Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

"Personal Firewalls" are mostly snake-oil
Sam Spade ^

Posted on 09/19/2001 7:22:26 AM PDT by Sir Gawain

"Personal Firewalls" are mostly snake-oil

A 'personal firewall' isn't a firewall. A firewall is a dedicated box with (usually) two or three ethernet ports running no services other than a firewall. My preferred configuration is an x86 box with a couple of tulip cards running FreeBSD or OpenBSD and ipf, though you can do OK with Linux and iptables too. You can run either on a $100 obsolete PC. (*BSD is better, but Linux is easier for a new user to configure).

Even the little hardware NAT boxes that you can get for sharing a DSL connection or cable modem are way better than any 'software firewall' (The NetGear RT311 and RT314 are extremely sophisticated and flexible NATs and start at less than $100 - they do full NATing, allow port forwarding and filtering to a protected network (NetGear Firewalls and NATs).

So... what does a 'personal firewall' actually do? Well, effectively it listens on all the ports on your system. This provides no real additional security over turning off the services that you don't use.

I'll repeat that - it provides no real additional security over turning off the services that you don't use. (Maybe it'll block trojans from phoning home, but A) if you've run a trojan your system is completely compromised and B) http://cyberpunks.org/display/356/article/).

What it does do is break standard network applications (such as traceroute) and, more importantly, if badly written it will claim normal background network traffic is some sort of attack, alarming the user for no good reason. I've never heard of a 'personal firewall' that isn't badly written in this way. That doesn't mean one doesn't exist.

Why do the authors do this? Two reasons, as far as I've been able to gather.

The first is that most of the people writing these applications know next to nothing about IP networking. They may be pretty good windows developers, but they have no idea what normal network traffic looks like. That should make you nervous about their ability to block any real malicious intent.

The second is more insidious... Why is an end user going to buy / register / upgrade their 'personal firewall'? They're not going to do so if they don't perceive any benefit from it. If it were a properly written application that just sat there, doing its job quietly in the background, users would forget it was there. But if it pops up warnings about 'attacks' all the time then it's clearly Doing Something. Most of those warnings are entirely frivolous - normal network traffic. And the remaining few... well... if the 'personal firewall' has protected your system from the supposed 'attack'... why do you care about it? You're safe from that supposed 'attack', right? So why pop up warnings and alerts? To make you feel you're getting a service from this program and so you'll pay for updates or 'Pro' versions.

The bottom line is this... If you care about your home network security a lot, and you're interested in it, spend the time to learn about networking and build yourself a standalone firewall.

If you don't want to spend that amount of energy on it, buy a standalone dedicated NAT or NAT+firewall box. I like the NetGear RT-311 and its siblings, but there're a bunch of others out there too. It'll sit there, do its job and never bother you again.

If you want to play with a piece of windows software that makes you click all over the place, there's always minesweeper.

If you'll feel safer sleeping at night knowing there's a 'personal firewall' running on your system, then install one. As long as you pay no attention to the "hack attacks" it reports it's better than nothing. A free one, ideally, as few of them are worth paying for. Turn off all the alerts and logging - you'll just waste your time (and, more importantly to me, my time and the time of other network administrators your complaints go to) increase your blood pressure and provide no benefit to you. If you really want to leave them turned on and see where traffic is coming from, feel free, but remember that most of the traffic you see is harmless, and that even if it isn't harmless it can't affect your system (if it could, it wouldn't be logged). Oh, and try not to waste admins time with frivolous complaints.

"But, but, but reporting these alerts to network administrators will help them catch crackers!"

Uhm, no. I know a whole bunch of network security and abuse staff. The response to any complaint with ZoneAlarm, BlackIce etc logfiles in it is to close the ticket, usually with an annotation like 'GWF' (Goober with Firewall). 99% of those reports are frivolous, about normal network traffic. In the remainder of cases there's nowhere near enough data in the logfiles to provide any idea of why the end user is upset. If you send frivolous complaints that just wastes the time of the staff receiving them and prevents them from handling real security issues. How do you tell if a complaint is frivolous? If the sender doesn't understand basic networking, it's almost certainly frivolous. If the sender is complaining based on 'personal firewall' logs, it's definitely frivolous.

