republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Bi-Directional Firewalls » Both Ways.
Search Topic:
Uniqs:
39
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
Honestly.... »
« Overkill for most  
AuthorAll Replies


ahulett
Life Without Walls
Premium
join:2003-02-02
Bellevue, WA

Both Ways.

Saying an inbound-only firewall is sufficient is like saying a customs check is only needed for those entering a country, and those leaving it are free to enter neighboring countries unchecked. An inbound firewall is ineffective against viruses/trojans/malware on CDs, floppies and USB memory devices, and items slipping by email defenses.

You need security checks both ways.
--
Aaron Hulett | Trojan Analyst | Mischel Internet Security

dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

said by ahulett See Profile:
Saying an inbound-only firewall is sufficient is like saying a customs check is only needed for those entering a country, and those leaving it are free to enter neighboring countries unchecked.
And that's how customs works for the majority of travellers.

Fly from USA to UK? You're inspected by UK customs. USA customs doesn't look at you.

Return from UK to USA? You're inspected by USA customs. UK customs doesn't look at you.


blackjeep

join:2001-07-12
Atlanta, GA

reply to ahulett
Have you ever been thru a customs check? Try going across the border into mexico. You can drive right across or walk across with virtually not even a glance from the mexicali police. But try just driving back from Mexico, or carrying a bag walking across the border and see what happens. They are going to stop you, and search you, and if they find ANYTHING suspicious, they'll strip search your car for contraband. Unidirectional border.


ahulett
Life Without Walls
Premium
join:2003-02-02
Bellevue, WA

reply to dave
I was using the customs checkpoint as a whole as the comparison to firewalls.

You may not get "thoroughly checked" by a customs agent, but your passport's still processed, right?
--
Aaron Hulett | Trojan Analyst | Mischel Internet Security


ahulett
Life Without Walls
Premium
join:2003-02-02
Bellevue, WA

reply to blackjeep
"Have you ever been thru a customs check?" My passport says I have. That's fun, getting your bag's contents spread across a table in front of everyone. At least I haven't had that happen to me, yet. But I've seen it happen to people I know.

"You can drive right across or walk across with virtually not even a glance from the mexicali police."

Guess you could compare that to a security hole in a firewall.

Is there some reason we're taking this so literally? It was a comparison to help understand my point, not a "this is exactly how firewalls work... just like customs checkpoints" statement.

So....... imagine that the ONLY way from one country to another is ONLY by going through a boarder crossing. No illegal methods. Does that help bulletproof the comparison?

Sheesh.
--
Aaron Hulett | Trojan Analyst | Mischel Internet Security
Forums » Bi-Directional FirewallsHonestly.... »
« Overkill for most  


Sunday, 22-Nov 18:56:50 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [196] Weekend Open Thread
· [117] Verizon Again Hints At Metered Billing
· [97] There's Still No Evidence That Metered Billing Is Necessary
· [93] Will AOL's Implosion Ever End?
· [85] Spain Declares Broadband A Legal Right
· [75] Deploying FTTH Without Digging Things Up
· [74] Verizon To Be Tested By Unofficial Droid Tethering
· [73] Femtocells Are A No Show
· [67] Verizon To AT&T: The Truth Hurts
· [60] Chicago Tribune Visits 'Comcast University'
Most people now reading
· Smoker's Applecare warranties may not be worth anything [All Things Macintosh]
· Why do cats... [General Questions]
· Extra charge to use Master Card instead of Visa? [General Questions]
· More MLPPP goodness [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· persistent connection to qw-in-f113.1e100.net on boot [Security]
· Hacking.....seriously, how easy is it to get hacked? [Security]
· TekSavvy Price Increase? [TekSavvy]
· what cellphone/company to get? [TekSavvy]