Online Arrmor

Mar 13, 2009 65 Replies

No, I don't. Seeing which ports are open on the inside of a system does not tell you which of them are actually accessible from the outside. It may give you an idea which of them might be accessible at most, but that's about it.

You don't see that with netstat either. Your point being?

I'd still like to see proof for that claim. And no, your hotel example does not count, because hotels aren't regular ISPs. I wouldn't expect unfiltered Internet from a hotel just like I wouldn't expect unfiltered Internet from some company Intranet. I do expect unfiltered Internet from my ISP, though.

Yes. However, since that someone usually is either the host in question or its border router, online port scans still suffice in most situations. If you're worried about a middle man: there's still tcptraceroute.

cu

59cobalt

This is far away from "has to do nothing at all with it", but it's your decision, of course.

This is the reason, why I recommended to read the config of the filtering implementation and check the actual status of it, Ansgar.

Try to have an smtpd working on port 25 in a net of the German T-Online, then you have the proof. Ansgar, I know that you know the discussion about "SMTP submission".

You wanted to have an example, I gave you one. Hotels are ISPs which are not only used by me in a regular way.

Then don't go to the big ones. But my claim wasn't, that every ISP is filtering, only that some do. And I may add: unfortunately some of the big ones.

Yes, of course. But we're not talking about people who know those tools, do we?

Yours, VB.

That's baloney. It only does a poor job of traceing incoming malware.

Since when has it become the job of a firewall to trace incoming malware?

But isn't it that using a computer means that the user has to always tinker somehow with his/her computer? ( From Skype to Google's toolbar) Of course, as you say, the user could pay someone more knowledgable to do it for them , but then it would be quite expensive for most people.

Would you say that installing updates would qualify as installing components?

Geo

Indeed, and that's the crux of it. People want the convenience without the responsibility.

Probably. I'm not suggesting a hard and fast rule, to stick with the arguably bad analogy, some drivers don't know how to add fuel to their vehicles, some can do windshield fluid and add oil but not change oil, others do their own oil changes, some rebuild engines.

In the same vein, there is a difference between automatic updates (Windows Update, Chrome, Firefox, AV definitions), approved automatic updates (Adobe Reader, Flash, most other software), manually updating software, installing new software, and choosing what software to install.

This is true in most areas of life, my mom needs help hooking up a new DVD player, my dad hooks up his own DVD players but needs help pulling new coax and crimping ends, I do all of the above myself.

Making installing new software a bigger deal in terms of user interface might help, since it would stress to users the difference between "do whatever you want, you won't break anything" user mode and "you might screw up your system" administrative mode.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required