funsec mailing list archives

RE: Windows Vista Firewall: No Outbound Filtering By Default


From: "Brian Azzopardi" <brian () gfi com>
Date: Wed, 26 Apr 2006 18:00:57 +0200


Ok, how about this: whenever an app tries to open an outbound connection
Microsoft's own antispyware/AV tool kicks in and scans the executable
(and its parent processes, if any). If app is clean user does not need
to be bothered.

Brian


-----Original Message-----
From: funsec-bounces () linuxbox org [mailto:funsec-bounces () linuxbox org]
On Behalf Of Larry Seltzer
Sent: Wednesday, April 26, 2006 5:42 PM
To: funsec () linuxbox org
Subject: RE: [funsec] Windows Vista Firewall: No Outbound Filtering By
Default

...Microsoft has decided that the Windows Vista firewall will include 
no
outbound filtering by default. Apparently, Microsoft was considering
blocking outbound connections by default, but, in response to large
enterprise customer requests, they won't be doing that.... 

If it were just a matter of enterprise requests the answer would be
simple:
turn on outbound filtering on Home and Media Center, not Pro (or
whatever the SKUs are called in Vista, I forget). But the article goes
on to say, and quotes Zone Labs as agreeing, that outbound filtering is
a tough thing for the average consumer to configure, and I have to
agree. People who blithely dismiss Microsoft's concern for security in
cases like this really need to make a constructive suggestion, not just
snotty cracks like Skoudis does.

Larry Seltzer
eWEEK.com Security Center Editor
http://security.eweek.com/
http://blog.eweek.com/blogs/larry%5Fseltzer/
Contributing Editor, PC Magazine
larryseltzer () ziffdavis com 


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

  
This mail was checked for viruses by GFI MailSecurity. 
GFI also develops anti-spam software (GFI MailEssentials), a fax server (GFI FAXmaker), and network security and 
management software (GFI LANguard) - www.gfi.com 


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: