Reviewers Recommend
Lesbians LessonsLesbians Lessons - review by Danielmayu33216
Starring: Rachael Cavalli, Isa Bella. Read review
All Forums > Tech Talk > Tech Talk Forum Page 59 > destructive worm
AuthorPost
daviangel
Member

Only time I would buy a girl flowers is if she was in the hospital
455 Posts
1/04
Posted - Mar 21 2004 : 4:37AM
Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Mar 22 2004 : 4:41AM
Fortunately, I paid attention to Steve Gibson and didn't get Black Ice when I was looking at firewalls.
daviangel
Member

Only time I would buy a girl flowers is if she was in the hospital
455 Posts
1/04
Posted - Mar 22 2004 : 5:54AM
Yeah I remember when windows xp came out he created quite a controversy talking about how insecure it was and pissed off enough people to get his website taken down via DDOS.
I never had a problem with him and actually use his shields up all the time.
Personally I use zonealarm the best free firewall software bar none.


Edited by - daviangel on 3/22/2004 5:55:18 AM

GaySatyr
Senior Member

Half dirty ol' man; half horny ol' goat!
1684 Posts
10/00
Posted - Mar 22 2004 : 1:22PM
Zone Alarm is an excellent choice for a software-based firewall; however, anyone with a broadband connection ought to have a true, hardware-based firewall similar to the one built into the USR-8000A router. ~ GS
Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Mar 22 2004 : 6:45PM
Huh? I think I know what you're saying but that 'true' bit is confusing me. If you mean that having a separate piece of hardware running your firewall prevents the possibility of oh, say the dialer program you unknowingly downloaded for www.XXXILikeToFuck.com disabling your firewall then I agree. Otherwise, "hardware-based" firewalls are no different from PC-based firewalls.
 
GaySatyr
Senior Member

Half dirty ol' man; half horny ol' goat!
1684 Posts
10/00
Posted - Mar 22 2004 : 7:11PM
My point is that with a "box" like the USR-8000A and its NAT and ping absorption features as well as its ability to lock out a variety of other access holes, I get easy access to the internet whereas from an outside perspective, I don't even exist. There is nothing to target if I can't be found. When I post somewhere that an IP address is tracked, it is the IP address assigned to my DSL modem, not the one used by my computer. If you "ping" me, you get no response. I'm a dead end, and, thus, uninteresting to outside hackers.

With a software-based firewall running on my computer, I lose a physical layer of protection (including NAT and ping absorption) plus I am subject to a variety of potential bugs and holes in the firewall software itself as well as attacks on the firewall software from the outside in addition to threats I might have unwittingly downloaded and installed on my own machine in the form of dialers, viruses and worms.

The hardware box, while not a 100% guarantee that nothing will ever happen, is significantly more secure than a software firewall application and, at about US$65, it is cheap insurance for a broadband internet access user.

~ GaySatyr

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Mar 22 2004 : 7:47PM
Let's get our terminology straightened out first. A "hardware-based" firewall is a firewall program that runs on a dedicated device. That is, it does not share CPU registers, memory or other components with any other program. Agreed?

Now, even though it has the hardware all to itself (hopefully), it is still a program and thus subject to error just like every other program written by man. Therefore, singling out PC-based firewalls (what you call software-based firewalls) as potentially buggy is inappropriate. What can be suggested is that, given that a PC-based program has to protect itself against internal as well as external attacks, the hardware-based program should have fewer weaknesses. However, ultimately, we're at the mercy of the programmers in either case.

Putting on my network engineer hat, the NAT feature is definitely a plus, but that's an additional feature; if memory serves, firewalling isn't even discussed in the RFC. As for PING absorption, I can do that with any decent PC-based firewall. Also, I assume you're not talking the ISO model when you mention the physical layer, because I'm clueless about what NAT and PING have to do with hardware and signal propagation.

Note - this isn't to put anybody off of GS's suggestion. Getting a "hardware-based" firewall is definitely an excellent choice, it's just that he's in my bailiwick now and I get kind of exacting when that happens.

