sygate and shields up

Sep 08, 2005 42 Replies

Sure it is because it's an unnecessary step which will take time (and maybe money if you wasted money on a personal firewall) to implement. It's unnecessary because if you have B (or A) then you don't need C.

If I limit the discussion to inbound connection requests (which you want to 'stealth') then it should be easy to see that as a home PC user I can have A. I can make it impossible for anyone else on the internet to get a potentially exploitable response from my PC. To do this I simply make sure that no services are being offered to the Internet. It does not matter how my PC responds to an inbound packet containing any port numbers or other information as long as the PC does not send any useful information back in response to an unsolicited request. The fact that it does send something back (closed or port unreachable) is irrelevant. This does not mean that useful information is sent to anyone else. I know you'll try to argue that this gives your IP away or tells the 'hacker' that you are there but I think this has more to do with psychology than anything else. In some cases it's due to lack of knowledge. The misconception that 'stealth' hides your IP is not uncommon, as is the misconception that a firewall hides your IP. A worse misconception is that a personal firewall will keep malware off your PC.

I think you should increase your knowledge. Buy the book Moe Trin recommended. Do some searches. The Internet is not the answer to everything but if you want technical information on how it works then a search engine is all you need. You may already be aware of how to search but here are some examples in case they help.

formatting link
formatting link
Try some tools which will show useful information which you can learn from.

formatting link
Understand what you are connecting to, and why. Tools such as shields up do not tell you what your computer is having a conversation with if your computer made the outbound request to another computer.

Make sure you are not offering any unnecessary services to the Internet.

formatting link
But don't be fooled into purchasing any unnecessary products offered by those sites, just use them to check whether any obvious services are being offered to the Internet.

When you've read everything you can find, ask questions either here or in comp.protocols.tcp-ip By then you may find your questions being answered by a different set of people - those who never bother with pointless arguments about whether stealth is better or not because they already have sufficient knowledge to make their own decision.

I would advise you to forget about whether or not stealth makes you more secure and concentrate on other things which are far more important. If you are not already aware of what is running in your computer and why it's there and what it's doing then find out. A personal firewall will not help with this and 'stealth' will not make the slightest bit of difference. If you must use Internet Explorer then ask yourself why it's had a security update every month since the beginning of time. No browser is 100% secure but a B browser is better than a C one.

Personal firewalls exist to persuade people to buy them. They do not exist to help educate people to the level where they understand why they didn't need to purchase that firewall software.

Jason

My point being that that (in my example) there is no way to differentiate. Security by obfucasion/doubt, no certainty. Unlike your 'definite' .

I think I am/we are thinking of two distinct setups/talking at cross purposes.

Thank you for the brief exchange of views.

Yes. Aren't we talking about boxes, which are connected via Modem, DSL, $WHATEVER to the Internet, and "protected" by the "stealthing" feature of a "Personal Firewall", so their IP-address is "hidden"?

I just wanted to explain, why this cannot work.

Of course, it is possible to completely hide an host in a network - just _never_ send anyting to any other host, use the connection read only.

That includes, do not "load" webpages, do not send or receive E-Mail with this host.

In such a scenario, the host is invisible to the rest of the network. Sometimes, one is doing this for sniffing purposes, for example.

Yours, VB.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required