Friday, August 25th 2006

Personal firewalls cause more problems then they solve.

Recent testing by Munich-based PC Professionell is showing results that are not boding well for personal firewall manufacterers. The personal firewalls the magazine tested, from shady freeware to heavily advertised professional editions, could not block all attempts for programs to gain outbound access to the internet. Several firewalls were even turned off by the programs accessing the internet. These firewalls are simply not comparable to corporate firewalls. Corporations have the resources to buy entire computers dedicated to defending a network. The magazine also found much more effective ways to protect yourself online.
  • Browsers are the most vulnerable part of the computer, and Javascript is the most vulnerable part of the browser. Be sure you know who's installing what into your browser.
  • Use common sense when browsing. According to the German Federal Agency for Security in Information Technology, "Desktop firewalls, as they are also called, are practically extraneous, presuming that you adhere to the basic rules of safe surfing,"
  • Keep your applications up to date. Malware takes advantage of the published flaws in a program, so patches for those flaws can keep your computer safe.
  • Buy a hardware router. They take the roll of a firewall, and render software that plays the role of a firewall useless.
  • Don't open E-mail attachments from people you don't know.
Source: Mail&Guardian
Add your own comment

22 Comments on Personal firewalls cause more problems then they solve.

#1
Alec§taar
Somebody's a "/." fan... lol!

:)

* Am I right, or am I right...??

APK

P.S.=> All that stuff? I've been saying it since 1997, in my "APK Windows Security & Speed pages" cited here in our System Optimization thread, & originating here:

www.avatar.demon.nl/page/index.html

ESPECIALLY THE JAVA/JAVASCRIPT PART!!!

(& I used to get called "STUPID" for it... all the way back from 1996 onwards)

Yet now? It's ALL coming true (hell, always WAS, but others didn't see it far ahead enough possibly, & certainly NOT the group I refer to later ->)... Guess I wasn't so "STUPID" (this is directed to arstechnicans everywhere, lol) after all, others are noting now too... apk
Posted on Reply
#2
oldschool
In my experience the biggest threat isn't that Personal Firewalls may be inferior to enterprise industrial strength protection, the biggest threat is e-mail. Virtually ALL hard or soft firewalls are defenseless against most e-mail threats unless you stop ALL e-mail from passing thru. My concern is the crap that comes via e-mail even if it's screened because most anti-scum screening is for known viral garbage. As a reference point there are hundreds of new viral threats released PER WEEK, that any reputable anti-virus company can confirm. It only takes one... If you look at the SCUMWARE that gets into your e-mail box every week then you'll understand you have just about zero protection even with the best of hardware and software devices.
Posted on Reply
#3
zekrahminator
McLovin
You're right about slashdot :). And yes, most of those tips are common sense :laugh:. I betcha all the people who called you stupid buy $50 a month subscriptions to Norton because the guy at best buy told them to :p.
Posted on Reply
#4
KennyT772
sad thing is i know 7 of those people..
Posted on Reply
#5
stealthfighter
I don't use any protection. Drains rescouces. But then again I only go to like 4 websites.
Posted on Reply
#6
Alec§taar
zekrahminatorYou're right about slashdot :).
Thought so, so am I (@ times, I don't post there anymore though - don't like the format & sometimes? Those dudes get WAY outta control, lol!)
zekrahminatorAnd yes, most of those tips are common sense :laugh:
MOST of them are, imo also... but, not everyone possesses that, or has "hidden agendas" for SOME things that increase performance, NOT to be commonly known!

Best example of this?

CUSTOM HOSTS FILES USAGE (for both locally stored URL to IP address speedups, AND for adbanner blocking (BOTH SPEED YOU UP QUITE A LOT)).

Customized ones... YOU DO speed up via those!

I.E./E.G.-> You can resolve URL addresses FAR FASTER than w/ DNS resolutions, but sometimes, the sites change IP or scopes, etc. & you have to edit (no biggie, not for the speed increase & that does NOT happen everyday).

BUT, website owners, w/ adbanners?

They HATE if you block those, rightfully so: It's their income...

HOWEVER, I pay for my linetime, I want the FASTEST there is & banners cut INTO that pretty large (depending on the banner & its server) & they also have been shown MANY TIMES the past few years to harbor (gee, here it is again):

JAVASCRIPT THAT IS MALICIOUS!
zekrahminatorI betcha all the people who called you stupid buy $50 a month subscriptions to Norton because the guy at best buy told them to :p.
No, they're just "the great arstechnica" lol...

(Sarcasm - or, is it? I have had it out with them FAR too many times, so... it may not be, but I am NOT the one who goes looking for it, everytime, they have... & I just pound them into the dirt, easily! It's fun...)

