Messages - Tuxman [ switch to compact view ]

Pages: prev1 ... 441 442 443 444 445 [446] 447 448 449 450 451 ... 489next
2226
General Software Discussion / Re: Stop Windows from calling home
« on: January 04, 2010, 08:55 PM »
You're the one who flat-out claimed that packet filters aren't firewalls
Packet filters and "real" (hardware) firewalls work on the network layer, "software firewalls" mainly on the application layer. (With a driver-thingy on another layer, probably, but then we'll have a packet filter again.)

and that Windows' built-in firewall is useless
... and potentially dangerous.

2) why would't I run an important server on a Windows box?
Because Windows is not known for stability and security, both of them are the most important attributes of servers IMO.
(Oh, and Windows' cmd.exe without [at least] some *ix tools is, at best, a sick joke when it is about configuration and server maintenance. This refers explicitly to this special case. In other threads I'll stick with my opinion that cmd.exe is everything I need. Maybe because I don't have to control a server system with it. But we're drifting a bit OT here, aren't we?)

Ever checked this list?
Uptime depends on various things. That Windows servers are on top of the list doesn't necessarily mean something. (edit: Missed a dot.)

My personal fileserver (which can hardly be thought of as a critical machine) runs linux - simply because it's free. Free as in beer.
Now that's not actually a reason. If it was, no-one would use Windows anymore, as it is not free.  :D

2227
General Software Discussion / Re: Stop Windows from calling home
« on: January 04, 2010, 07:46 PM »
Fortunately, I'm not a stupid user that clicks yes to everything, and locations that are sensibly set up will have non-trusted users run as exactly that: non-trusted users without admin privs.
So, at least, we're talking on a similar level. Quite a progress yet.

Btw, as for automatic updates: standard users should keep that on. But, while it hasn't happened very often, once in a blue moon and on a subset of configurations, updates have caused trouble.
I know about that, but I wouldn't count this as a reason to disable AU for standard users. We're not talking about important servers right now (which should never run Windows anyway), right?

2228
General Software Discussion / Re: Stop Windows from calling home
« on: January 04, 2010, 07:27 PM »
one should think that a software firewall (if primarily focusing on packet filtering) isn't that hard a job to get right.
Given that we only talk about a packet filter and nothing more: You'll need some kind of an A.I. to decide which traffic is "good" and which is "bad". A packet filter completely controlled by its users does not do what it is intended to.

2229
General Software Discussion / Re: Stop Windows from calling home
« on: January 04, 2010, 06:56 PM »
Show me an exploit for the built-in Windows PF? Not saying it doesn't exist, I just haven't seen it.
There is one for the XP firewall, and I doubt there are none for newer versions ...

with proper software design, there's no reason that a 3rd-party software firewall can't be as secure as Windows' built-in...
If we assumed proper software design, there were no holes in Windows at all, right?

2230
General Software Discussion / Re: Stop Windows from calling home
« on: January 04, 2010, 06:46 PM »
If you've ever tried bringing an XP box pre-SP2 on the internet without 3rd party PF or a NAT'ing router, you'll see how fast this happens with internet traffic.
Like that Sasser worm? I know it, yep ...  :-\
A well-configured machine is daily patched and does not run any services which just are not needed. Of course, there are always some (rare) exploits for needed services. But there are also exploits for common "firewall software", and I think there are more of them. So, actually, a LAN/WLAN system running a "personal firewall" and the default services is more probably vulnerable than a LAN/WLAN system running only the default services.

Pages: prev1 ... 441 442 443 444 445 [446] 447 448 449 450 451 ... 489next
Go to full version