GaySatyr
Senior Member

Half dirty ol' man; half horny ol' goat!
1684 Posts
10/00
Posted - Mar 22 2004 : 8:04PM
LOL - I defer to your terminology, Hardware, and to your expertise. Regardless, my "box" is significantly safer than Zone Alarm. ~ GS
daviangel
Member

Only time I would buy a girl flowers is if she was in the hospital
455 Posts
1/04
Posted - Mar 26 2004 : 12:54AM
firewalls do not eliminate the need for Intrusion Detection Systems
p.s.
I think we can all agree that firewalls are only a part of the solution to security.
And as far as what hardware said about software vs hardware. A good analogy would be modern day video cards. I got a geoforcefx that can do T&L lighting in hardware and all kinds of other cool graphics stuff and it can do them really fast. That is not to say that an old ati card that doesn't have hardware T&L,etc cannot do T&L the same things and run the same games. It can but it does them really slow since it's doing it using software(your computer's cpu) without depending on a piece of hardware dedicated soley to T&L like my geoforcefx card has.
GaySatyr
Senior Member

Half dirty ol' man; half horny ol' goat!
1684 Posts
10/00
Posted - Mar 26 2004 : 1:24AM
I agree that a good firewall is not enough. in my apartment, I have the following:
  • a DSL modem connected to the wall phone jack

  • a USR-8000A firewall/4-port router connected to the DSL modem

  • a computer running XP/Pro

  • a computer running XP/Pro

  • one free port

  • a 3Com 10/100 5-port mini-hub connected to the USR-8000A

  • a computer running Win2K/Pro

  • a computer running Win98SE

  • a computer running DOS6.2 & Win3.11

  • a computer running Red Hat linux

  • one free port
The computers are running versions of NAV, Black Ice Defender, Ad-Aware, & SpyBot S&D as appropraite for their OS versions. I don't use OutLook for email. I usually use the Mozilla browser (Netscape 4.7 on the oldest two machines). My primary wordprocessor is WordPerfect -- not MS Word. I keep all OS files, applications and utilities up to date.

I'm not 100% safe, but I'm probably 99 & 44/100ths safe.

~ GaySatyr

Hardware All-Star Supporter
All-Star Member

Your other left
14594 Posts
3/02
Posted - Mar 26 2004 : 3:57AM
If I understand you correctly, you are saying that a firewall program running on dedicated hardware runs faster than a PC-based one does. I can think of examples where that's true, but it isn't a factor in most homes. Bear in mind that your average home network connection is moving packets at a rate that is relatively low compared to the capabilities of your system bus and CPU. Thus, the firewall doesn't have much work to do in the first place.

Firewalls are relatively simple programs (I'm not going to address the complexities that can arise in a business setting) that require no mathematical computations. They should deny by default, which means that a short, straight-forward decision tree is all that is required - if packet A matches the approved list of allowed ports then it comes in, otherwise it is dropped. That's it.

This means that a firewall program should have little measurable impact on performance. The issue for the average PC user isn't going to be performance but rather the safety of the platform the firewall is running on. If the PC is compromised through some other vector then the firewall may be rendered useless.

PS - I also agree that a firewall doesn't provide complete protection.

PPS - "It can but it does them really slow since it's doing it using software(your computer's cpu) without depending on a piece of hardware dedicated soley to T&L like my geoforcefx card has."

You dropped an "and" there - "using software AND your computer's CPU." To be clear, the old graphics cards didn't support T&L because different software companies used different instructions to do the necessary computations. This meant that the work had to be done by the main CPU. The problems there were
a) the main CPU wasn't designed specifically to do graphics computations (which are mathematically complex), and
b) the main CPU had other tasks to do as well.
Therefore, the software industry continued to extend the common instruction set for graphics. Once the industry adopted a common instruction set for T&L, it could be rendered in hardware by the graphics card manufacturers.

Now, aren't you glad we had this chat? lol

daviangel
Member

Only time I would buy a girl flowers is if she was in the hospital
455 Posts
1/04
Posted - Mar 26 2004 : 9:53PM
Ok I guess I didn't get my point across. which was without software your computer or any piece of hardware is just a pile of junk. Same thing with a router,microwave,etc capice.



Jump To: