Re: Linux vs Windows Firewalls

Lawrence MacIntyre <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Organization High Performance Information Infrastructure Group
Message-ID <1063205402.1433.80.camel@nautique>
So if I name my worm svchost.exe, the MS firewall will allow it to use
your interface, but if I foolishly name it myworm.exe, it won't.  That
doesn't buy you much security.  Firewalls must use ports, addresses, and
protocol elements to be effective.  Filenames don't provide any
meaningful security.

Filenames are simpler for users to understand, but unfortunately for
them, not really effective means of protecting their machines.  You are
much safer with the RedHat Linux default installation, which basically
allows anything outgoing and nothing incoming except for DNS and
responses to connections initiated by the local machine.

Remember that Linux doesn't have Outlook so the danger of executing
random executables that have been received in email is only as great as
the liklihood that the user will save and execute the file manually. 
Also activeX doesn't work on any Linux browsers, so that mass of
security holes isn't present either.  Assuming that the user doesn't log
in as root, any worm or virus that might be written for Linux can only
infect that user's files.  It can't affect the OS or other users.

On Wed, 2003-09-10 at 10:10, PK Carlisle wrote:
> Care to add some substance regarding HOW I'm wrong?  
> Precisely how, given the limitation in the Linux firewall pointed out, 
> is Linux to be made more secure?  Opening a port to every 
> program that wants to communicate over that port seems sloppy 
> and risky.
> 
> Thus spake annoyances-request-DzJonyRHso41Ayx8vbq1stBPR1lH4CV8@public.gmane.org:
> 
> > Date: Tue, 9 Sep 2003 21:06:01 +0200
> > From: "Daniel C. von Asmuth" <asmuth-8LkvcxCLB6JmR6Xm/[email protected]>
> > To: [email protected]
> > Subject: Re: [Annoyances] Linux vs Windows Firewalls
> > Reply-To: [email protected]
> > 
> > Thus quoth PK Carlisle on Mon, Sep 08, 2003 at 10:29:47PM -0500:
> > 
> > > Am I wrong or can it be that my Windows system is -significantly-
> > > more secure online than Linux??
> > 
> > The former case applies.
> > 
> > Kind regards,
> > 
> > 
> > Daniel von Asmuth
> 
> 
> 
> 
> 
> ------------------------ 
> 
> If god had not created yellow honey, men would think figs sweeter than they do.
> 
> 
> Earthlink, AOL, Yahoo & MSN/Hotmail IM: mrgoodbytesim  ICQ:13418006
> PGP Public Key: http://home.earthlink.net/~mrgoodbytes/pkpubpgp.asc
> VOX: 708-296-2466  FAX: 708-452-8594 
> 
> 
> _______________________________________________
> annoyances mailing list
> [email protected]
> http://michelangelo.renaissoft.com/mailman/listinfo/annoyances
-- 
    Lawrence MacIntyre     865.574.8696     [email protected]
               Oak Ridge National Laboratory
High Performance Information Infrastructure Technology Group
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQA/XzoZCNjP8rawCW4RAgMcAJ4ijEb9UICuHOM0+TvM9qqZ8VfP3QCfUXeN
v8vIaVt2eVfr2H6pothfT4U=
=n7FM
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.