On Sat, 29 Jan 2011 16:01:50 -0500, DasFox wrote:
> On Sat, 29 Jan 2011 15:42:32 -0500, Android wrote:
>
>>> With your IP out there and a cheapy firewall, you can be owned...
>>
>> The best firewall in the world is free.
>
> NAME IT...with cites...
Give me some design specifics and an intelligent assessment of your threat
model, and I'll answer your question in no uncertain terms. And it WILL
include a free firewall befitting your needs. It will NOT, however, include
crap "software firewalls".
(If you have half an IQ point free you already know where I'm going)
Now, back to what you snipped and ran from. Lets see if you can man up or
not... whether your self-stroking persona actually has any clue at all, or
if you're nothing but hot air and don't even know what the hell I'm talking
ABOUT, let alone understand it...
> Most ISPs where I live do not hand out static IPs for Broadband, of
> course they are dynamic, BUT those Dynamic IPs stay with you for 30-45
> days...or LIFE...
So what? Having a more or less static IP address is a GOOD thing if you're
smart. Saves you from having to deal with the aftermath of the previous
owner and his P2P antics or soch.
> With your IP out there and a cheapy firewall, you can be owned...
The best firewall in the world is free. And even lesser firewalls are
perfectly capable of spitting back "unreachable" packets in response to
anonymous requests. Just like boundary equipment does when the host being
probed actually DOESN'T exist.
Yes, Gibson's machine hiding snake oil is little more than security theater
designed to dupe the masses. Nonexistent machines don't eat packets,
something actually SAYS they're not there. So when packets magically
disappear it's a sure sign there's a machine at that IP address. And one
owned by a noob at that.
> There's a VERY BIG point to hiding your IP and not exposing it and I
> can't believe you don't think so...
I can't believe there's still people out there who are so willing to
swallow whatever bile a media whore like Gibson vomits up.
> How do you think people get hacked and what you don't think boxes
> don't get hacked anymore? Of course they do...
Actually, port hacking like you're describing accounts for almost ZERO
successful attacks. But don't let little things like facts bother you.
[...]
> Maybe because you used the word HOME user you think that this makes it
> ok and it is good enough? Yes for a lot of average users that may be
> true, but in todays world with all the changes over the past 20 years
> I don't believe as a Tech that the Windows firewall is good enough
> anymore...
It's fine, as software firewalls go. It's also completely unnecessary in
modern times with modern equipment. I don't think there's an off the shelf
router on the market that doesn't include a firewall these days. That and
NAT alone make your machine completely invisible to the outside.
>
> Even for Grandma just surfing the web and emailing the grandchildern,
> her box can be hacked and used to commit crimes, so in that sense, no
> it's not just as good as it gets...
Things like "stealth" aren't just not good enough, or "good as it gets",
they're worse than doing nothing in a lot of scenarios. And completely
meaningless in the rest.