall and not any personal
firewall) could enforce control over that application.

cu
59cobalt
--
"If you think technology can solve your security problems, then you
don't understand the problems and you don't understand the technology."
--Bruce Schneier
.



Relevant Pages

  • Re: cant get to admin account from fast user switching
    ... Have you tried tapping CTRL-ALT-DEL twice to bring up the log-in screen? ... To get more information and resources about how to help protect ... > Normally the admin acount does not display on the Welcome Screen. ... At this point the admin account will show up on the ...
    (microsoft.public.windowsxp.general)
  • XP Pro logons changed after recent Windows Update
    ... DSL with Windows Firewall, Windows Defender and up to date AVG ... admin), and my wife, along with the ... I came down and tried to log into my account - and my ... Part of me thinks this was an automatic reboot that didn't ...
    (microsoft.public.windowsxp.general)
  • Re: Outpost firewall prob when shutting down PC (XP SP2)
    ... anything that protects a user better than the Windows Firewall. ... Not using an account with admin privileges ... There is no way to protect a machine from its admin other than not ...
    (comp.security.firewalls)
  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)