Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: [NTSEC] ActiveX, MSIE and Quicken
From: Mike Shaver <shaver @ neon . ingenia . ca>
Date: Sun, 2 Feb 1997 14:52:29 -0500 (EST)
To: lists @ reflections . mindspring . com (Todd Graham Lewis)
Cc: firewalls @ greatcircle . com
In-reply-to: <Pine . LNX . 3 . 95 . 970131093619 . 355F-100000 @ reflections . mindspring . com> from Todd Graham Lewis at "Jan 31, 97 09:42:57 am"

Thus spake Todd Graham Lewis:
> On Fri, 31 Jan 1997, Russ wrote:
> 
> > So yes, plug it up today, that's what I recommend anyway, but What we
> > really need are new/improved desktop security products, not more filters
> > for Firewalls.
> 
> Not to be contentious or anything, but what we _need_ are designers who
> put different technologies on different port numbers rather than cramming
> everything under the sun down port 80.

Pardon the arrogance, but what we _need_ are firewall
designers/implementors/administrators/advocates who have outgrown the
bogus `port = protocol' bit.  Ports have meaning only for connection
management.  The use of `well-known-ports' is a convenience (snicker)
at best, designed to allow people to synchronize their /etc/services
files in lieu of a decent service-location directory or whatever.

Assuming that port 80 means HTTP is only marginally more clueful than
assuming that ports below 1024 are from root and so it's all Really OK
To Trust Them.

(Similarly for assuming that HTTP means HTML and images.)

If you want to filter an application protocol, you need a
application-protocol-level filter.

> Geez, at age 21 I really am too young to get an ulcer.

Not by a fair shot, gramps. =)

Mike

--
#> Mike Shaver (shaver @
 ingenia .
 com) Ingenia Communications Corporation 
#>                   Welcome to the technocracy.
#>                                                                     
#> "Nobody ever went broke underestimating the public's intelligence."
#>                    - cbird @
 chat .
 carleton .
 ca

Indexed By Date Previous: Re: [NTSEC] ActiveX, MSIE and Quicken
From: peter @ baileynm . com (Peter da Silva)
Next: Re: checkpoint firewall-1 logs
From: Kevin McPeake <cowboy @ dns . byelex . nl>
Indexed By Thread Previous: Re: [NTSEC] ActiveX, MSIE and Quicken
From: peter @ baileynm . com (Peter da Silva)
Next: RE: [NTSEC] ActiveX, MSIE and Quicken
From: Jerry Mendes <mendes @ garnet . berkeley . edu>

Google
 
Search Internet Search www.greatcircle.com