Re: Vista FW outbound check



"Riccardo" <riccardo@xxxxxxxxx> wrote in message news:46a30c83$0$37200$4fafbaef@xxxxxxxxxxxxxxxxxxxxxx

"Kayman" <kayhkay~nospam~@gmail.com> wrote in message news:f7ebo4$nci$1@xxxxxxxxxxx

Learn how to configure Vista Firewall to suit your computing habits.

Interesting/educational reading:
http://www.microsoft.com/technet/technetmag/issues/2006/05/SecurityMyths/default.aspx
Scroll down to:
"Myth: Host-Based Firewalls Must Filter Outbound Traffic to be Safe."

http://www.microsoft.com/technet/technetmag/issues/2007/06/VistaFirewall/default.aspx
"Outbound protection is security theater-it's a gimmick..."
"...the Windows firewall will provide the protection you need..."

Stay away from 'Phoney-Baloney' 3rd party PFW's - use your brain and filter
out the absurd advertisement hype created by these makers.
http://samspade.org/d/firewalls.html
"Personal Firewalls" are mostly snake-oil"

Thanks a lot to you all for the useful suggestions.
You're welcome.

I read the Microsoft opinion on the subject and I disagree.
This is your prerogative. What are your technical reason arriving to your conclusion?

I still would appreciate an optional display notification on outgoing packets, not just for Worm/Trojans etc but also to be able to know what happen to my computer when I run a program.
Sure, it gives that 'comfortable' feeling :)

On my old XP box I used kerio FW and it was very instructive to see (and block) many unsolicited outgoing connections that legitimate programs make (not just to check for new version) but may be to stole my personal data or habits or who knows.

So you think, (remember the illusion bit?) :)

I still hope Microsoft will include this option on SPx

Won't happen (please do some more research on this).

Below are a couple of additional write-ups which you may also find interesting and educational.
BTW - I have yet to see reports challenging these views from the makers of PFW's (aka Phoney-Baloney Ware) :).

Please take some time to read this article by Bruce Schneier about why bad
security products tend to beat the good ones in the market place:

http://www.wired.com/politics/security/commentary/securitymatters/2007/04/securitymatters_0419

Some interesting extracts:

"Why are there so many bad security products out
there? Why do mediocre security products beat the good ones in the
marketplace?"

"In a market where the seller has more information about the product
than the buyer, bad products can drive the good ones out of the
market."

"In the late 1980s, there were more than a hundred competing firewall
products. The few that "won" weren't the most secure firewalls - they
were the ones that were easy to set up, easy to use, and didn't annoy
users too much. Because buyers couldn't base their buying decision on
the relative security merits, they based them on these other
criteria."
--
And an article by Jesper Johansson:

"There are several serious flaws in the reasoning that outbound,
host-based firewalls will actually stop attacks."

"Since there is no application isolation between applications running
within the same user context there is no real way to prevent this from
happening. Only by completely re-architecting Windows could this be
prevented, and even then, it would only truly work if everything we
know about computers, from the hardware on up, changed fundamentally."

http://msinfluentials.com/blogs/jesper/archive/2007/07/19/at-least-this-snake-oil-is-free.aspx

Happy reading:)




.



Relevant Pages

  • [REVS] Bypassing Client Application Protection Techniques
    ... Get your security news from a reliable source. ... protection programs. ... * Kerio Personal Firewall 4.0 ... And we got actually nothing in the field of client application ...
    (Securiteam)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Why hasnt Symantec addressed nastier Messenger spoofs
    ... Norton / Symantec has been silent on whether Norton Internet Security ... DSL firewall will stop these kinds of pop-ups. ... major ISPs and broadband systems. ...
    (comp.security.misc)
  • Re:RE : suggestions on a good firewall
    ... Subject: RE: suggestions on a good firewall ... CheckPoint does! ... with a url-filtering server. ... IT Technical Security Officer ...
    (Security-Basics)
  • Re: What is the Pattern here ?
    ... These are all Dialup Connections that I had no connection with at the time. ... It's obviously an enormous security hole, ... > and a real firewall box. ...
    (comp.security.firewalls)