:)

APK

P.S.=> Javascript &/or JAVA get a bad rep worldwide, for security reasons? You can BET every java/javascript coder (myself included on the latter)? Will NOT exactly "be in love with you" for putting up proofs the tool they use is NOT totally safe/secure... apk
Posted on Reply
#7
zekrahminator
McLovin
I'm not exactly a slashdot poster, I'm more like a reader...they post good news. As for the banner ad thing, Adblock and Filterset G takes care of all the banner ads :). There are a couple pop ups I can't stop, but they are usually blank or not on TPU lol. And I'm not saying that Java sucks, I'm saying that the source I have says its got some security loops that are easily exploited lol. Not the programs itself, just the language...sorrry if I offended you (or your friends).
Posted on Reply
#8
Alec§taar
zekrahminatorAs for the banner ad thing, Adblock and Filterset G takes care of all the banner ads :).
Hmmm, correct me IF I am wrong, but... a browser NOT SHOWING YOU AN AD, is not the same as blocking it @ the HOSTS FILE level.

You STILL give them a "hit" whether you know it, or not... webmasters, assuming I can trust you here (because this IS your income)?

Is this NOT the case??

HINT/WARNING: LOADED QUESTION!
zekrahminatorAnd I'm not saying that Java sucks, I'm saying that the source I have says its got some security loops that are easily exploited lol. Not the programs itself, just the language...sorrry if I offended you (or your friends).
Naw, I don't get offended on tech stuff (USUALLY, unless attacked on it & this has happened to me before & I rarely lose - not being an arrogant a-hole here, just stating it how it is)

I am here to learn (or, teach)... in general, just to grow stronger! When & IF I am in error on technicals? It's OK by me... they stick by me the longest/strongest.

APK

P.S.=> The question above: Here is one I have always wondered about (or, have I, & is it just a test)? We'll see... lol! apk
Posted on Reply
#9
zekrahminator
McLovin
I know nothing about W1zzards advertising payments. I just know that I get a piece of them, and the size of that piece depends on how much news I post :). And you're probably right, I think adblock just hides the ads.
Posted on Reply
#10
Alec§taar
zekrahminatorI just know that I get a piece of them, and the size of that piece depends on how much news I post :). And you're probably right, I think adblock just hides the ads.
BINGO!

BUT, still:

Let's see a webmaster's take on it!

:)

(... hopefully, one will show up & refute me...)

APK

P.S.=> I would like W1zz's view, MAINLY because he is a coder, CAN DO THE JOB & on many levels evidenced by his work, unlike many others out there that host sites... this, I can actually RESPECT! apk
Posted on Reply
#11
infrared
LOL, you talk in posts just like 'V' :D ur Avarta is perfect for you! I can hear his voice in my head as i read your posts.
Posted on Reply
#12
Alec§taar
infraredLOL, you talk in posts just like 'V' :D ur Avarta is perfect for you! I can hear his voice in my head as i read your posts.
Yes... & that is part of my "master plan" (lol, oh nooo... he's onto me!)

:)

* HEY: How far wrong can you & I go, with Hugo Weaving behind us?

APK

P.S.=> He's an AWESOME talent man... no doubt about it! apk
Posted on Reply
#13
zekrahminator
McLovin
Okay I officially want to see that movie now :).
Posted on Reply
#14
pt
not a suicide-bomber
zekrahminatorOkay I officially want to see that movie now :).
me too :D, gues i'm going to pay a visit to the videoclub soon
Posted on Reply
#15
Alec§taar
You'll love it,

(I nearly GUARANTEE this... )

* & it does make you think & look around you, @ THE WORLD TODAY!

APK
Posted on Reply
#16
Steevo
And besides Natalie Portman in a school girl outfit and a panty shot.
Posted on Reply
#17
CjStaal
zekrahminatorI know nothing about W1zzards advertising payments. I just know that I get a piece of them, and the size of that piece depends on how much news I post :). And you're probably right, I think adblock just hides the ads.
oh shit, you for real? w1zz pays the staff???? that's the shit
+1 w1zz :)
Posted on Reply
#18
pt
not a suicide-bomber
i wan't a staff job too... :p
Posted on Reply
#19
gR3iF
is a NAT Firewall in a Router enough?
Posted on Reply
#20
zekrahminator
McLovin
gR3iFis a NAT Firewall in a Router enough?
If it's in the router, then it's exactly the type of firewall I was saying is something you should have :).
Posted on Reply
#21
Alec§taar
gR3iFis a NAT Firewall in a Router enough?
Supposedly, it's decent, but there are things like "stateful packet inspection" & such that make some routers better.

CISCO units are good ones to look over for features, & now that CISCO has acquired LinkSys? Many of THEIR consumer-grade commodity routers have the things that are above Network Address Translation alone, for better security.

APK

P.S.=> The REAL idea today? Is "layered security", one barrier after another... if you want MORE on that? See the "System Optimization" sticky thread in the software section & I put up a few URL's & techniques in there that will MASSIVELY take you to that level, for about 45 minutes or so TOPS of work on your end... apk
Posted on Reply
#22
gR3iF
i have a cisco router with build in spi and dmz on an exclusive port, but i dont like the cisco setup its done over com port console^^
Posted on Reply
Add your own comment
Apr 29th, 2024 13:48 EDT change timezone

New Forum Posts

Popular Reviews

Controversial News Posts