Linked by Thom Holwerda on Sun 18th Feb 2007 20:29 UTC, submitted by Jennifer Logan
Windows "What is it with the Windows Vista Firewall and its refusal to go away? All our PCs are secured behind two firewalls: a hardware firewall and Microsoft ISA Server. The only traffic that gets in is the traffic that we want to get in. Now we can appreciate having the firewall on by default; but after turning it off over 20 times, it's getting to be too much."
Thread beginning with comment 214340
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[3]: Not Necessary!?
by jessta on Mon 19th Feb 2007 11:51 UTC in reply to "RE[2]: Not Necessary!?"
jessta
Member since:
2005-08-17

A Trojan masked by a rootkit that can't disable/bypass your software firewall? I think not.

So your argument is that a software firewall can prevent unauthorised outgoing connections?

I'll give you that preventing unauthorised outgoing connections is a useful thing. But you first have to control everything about what a program is allowed to do otherwise a malicious program can just use another program, that is authorised to make connections, to make the connections it needs.

A firewall is not a replacement for security,
This is very true and is my biggest issue with software firewalls and anti-virus. They add very little in terms of security while costing money, eating computing resources and giving the user a false sense of security.

There is a huge industry built around selling users 'security' software by marketing through fear and aren't solving the problem in the right place.

Reply Parent Bookmark Score: 1

RE[4]: Not Necessary!?
by bryhhh on Mon 19th Feb 2007 13:34 in reply to "RE[3]: Not Necessary!?"
bryhhh Member since:
2005-07-22

A Trojan masked by a rootkit that can't disable/bypass your software firewall? I think not.

Quite right, hence the reason why I said "a firewall might just save the day.", (Emphasis added).

So your argument is that a software firewall can prevent unauthorised outgoing connections? [/i]

No, my arguement is that whilst a firewall should not be used as the basis of a security implementation, it does compliment properly securing or disabling services. Firewalls (hardware and software) are not infallable, but they should not be overlooked.

There is a huge industry built around selling users 'security' software by marketing through fear and aren't solving the problem in the right place.

Very true, and I'm aware of far too many people that buy into this false sense of security.

Edited 2007-02-19 13:35

Reply Parent Bookmark Score: 1