RE: RE: Linux vs Windows Firewalls

"Jones, Gregory James" <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
Subject: RE: [Annoyances] Linux vs Windows Firewalls
Date: Thu, 11 Sep 2003 09:00:08 -0400
From: "Ridgeway, Alan" <[email protected]>
To: <[email protected]>
Reply-To: [email protected]

>> Yes it does, what you said was that having a firewall that allowed filtering
>>based on programs made the system (windows in this case) inherently super ubber
>>duper more secure than linux.

Windows doesn't natively have a firewall based on programs.  It will block incoming ports _only_ if it is turned on (we're talking about XP) which it isn't by default.

You can add a program level firewall to Windows (several actually), but they don't come with Windows and not many people know about them.

> > If you read news papers or news sites, you will find out which OS has
>> the worst leaks.

Most sources will, correctly, report that Linux, BSD (especially BSD), and Mac OS X are more secure (in most of their forms) out of the box.  That just means through default installation.  Almost any OS can be made secure by either configuring it correctly or (and?) by adding third party add-ons.

>>You are assuming all Windows machines run Windows firewall. That is not the case.
>>The newspapers are NOT documenting Windows Firewalls failing, they are documenting
>>RPC buffer overflows. They are documenting SMB failures. They are NOT documenting
>>Windows Firewall

You are absolutely correct.  Windows machines don't run Windows firewall by default.  It is easy to turn on, but most people don't even know that it is there.  Also it ONLY blocks incoming connections.  A Windows system with the firewall enabled still could be compromised by a trojan (delivered via email or disc) and used as a lauching pad for attacking or infecting other machines.

>>Now, blocking on programs I think is ubber stupid and unnecessari.

I disagree here... with a caveat.  If you think about blocking "programs" as instituting a firewall that doesn't allow unauthorized programs to access the network.  This can help decrease the spread of virus programs/worms.  The third party "personal firewall" zonealarm for windows can block worms from opening additional ports and lauching attacks.  Or more generally a firewall configured at the corporate gateway that blocks egressing ports used by known worms/trojans can protect the general Internet from localized infections.

>I agree. But I don't agree with the line of thinking that anything in Windows
>can be discredited because an unreleated part of the OS failed. It's like saying
>Denial of Service attacks are normally caused by guys who run Linux, therefor
>all of Linux will cause Denial of Service attacks at will. It's not logical.
>It does not give credability to Linux to illogically bash Microsoft. If you want
>to bash Microsoft, do on stuff they deserve to be bashed on (and I agreee there is
>plenty to bash them on.)

Microsoft should allow the firewall to block egress ports as well.  This can be done with IPtables and IPchains, I believe which come natively in most distributions.  So.  Microsoft could be faulted with not including a robust solution.  

There could also be made a case for the fact that modern networked OSes should include a firewall or other form of port blocking.  Given the nature of the net, this is becoming a mandatory OS feature.


>>So now, drop this subject for heavens sake!

>I'm sorry, but you are not the moderiator of this list.
>You don't get the last say just because you want to.
>I invite others to voice there thoughts because that is the way
>we learn. I you can't handle the subject, then write a filter
>for this suject line and delete it from your e-mail before you even see it.

>Alan

Jim

*All views and opinions are my own and do not represent those of anyone or any other institution.  No one else would want them.*
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.