Re: Linux vs Windows Firewalls
Lawrence MacIntyre <[email protected]>
| Newsgroups | gmane.linux.usability.annoyances |
|---|---|
| Organization | High Performance Information Infrastructure Group |
| Message-ID | <1063205402.1433.80.camel@nautique> |
So if I name my worm svchost.exe, the MS firewall will allow it to use your interface, but if I foolishly name it myworm.exe, it won't. That doesn't buy you much security. Firewalls must use ports, addresses, and protocol elements to be effective. Filenames don't provide any meaningful security. Filenames are simpler for users to understand, but unfortunately for them, not really effective means of protecting their machines. You are much safer with the RedHat Linux default installation, which basically allows anything outgoing and nothing incoming except for DNS and responses to connections initiated by the local machine. Remember that Linux doesn't have Outlook so the danger of executing random executables that have been received in email is only as great as the liklihood that the user will save and execute the file manually. Also activeX doesn't work on any Linux browsers, so that mass of security holes isn't present either. Assuming that the user doesn't log in as root, any worm or virus that might be written for Linux can only infect that user's files. It can't affect the OS or other users. On Wed, 2003-09-10 at 10:10, PK Carlisle wrote: > Care to add some substance regarding HOW I'm wrong? > Precisely how, given the limitation in the Linux firewall pointed out, > is Linux to be made more secure? Opening a port to every > program that wants to communicate over that port seems sloppy > and risky. > > Thus spake annoyances-request-DzJonyRHso41Ayx8vbq1stBPR1lH4CV8@public.gmane.org: > > > Date: Tue, 9 Sep 2003 21:06:01 +0200 > > From: "Daniel C. von Asmuth" <asmuth-8LkvcxCLB6JmR6Xm/[email protected]> > > To: [email protected] > > Subject: Re: [Annoyances] Linux vs Windows Firewalls > > Reply-To: [email protected] > > > > Thus quoth PK Carlisle on Mon, Sep 08, 2003 at 10:29:47PM -0500: > > > > > Am I wrong or can it be that my Windows system is -significantly- > > > more secure online than Linux?? > > > > The former case applies. > > > > Kind regards, > > > > > > Daniel von Asmuth > > > > > > ------------------------ > > If god had not created yellow honey, men would think figs sweeter than they do. > > > Earthlink, AOL, Yahoo & MSN/Hotmail IM: mrgoodbytesim ICQ:13418006 > PGP Public Key: http://home.earthlink.net/~mrgoodbytes/pkpubpgp.asc > VOX: 708-296-2466 FAX: 708-452-8594 > > > _______________________________________________ > annoyances mailing list > [email protected] > http://michelangelo.renaissoft.com/mailman/listinfo/annoyances -- Lawrence MacIntyre 865.574.8696 [email protected] Oak Ridge National Laboratory High Performance Information Infrastructure Technology Group
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQA/XzoZCNjP8rawCW4RAgMcAJ4ijEb9UICuHOM0+TvM9qqZ8VfP3QCfUXeN v8vIaVt2eVfr2H6pothfT4U= =n7FM -----END PGP SIGNATURE-----