Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Java Firewall
From: C Matthew Curtin <cmcurtin @ research . megasoft . com>
Date: Mon, 9 Sep 1996 22:56:31 -0400
To: Shmulik Suhami <suhami @ mail . finjan . com>
Cc: firewalls @ GreatCircle . COM, shlomo @ mail . finjan . com
In-reply-to: <323410FB . 344E @ finjan . com>
References: <323410FB . 344E @ finjan . com>
Reply-to: cmcurtin @ research . megasoft . com

>>>>> "Shmulik" == Shmulik Suhami <suhami @
 mail .
 finjan .
 com> writes:

Shmulik> Does anyone know of a Java enabled firewall?  Is there a need
Shmulik> for such a feature?  Are there any products available?  --

What problem are you trying to solve that requires a "Java enabled"
firewall?

What exactly is a "Java enabled" firewall?

On the issue of Java on firewalls, or Java in secure environments...

Java is very new stuff. It's been brewing (pun intended :-) in the
labs a long time, but it's still new. Security model has to be
scrutinized, and we (security geeks) need to bang on the
implementation to see how well it enforces the model.

Generally speaking, it's a bad idea to use any New Stuff where
security is a big concern. The reason is practical: without knowing
what bugs are there, it's difficult to assess what sorts of risks
you're exposing yourself to.

Now, if you're talking about firewall-type *applications* that are
written in Java, you're dealing with another religious issue
altogether: Should any compilers or interpreters live on your bastion
host? There isn't anything less secure about using an application
that's written in Java vs. one written in C. In fact, given that the
liklihood of errors in memory allocation, use of pointers, etc., is
between nil and very small, just the opposite might be argued.

But Java is *very* slow by comparison to C. And you need to have a
bytecode interpreter on your bastion host, or a Java development
environment that lets you generate machine-native object code.

In any case, what is it that you're trying to gain with this?

-- 
C Matthew Curtin                MEGASOFT, INC                Chief Scientist
I speak only for myself.  Don't whine to anyone but me about anything I say.
Hacker Security Firewall Crypto PGP Privacy Unix Perl Java Internet Intranet
cmcurtin @
 research .
 megasoft .
 com http://research.megasoft.com/people/cmcurtin/


References:
  • Java Firewall
    From: Shmulik Suhami <suhami @ mail . finjan . com>
Indexed By Date Previous: Re: smap alternative?
From: C Matthew Curtin <cmcurtin @ research . megasoft . com>
Next: Re: Modem hacking
From: harker @ harker . com (Robert Harker)
Indexed By Thread Previous: Java Firewall
From: Shmulik Suhami <suhami @ mail . finjan . com>
Next: FW-1 on ATM Link w/ LANE
From: "Phipps, Chuck, , PM-IMT" <PHIPPSC @ pentagon-reno . army . mil>

Google
 
Search Internet Search www.greatcircle.com