Re: What's the point of not allowing all outgoing traffic by default?



Keme wrote:


Of course! Expect everyone to be perfect, knowledgeable and in control at all times, and consider OS security bugs/flaws nonexistent.


Seems like you're ignoring the enormous amount of insecurity introduced by the pseudo security software itself.

> That simplifies everything,

That's exactly the point. The biggest fiend of security is complexity, that's why adding more complex code is very unlikely to be any good solution. Especially when it's totally unreliable and trivially circumvented.

Irony aside, albeit filtering is not a panacea it is a useful supplement to other measures, like avoiding admin privileges on user accounts, safe conduct on the internet, installing security updates, etc., etc.

>

Filtering outbound traffic is not the ultimate solution, but an advisable measure.


Expect that it's largely impractical and only creates more problems without any real benefit.
.



Relevant Pages

  • Re: Inspecting Code for Security
    ... > inspections were not targeted at security, ... > logic errors, over complex code, missing comments, etc. ... > With security in mind what things other things should I be looking ...
    (SecProg)
  • Re: security of OpenBSD vs Linux distros
    ... >>> security, so I don't see much of the point since SSH can be ... This complex code is more secure in the userland? ... > almost as bad as an exploit in the kernel. ... OpenBSD community. ...
    (comp.os.linux.security)
  • Re: security of OpenBSD vs Linux distros
    ... >> security, so I don't see much of the point since SSH can be ... This complex code is more secure in the userland? ... almost as bad as an exploit in the kernel. ... OpenSSL, but this is on my Linux system, I don't currently ...
    (comp.os.linux.security)