The abuse desk staff I talk with hate users of 'personal firewalls' more than they hate spammers. That should tell you something about how useful your complaints will be.

"You're just a unix bigot and don't like Windows applications!"

I don't like Windows applications for networking, no, as Windows isn't very good at it in general (with a few exceptions - some of the kernel level networking code in NT4 and NT5 is extremely sophisticated). As for being a unix bigot... I'm a Microsoft Independent Software Vendor, subscribe to Microsoft Developers Network and in my spare time produce Windows Network Applications.


TOPICS: Miscellaneous; News/Current Events
KEYWORDS:
Navigation: use the links below to view more comments.
first 1-2021-32 next last

1 posted on 09/19/2001 7:22:26 AM PDT by Sir Gawain
[ Post Reply | Private Reply | View Replies]

To: Fiddlstix, Texaggie79, RedBloodedAmerican
ping
2 posted on 09/19/2001 7:27:31 AM PDT by Sir Gawain
[ Post Reply | Private Reply | To 1 | View Replies]

To: sirgawain, unix, dead
NT ALL THE WAY BABY!!!! Point and click your way to DOMINANCE!!!
3 posted on 09/19/2001 7:32:26 AM PDT by Texaggie79
[ Post Reply | Private Reply | To 1 | View Replies]

To: sirgawain
Alright another Sam Spade user
4 posted on 09/19/2001 7:32:50 AM PDT by Texas_Jarhead
[ Post Reply | Private Reply | To 1 | View Replies]

To: sirgawain

My dear brother and sister FReepers,

At this, of all times in my lifetime, I would like nothing more than to be able to read these threads and reply to them.  I have much I would like to say.

BUT, I cannot!

Why?

Because I am trying hard to raise the finances needed to keep FreeRepublic up and running so that we can continue to share valuable information and respond to it.

I beg you, if you have not yet donated to FreeRepublic this quarter,  do so now!

If you have already donated, THANK YOU VERY MUCH AND GOD BLESS YOU, please ping your friends, and FReep on...!

I realize you are giving to lots of Relief efforts and I encourage you to do so.  But we need to help FR too.  Where would we be right now without it?

If you have no money, please come and bump the Fundraiser Thread.

I would really like to reach our goal quickly so that I and the rest of the dedicated FReepers who are working the Fundraiser Threads can participate in what is undeniably the most important time in FreeRepublic's history.

WHERE WOULD YOU GET YOUR NEWS FROM IF FREEREPUBLIC WASN'T HERE?<--click here

Support FreeRepublic! Support the U.S.A. <--click here

5 posted on 09/19/2001 7:33:28 AM PDT by 2ndMostConservativeBrdMember
[ Post Reply | Private Reply | To 1 | View Replies]

To: sirgawain
"Personal Firewalls" are mostly snake-oil

Not according to Steve R. Gibon of Gibson Research. He swears by ZoneAlarm.

Just because YOU say something, doesn't make it so.

6 posted on 09/19/2001 7:37:20 AM PDT by E. Pluribus Unum
[ Post Reply | Private Reply | To 1 | View Replies]

To: sirgawain
Tx.
7 posted on 09/19/2001 7:39:43 AM PDT by First_Salute
[ Post Reply | Private Reply | To 1 | View Replies]

To: Texaggie79
I run Win 2K with zonealarm, and I have been pretty happy with it. I'm using the shareware version now, and I believe I'm going to drop the $40 for the pro version. Just like the article says, 99% of the port scans are "legit" attempts from data miners to get cookie info from your system. I have had a few port scans now that I wasn't to sure about. One was an IP address listed as some invstigation firm in Mexico City. That one was kind of wierd. Anyway, I do like to know who is trying to get info from me, and the shareware from zonealarm does it well. I am sure that there are people out there without a clue that are calling administrators complaining about port scans that are, sadly, becoming routine. All in all, I won't connect to the net without my firewall running. Anymore who knows what might happen?
8 posted on 09/19/2001 7:49:18 AM PDT by Space Wrangler
[ Post Reply | Private Reply | To 3 | View Replies]

To: E. Pluribus Unum
I second that. ZoneAlarm RULES.
9 posted on 09/19/2001 7:51:30 AM PDT by Constitution Day
[ Post Reply | Private Reply | To 6 | View Replies]

To: sirgawain
I've been quite happy with ZoneAlarm. I've been running it under both Windows 98 and Windows 2000 Professional for about four months, and it's already protected my machines from a variety of crack attacks.

