Re: What's the point of not allowing all outgoing traffic by default?



linuxlover992000@xxxxxxxxx wrote:
I have a small home network comprised of Windows and Linux PCs. I am
not serving anything to the internet. That is, all incoming traffic is
blocked blocked.

On the other hand, up until now, I allow ougtoing on a case (port/
service) by case basis. That is, up until now I add yet another port
range to the list of allowed ports/services whenever I discover
another application that needs it.

As time goes by, I discover now that I accumulated a long list of
"allow" that amounts to *almost* openning all ports... which brings
the obvious question: why make it so complicated and tedious, when I
can simply allow all outbound traffic and be done with all the hassle?

Nowdays when client PCs use so many services that practically require
opening all outgoing ports, it seems that the classic rule of thumb of
"First disallow everything by default, then only allow those needed"
is simply outdated.

Am I missing something?

Yes. Since you're in control of your internal network the reasonable
measure against unwanted outbound traffic is not to block that traffic,
but to eliminate its source.

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich
.



Relevant Pages

  • Re: Why Im Writing My Book - OT in a way
    ... > computer victims using Windows and the Internet. ... > explore, discover, and communicate with the world around me. ... > kid elected to adopt a ferret, I desired to gain as much information on ... I was unaware the hackers were going to use my ...
    (microsoft.public.security)
  • Re: Damn you, FEDEX! or Nikon D40 lost in Springfield, MO blackhole.
    ... the 2 mp Mavica he had been using with a Nikon D40. ... After shopping around, he got me to order one for him. ... The shipper had it insured, but from what I have read it could take weeks to sort this crap out. ... You may get your insurance from FedEx and a couple weeks later they find it and deliver it. ...
    (alt.photography)
  • RE: Lost Internet Access
    ... Subject: Lost Internet Access ... Thanks and I'll let you know what if anything I discover. ... take short cuts in doing an OS Install ... ...
    (Debian-User)
  • Re: Whats the point of not allowing all outgoing traffic by default?
    ... range to the list of allowed ports/services whenever I discover ... opening all outgoing ports, it seems that the classic rule of thumb of ... Yours is a philosophical question. ... We should all be good Internet netizens. ...
    (comp.security.firewalls)
  • Re: Power Cable Challenge
    ... >> Have you seen this which was published in Saturdays Guardian. ... >> I follow a couple of`Forums on the internet. ... They're all *impossible*, as you will discover. ... embarrassment, try it with a friend before entering into the full ...
    (uk.rec.audio)