Zone Alarm (Freeware-) stopped reporting intrustions..

Oct 03, 2006 74 Replies

formatting link
>>>>>> the chapter "Myth: Host-Based Firewalls Must Filter Outbound

Well you might consider them pointless features ,but microsoft actually calls it a "benefit" and "an important part of thier security strategy".Of course the odd blogger or person such as yourself may disagree ...just as many wouldnt. me

I agree ,though application firewalls can limit the effects of "bad" software too in certain circumstances. me

Would you guarantee that othe forewalls do not send any info to the author without my knowledge? Have you tested (I huess you have for ZA since you know it sends info even if the user has "check" not to...)?

Then what does that option do? It might hide your actual IP (but that's not a problem anyway as that is fake due to a router :-)

"And if you think it can block malicious outbound traffic see Microsofts statement at

formatting link
chapter "Myth: Host-Based Firewalls Must Filter Outbound Traffic to be Safe. " "

Did you actually read the informtaion you're referring people to? Basically some guy at MS deems the need for Outbound Traffic Filtering as a myth because the majority of users are too stupid to understand that's going on when prompted to allow/deny the traffic.

That's like saying "Myth: Need for strong passwords including capital letters". So because someone might not realize their caps key is on then we shouldn't allow people to put capital letters in passwords.

Just because his grandmother likes "sexy dancing pigs" and clicks "ok" without knowing what she's talking about doesn't mean that Outbound Traffic filtering is a useless security feature to the rest of us. (As demonstraighted my MSs inclusion of outbound filtering in Vista).

Well, it will help maximizing their sales, so it sure is a benefit. For them. Anyway, you need to distinguish between what sales droids and security professionals tell you. They won't necessarily tell you the same.

cu

59cobalt

Apparently it's you who hasn't read the article. Users not being able to understand what the firewall tells them is one argument against attempts to filter outbound traffic. Another argument is that malware can most easily remotely control applications that are *allowed* to communicate outbound (e.g. the web browser), thus bypassing the application filter.

cu

59cobalt

Why would it maximise thier sales if its a myth?...wont it be found wanting? me

Most modern firewalls are protected against this kind of circumvention. me

snipped-for-privacy@gmail.com schrieb:

I am certainly not a security specialist. But it seems ridiculous to me to assume that software A could control software B on the exactly same machine, if:

  1. software A and software B run in the same user context (typically admin)
  2. software A does not know anything about software B, while B has been tested against A

Obviously MSFT has spent their marketing dollars wisely. At the very least, they fooled you.

Regards Thomas

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

I underlined the (already given) answer for your convenience.

cu

59cobalt

No.

cu

59cobalt

snipped-for-privacy@gmail.com schrieb:

I am certainly not a security specialist. But it seems ridiculous to me to assume that software A could control software B on the exactly same machine, if:

  1. software A and software B run in the same user context (typically admin)
  2. software A does not know anything about software B, while B has been tested against A

Obviously MSFT has spent their marketing dollars wisely. At the very least, they fooled you.

Regards Thomas

Im looking for an answer but cant see one given.I asked if application firewalls are a myth ,then surely people would see through that (like yourself of course).So why would blatant lies boost sales? me

Maybe they fooled you into thinking thier xp firewall, without outbound application filtering was enough. me

I take it you need glasses then.

What makes you believe that?

Because people fall for them?

cu

59cobalt

Like which ones? The only one I've seen try (and fail at it) is ZoneAlarm 6.5 Pro.

cu

59cobalt

Thank you for being concerned ,the pair i have are fine.

Because you stated such.

you havent...have you

me

Quite obviously they are not.

Ummm... no?

And because I didn't fall for this particular lie noone will fall for any lie ever? That's one hell of a claim you put up.

cu

59cobalt

Just google for firewall component control,Anti leak...dll injection etc.Theres quite a few of them.Of course if you are behind a router you may wish to use SSM or similar rather than a software firewall with application control.However if you are not ,the software firewall might be a good all in one choice.If you are very careful you may not need anything at all. me

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required