Granted that a firewall appliance that stands alone between your computer and the network cable can be made less intrusive and possibly even more protective, ZoneAlarm appears to do a reasonable job, and so far it hasn't destabilized any of my systems at all.

Freedom, Wealth, and Peace,
Francis W. Porretto
Visit the Palace Of Reason: http://palaceofreason.com

10 posted on 09/19/2001 7:56:01 AM PDT by fporretto
[ Post Reply | Private Reply | To 1 | View Replies]

To: Space Wrangler, Constitution Day
99% of the port scans are "legit" attempts from data miners to get cookie info from your system.

ZA needs to put this disclaimer on the site before you DL. I get so many emails from friends that are freeking out after they install ZA because of all the IP blocks they are getting. I'm tired of explaining to each one.

Also Zone Alarm is good with NT but only if you use it 100% of the time. I got to where I turned it off every now and then, and it would shut down my internet connection. And I was told the same from many on NT newsgroups.

11 posted on 09/19/2001 7:57:37 AM PDT by Texaggie79
[ Post Reply | Private Reply | To 8 | View Replies]

Comment #12 Removed by Moderator

Comment #13 Removed by Moderator

To: Texaggie79
That's absolutely correct. I freaked out for a while when I first installed it, but was helped by our IT Manager.
14 posted on 09/19/2001 8:15:10 AM PDT by Constitution Day
[ Post Reply | Private Reply | To 11 | View Replies]

To: semper_libertas
Gibson certainly believes ZoneAlarm is MUCH better than BlackIce though...

Yes, I di too because it looks at outgoing trafic as well as incoming. Coupled with my Netgear router, it works well.

15 posted on 09/19/2001 8:19:14 AM PDT by AFreeBird
[ Post Reply | Private Reply | To 13 | View Replies]

To: Texaggie79
ZA needs to put this disclaimer on the site before you DL.

If the people would click the link zonealarm provides, it is a very thorough and simple explanantion of what the port scans are. Personally, I don't worry about them, because if ZA logged it, then that means the attempt was un-successful. I have had two that piqued my interest as I stated above. The one from the "Investigaciones de y Internacionale" (I'm doing this from memory, so the exact name is probably a little diffrent from this) listed in Mexico city actually sent a little paranoid tremor through me. I can't figure out why a place like that was trying to scan me. Anyway, there's probably nothing to it, and this is probably just a fancy name for a data mining firm, bug I still wonder about it.

16 posted on 09/19/2001 8:46:41 AM PDT by Space Wrangler
[ Post Reply | Private Reply | To 11 | View Replies]

To: sirgawain
You are wrong. Flat out wrong. Yes, 99% of the software personal firewalls out there are garbage, but ZoneAlarm is simply the best software firewall package there is.
Get a copy and try it out. Or, I invite you to try to gain access to my system any time you want. You will fail.
If I'm wrong, I'll post here and say so.
If you fail, you must do the same.
17 posted on 09/19/2001 9:02:04 AM PDT by Bloody Sam Roberts
[ Post Reply | Private Reply | To 1 | View Replies]

To: Space Wrangler
Try BlackIceDefender...very good software and very good reporting system...but I'd use a secondary firewall/sandbox software too, like eSafe. Of course, 18+ pings in a matter of 30 minutes is a bit more then routine traffic.
18 posted on 09/19/2001 9:08:38 AM PDT by Stavka2
[ Post Reply | Private Reply | To 8 | View Replies]

To: sirgawain
Oops. I feel I must apologize. I am guilty of responding to your post before reading it entirely.
I am such an avid fan of ZoneAlarm that my hands flew over the keyboard before I read your whole post.
Many of the things you state are correct, but ZA is so far beyond all the other software firewalls out there, that it does offer adequate protection as a stand alone.
19 posted on 09/19/2001 9:09:35 AM PDT by Bloody Sam Roberts
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bloody Sam Roberts
Sam Spade wrote this. Not me. I just posted it. I hope you're addressing that site when you speak.
20 posted on 09/19/2001 9:09:49 AM PDT by Sir Gawain
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-32 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson