Re: Firewalls (oh no not another post)

Richard.Corfield.Admin-XZoyATsUNX5Wk0Htik3J/[email protected]
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
Personal firewalls are an interesting proposition, if all they do is
block ports. You could ask, if a port on a standalone machine is to be
blocked, then why is it open in the first place? The best way to block a
port is to close it. Remove unwanted services! (or on UNIX, ensure that
essentials if any are bound to loopback only, quick look at my system,
none of my open ports are "essential", my own DNS cache, squid, apache
and exim, none of which need to be listening on a home box, X is set
no-network by default on Debian)

It is a falacy, but once all too common practice, to enable services out
of the box. It was thought to be more user friendly if the user didn't
have to think a bit to enable file sharing, but instead all files were
shared by default. Asking the user to set a password on network resources
on install was considered too user unfriendly, so a default was often
chosen. Similarly, asking the user to think about configuring mail relay
rules - so just leave the box open relay so any nutcase can configure it -
its "User Friendly". Fortunately this is being fixed.

I wonder if the reason for not turning the firewall on by default may
be so that when the user installs some network server (Kazaa perhaps)
Microsoft don't get support calls asking why it can't accept connections,
something which would make Windows seem user unfriendly. (but on Windows
we always assume the presence of a GUI, so we could intercept the listen()
call when the server opens up its port).

If you can't afford an outboard firewall, I'd use a personal one. I'd
like to see operating systems require user effort, almost an "I agree
to maintain this server in a secure way" agreement, to enable a network
service. Debian seem to do this, and require things like passwords and
allowed host lists as part of the install process for the server in
question. This may be seen to be "User Unfriendly" with "too many techie
questions", but I see it as essential. The net is a dangerous place. You
shouldn't be running a server unless you understand how to configure it.

 - Richard

-- 
   _/_/_/  _/_/_/  _/_/_/ Richard dot Corfield    at    ntlworld dot com
  _/  _/    _/    _/      Fortune Cookie: Hardware, n.:  The parts of a
 _/_/      _/    _/       computer system that can be kicked.
_/  _/  _/_/    _/_/_/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.