Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Solaris for firwall
From: Doug Kaye <dkaye @ iserve . rds . net>
Date: Wed, 22 Nov 1995 18:45:15 -0800
To: firewalls @ GreatCircle . COM
Cc: dkaye @ rds . com

At 04:22 PM 11/22/95 -0800, you wrote:
>> ...  Putting
>> a secure application on top of an insecure O/S leaves you insecure.  
>
>This is correct.  But I think it's important to understand what "on top"
>means.  As I understand it, when Firewall-1 is installed on a Solaris
>machine, the filtering code goes between the driver and the rest of the
>OS.  So who cares if the OS is "insecure" when the OS won't see any
>packets it's not supposed to based on the filters that are defined.
>In this case FW-1 is not really installed "on top" of the OS but
>"inside" (or underneath?); a subtle but important distinction.
>
>Craig
>
>> 
>> Frank
>> Fortified Networks Inc. - Management & Information Security Consulting
>> Phone: (317) 573-0800   - http://www.fortified.com/fortified
>> 

Well, not quite that simple, Frank.  A non-hardened (i.e., off-the-shelf) is
itself harder to crack.  In theory at least, a Bad Guy could get into the OS
itself and change the way packet filtering is handled.  In other words, the
risks are not limited to those things which the firewall is attempting to
filter.

        ...doug

============================================================
Doug Kaye <dkaye @
 rds .
 com>  Rational Data Systems, Novato, CA
Tel:415-382-8400     FAX:415-382-8441     http://www.rds.com


Indexed By Date Previous: Re: Solaris for firwall
From: Jas (Matthew K) <matt @ uts . edu . au>
Next: Re: Secret key versus obscurity
From: Julian Assange <proff @ suburbia . net>
Indexed By Thread Previous: Re: Solaris for firwall
From: Scott Barman <scott @ Disclosure . COM>
Next: Re: Solaris for firwall
From: frankw @ in . net (Frank Willoughby)

Google
 
Search Internet Search www.greatcircle.com