Kids bypassing firewall via web proxy sites

Mar 13, 2006 378 Replies

I have a Juniper Netscreen Firewall which has optional Surf Control Web Filter blocking based on categories, and is updated by subscription (not terribly expensive).

formatting link
category is to block proxies, which it does rather well, so should grab most of them anyway and make it much harder to get around. gr

Effective security requires physical, logical, and administrative controls working in concert. Technical people prefer logical controls because they can understand and manage them. The fact that most logical controls (e.g. content filters) can be circumvented does little to diminish their value, it merely reinforces the fact they cannot solve security problems by themselves.

Volker and Sebastian claim the ability to circumvent any logical control, therefore such controls are useless.

Leythos says we know in advance what users need, therefore block everything else.

My boss says he posted the rules, therefore fire anyone who breaks them.

They are all wrong. Security is hard work because, to be effective, you have to find a way to get everyone to understand and participate.

Triffid

I think, this is the point here.

Some people here and at other places like the promises of advertizing so much, that they just don't want to hear, what's wrong with them.

Those people are believing in "Personal Firewalls make you secure", in "Web filtering is solving the problem completely", in "Virus Scanners prevent from every virus" and so on.

I guess, that the reasons for this are different: while it is very comfortable to believe and not to think, many professionals have the problem, that they sold too much stuff to their customers to say now that they were wrong.

Let's see the positive site of this: a complete industry lives from it. And this means business, money transfer, employed people.

It's comparable to the show business - and isn't every business like show business? ;-)

Yours, VB.

What's up with pedophilia in this special case, Jazz is telling about?

Yours, VB.

This is exactly what I was trying to say. Thanx for making that clear.

Yours, VB.

Sorry for explaining unclear.

;-)

Sorry, no.

It is much too important to educate kids than it can be done by machines.

And adult employees don't need a babysitter. There are much better methods for having a valuable society than installing a robot babysitter for adults.

Yours, VB.

I feel most secure in a free society. And this means, there isn't much control. A free society needs the majority of people being sensible enough to keep this society free. This is true with states, but it is true with companies, too.

Having a good relationship to my employees is the most important point for my daily work. And if there is a problem, I'm trying to talk to the person who has this problem in the very first place.

Control is only a second best option if nothing else helps - and usually if this is needed too much, I don't want to employ this person any longer.

Yes.

Yours, VB.

Because newsgroups are for spreading news and for discussion. They're for education and entertainment. They're not "my free of cost support system".

Many people misunderstand.

Yours, VB.

yes and yes. If you think about any form of content worth blocking, and any mechanism, it is available.

There is enough crossover so that each filtering component compliments each other. So far, no problems.

Are we even discussing the same thing? A user manually entering a proxy chain?

Taking the piss is fine. Swallowing it and trying to tell me it's fine wine is a swing and a miss. That was sarcasm, irony, parody call it what you will.

If you think effective content filtering is impossible why don't you try it? E.

Does this mean you won't fix my Zonealarm problems???????? ;-) E.

I disagree. Some adults need a good smack with a clue stick. I think where this topic is digressing is to methods of educating users and peers.

Also, It's about what technology can be used to mitagate threats and how effective it is. You (and others) saying that that is somewhat useless without the human skills and other items such as policy is quite valid to the overall methodology.

Note to usenetters: when reading a post ask: is english their first language. Often it isn't. Learn to deal with it.

Cheers, E.

Why trying something which is impossible already in theory, and I'm seeing everyday the problems this stuff has?

Look, of course content filtering helps to keep the normal user in control. It keeps her/him in control until she/he finds out how to circumvent. And the message about this method then immediately spreads.

A user who knows what she/he's doing, you never will control with such means.

It's just like with detecting tunneling. You can try it and you may have success. And, of course, you may not. It's just not secure.

Yours, VB.

Wrong, you don't have to get everyone to understand or participate, if you could get everyone on the same page it would be a nice world and firewalls would not be needed. Fact is that there is always some lamer that feels he/she is owed internet access from work, to do personal things, download p*rn or videos, and nothing you SAY or PRINT is going to stop them, but a properly setup network and security system will. Fact is that due to the lack of Ethics our jobs have actually become easier once we understand what the business really needs vs what the employees want - block everything that doesn't have a valid BUSINESS NEED, it solves most problems and secures the network at the same time - no one needs to read yahoo.com or nytimes.com or cnn.com while at work.

If you don't know enough to secure the network, as you've stated it can't be done, then how do you know when your employees are doing what they should not be doing - are you standing over their shoulders while they work?

So, why not explain how you would do it in a business with 2500 employees, three shifts, where they have full internet access (like you suggest everyone needs), so that people are not violating the law, not playing games, not downloading p*rn/videos, not connecting into their home computers, all from the company network....

Please enlighten us.

Except that it doesn't work that way in the real world - there are TO MANY TIMES WHEN KIDS HAVE ALONE TIME, as do many workers at their jobs, and to hire people to follow them around every second of the day is a waste - warn them, instruct them, protect them from their own mistakes, block access that would harm them.

Seems like you're twisting correlation and causality. The predictability follows from the strict orientation towards facts and reality.

It is. Unneeded complexity decreases both security and performance.

You're not getting the point: such measures are effective. However, baggage control is NY's subways surely is not, and content filtering is neither.

From the point of political economics it's a disaster, as a big load of money is spent on creating no value. It's like digging a hole at A, moving the spoil to B, digging a hole, filling in the spoil, getting the new spoil to A and filling the hole.

There is no business like show business.

Wrong again - content filtering is just part of the solution that many people use, saying that picking out red haired people will protect you is false too, but if you combine several methods you end up with a great protection method that covers known and many unknown threats.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required