Great Circle Associates Firewalls
(April 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: WWW proxy information
From: francis @ avalle . insoft . com (John [Francis] Stracke)
Date: Tue, 26 Apr 1994 17:22:06 +0500
To: firewalls @ GreatCircle . COM
In-reply-to: Kevin Altis's message of Tue, 26 Apr 1994 13:34:46 -0800 <m0pvtmx-0003UqC @ ibeam . intel . com>

>>>Since February, 1994, firewalls have been "safely permeable" for World Wide
>>>Web (WWW) clients via an application level proxy. Proxy support is built
>>
>>"Safely"? I don't think so.  There was some talk a while ago on this
>
>The trojan horse problem, discussed on this list previously, is a separate
>issue and as far as I can tell, unsolvable except by denying access
>altogether.

Unsolvable from the library/protocol level, yes.

>>I think there's (likely) nothing wrong with your proxy; but people
>>need to realize that running a proxied mosaic is scarcely safer than
>>running without a firewall.
>
>That is a major overstatement of the problem. 

Well, OK, but your implication that proxies make you safe is also a
major overstatement; I was concerned that, in your attempt to make
your (valid) point that proxies are good, you were going to go too
far, which would wind up in trusting people getting burned.  I believe
you stated that using a proxy meant you didn't compromise your
firewall at all.

>Cello, etc. Those PC and Mac environments which are the majority of
>machines, don't have the *same* environment problems mentioned above.

True.  And they probably have fewer holes, and more obscure; there's
probably nothing so egregious as the system() calls.  But you can be
sure there are some.

/===========================================================================\
|John (Francis) Stracke  | My opinions are my own.                          |
|InSoft, Inc.            |==================================================|
|Mechanicsburg, PA       | But this one goes to 11x.                        |
|francis @
 insoft .
 com      |                                                  |
\===========================================================================/


References:
Indexed By Date Previous: firewalls book
From: smb @ research . att . com
Next: Re: WWW proxy information
From: dwg @ rjrt . COM (David W. Griffith)
Indexed By Thread Previous: Re: WWW proxy information
From: altis @ ibeam . intel . com (Kevin Altis)
Next: Re: WWW proxy information
From: sedayao @ argus . intel . com (Jeffrey C. Sedayao)

Google
 
Search Internet Search www.greatcircle.com