Re: Firewalls (oh no not another post)
Richard.Corfield.Admin-XZoyATsUNX5Wk0Htik3J/[email protected]
| Newsgroups | gmane.linux.usability.annoyances |
|---|---|
| Message-ID | <[email protected]> |
Personal firewalls are an interesting proposition, if all they do is block ports. You could ask, if a port on a standalone machine is to be blocked, then why is it open in the first place? The best way to block a port is to close it. Remove unwanted services! (or on UNIX, ensure that essentials if any are bound to loopback only, quick look at my system, none of my open ports are "essential", my own DNS cache, squid, apache and exim, none of which need to be listening on a home box, X is set no-network by default on Debian) It is a falacy, but once all too common practice, to enable services out of the box. It was thought to be more user friendly if the user didn't have to think a bit to enable file sharing, but instead all files were shared by default. Asking the user to set a password on network resources on install was considered too user unfriendly, so a default was often chosen. Similarly, asking the user to think about configuring mail relay rules - so just leave the box open relay so any nutcase can configure it - its "User Friendly". Fortunately this is being fixed. I wonder if the reason for not turning the firewall on by default may be so that when the user installs some network server (Kazaa perhaps) Microsoft don't get support calls asking why it can't accept connections, something which would make Windows seem user unfriendly. (but on Windows we always assume the presence of a GUI, so we could intercept the listen() call when the server opens up its port). If you can't afford an outboard firewall, I'd use a personal one. I'd like to see operating systems require user effort, almost an "I agree to maintain this server in a secure way" agreement, to enable a network service. Debian seem to do this, and require things like passwords and allowed host lists as part of the install process for the server in question. This may be seen to be "User Unfriendly" with "too many techie questions", but I see it as essential. The net is a dangerous place. You shouldn't be running a server unless you understand how to configure it. - Richard -- _/_/_/ _/_/_/ _/_/_/ Richard dot Corfield at ntlworld dot com _/ _/ _/ _/ Fortune Cookie: Hardware, n.: The parts of a _/_/ _/ _/ computer system that can be kicked. _/ _/ _/_/ _/_/_/