Re: Atguard?



Bogwitch wrote:


Sure you won't, since you'd find that this class is empty.

Really? You're a fool.


Strange enough, no one, including you, could even state an example.

Yes, always. Would also be quite non-plausible how domain-specific software with no alternatives could be ad-ware supported. Doesn't this sound stupid even to you?

You said *FREE* alternatives. Not always.


I proclaim that every software for which no free alternative exists is not ad-ware supported.

Or they're just idiots. Best example so far: Skype.

Once again, anyone not agreeing with you is an idiot?


No. It's simply a fact that ~90 % of all computer users are idiots wrt computers. And those idiots typically install software without seeing any need for it, without any reasonable evaluation of their problem and without considering alternatives.

Or have you written all your own OS and apps?

Hm? Missing the logic in there...

Without authors, no apps. *You* don't care for authors.


Who said that I don't care for authors? I just don't care for specific authors. The authors of ad-ware supported software particularly I don't care for, for the authors of free alternatives I do.

No, I have cited an example of a *group* of software.
Without any (meaningful) definition.

It is clear to all must the most narrow-minded among us.


No. You're yourself confusing the subject. How do you define legitimacy of software? Even though 90% of users think that software is illegitimate if it sends data due to the user being too stupid to configure it correctly, this definition wouldn't be reasonable at all (since the software behaves as documented).

Remotely exploitable?


I didn't claim that this is remotely exploitable. As if locally exploitable wasn't worse enough, there are many other remotely exploitable security vulnerabilities including DoS with SYN, UDP and ICMP flooding or bypassing the filtering with overlapping IP fragments.

I do agree however that the use to which the OP puts AtGuard is legitimate.
Unless you actually think about it.

It is you that needs to considerthe OPs situation, not just the generic best practice as put forward by yourself.


Could it be that your argument makes no sense? The OPs situation is that his software doesn't work as he wants due to misconfiguration. Reasonable solution would be configuring the software correctly or simply replacing the software with alternatives.

Trying to filter at the network stack is a rather stupid approach.

AtGuard is not so broken.
Is that political correctness for "horribly broken"?

No, it's not so broken as to make it insecure for relevant applications.


Hm? Local privilege escalation and trivial bypassing is not exactly irrelevant.

as part of a layered security approach.
Ah, the "layered security" buzzword. Of c'mon, you can do better.

Again, we have had this discussion before. A layered securty approach is not a broken approach.


It is. Introducing superfluos layers to address misunderstood problems doesn't increase security, but just increases complexity. You're twisting it with "defense in depth", which works quite differently.
.



Relevant Pages

  • RE: [fw-wiz] The home user problem returns
    ... idiot clicking attachments can infect 10,000 other idiots a day ... >that institute end-user security training. ... >have no opportunity to hurt themselves. ... It uses Zen4 to render anything you get. ...
    (Firewall-Wizards)
  • RE: [Full-Disclosure] Antigen Path Disclosure
    ... security, you're all just playing with "the morning wood" (err.. ... the pool, I don’t care if he went off a bridge, I DON'T FUCKING CARE, ... something i never actually bothered poking at them or something i never ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
    (Full-Disclosure)
  • [Full-Disclosure] Beyond black, white, and grey: the Yellow Hat Hacker
    ... >>cashing in and making a great show of how much you care about protecting ... >>security is hypocritical, that's all. ... >I have a real fucking problem with idiots who know nothing, ... >This isn't a childish rant. ...
    (Full-Disclosure)
  • Re: Where is the notificiation about IE zero day vulnerablity?
    ... but over 2 hours ago I did say that a break in FF security would ... The problem I have with that is why would Yahoo, CNN or MSNBC care about ...
    (microsoft.public.security)
  • Re: [Full-disclosure] Full Disclosure Advisory on Full-Disclosure hax0r3rz
    ... because they affix the posts constantemente to feed egos can you at least ... to do with security of the computer. ... This issue has become increasingly disturbing as idiots from all over the ... Moderators are asked to do something productive which is ...
    (Full-Disclosure)