Unsolved

This post is more than 5 years old

2 Intern

 • 

7.9K Posts

1785

August 29th, 2004 15:00

Personal Firewall Poll

Everywhere I look, people continue to praise the "outbound protection" features of 3rd party firewalls and bash window's firewall for lacking such functionality.

I have been running some sort of personal firewall for around 5 years.  I have yet to have any "outbound protection" features alert me to an internal threat.

I have anti-virus software (mainly because I'm getting symantec corporate free at the moment from my school), and also run ad-aware and spybot every couple of weeks (which kill nothing but tracking cookies).  My first pop-up blocker was SP2's.

So my question is, to people who consider themselves somewhat intelligent (in terms of computers), and who do run AV and anti-spyware programs ... has outbound protection ever actually caught something bad or otherwise helped you?  Alternatively, has anything ever gotten around such protective features?

Honest stories only ... and I'm actually somewhat curious to hear the results.

Message Edited by NemesisDB on 08-29-2004 03:06 PM

2 Intern

 • 

11.9K Posts

August 29th, 2004 16:00



@NemesisDB wrote:

Everywhere I look, people continue to praise the "outbound protection" features of 3rd party firewalls and bash window's firewall for lacking such functionality.

I have been running some sort of personal firewall for around 5 years.  I have yet to have any "outbound protection" features alert me to an internal threat.

I have anti-virus software (mainly because I'm getting symantec corporate free at the moment from my school), and also run ad-aware and spybot every couple of weeks (which kill nothing but tracking cookies).  My first pop-up blocker was SP2's.

So my question is, to people who consider themselves somewhat intelligent (in terms of computers), and who do run AV and anti-spyware programs ... has outbound protection ever actually caught something bad or otherwise helped you?  Alternatively, has anything every gotten around such protective features?

Honest stories only ... and I'm actually somewhat curious to hear the results.

This post belongs on the Software - Other forum as the firewalls aren't part of Windows. 

If you run your system properly, then none of these programs will catch anything bad, because that would have meant you let it in in the first place.  Any decent firewall catches every program that tries to send out stuff without permission, usually for registration, checking for updates, etc.

895 Posts

August 29th, 2004 16:00

Mine has notified me several times of spyware that was installed by others using my PC trying to call home.  Granted it would have eventually been caught thru a spyware scan, but this was a instananeous notification that something was amiss.  Kip

224 Posts

August 29th, 2004 17:00

Everywhere I look, people continue to praise the "outbound protection" features of 3rd party firewalls and bash window's firewall for lacking such functionality.

As a general rule, you will find that the kind of people who are so gung-ho on third-party firewalls, or negative about Windows' built-in firewall, fall in two classes:

  • People with a vested interest in selling some stuff to the naive user
  • People with limited to no understanding of computer security issues

Otherwise, it is clear that the built-in firewall that comes with Windows, in particular the one included with SP2, at least meets, and often far exceeds the needs of the general home user. Second, the much-touted outbound protection is near-useless as a defense against true viruses and Trojans. People say that third-party firewalls help them detect spyware. I must confess that I have difficulty commenting on that claim, since I do not really understand why people install spyware on their systems in the first place. In any case, a minimum amount of common sense would be entirely sufficient as a defense against spy- and ad-ware.

I have been running some sort of personal firewall for around 5 years.  I have yet to have any "outbound protection" features alert me to an internal threat.

That matches my experience as well. I should also note that I am critical of the practice of many third-party firewall products to wave logs full with thousands of alleged "attacks" in front of their users, when it is clear that 99.99% of these so-called "attacks" represent perfectly harmless, and legitimate, attempts at connecting to common TCP/IP ports.

Alternatively, has anything every gotten around such protective features?

The so-called "protective" features are entirely useless as a defense against a determined piece of malicious code. Once the code is running on your machine (with administrative privileges, of course...) there is no defense. The makers of ZoneAlarm, in particular, are guilty of a blatant lie if they claim otherwise. Code that can disable or circumvent a firewall in your system is freely and easily available on the internet.

Finally, as an aside, one might note that due to its deep embedding into the operating system, Windows' built-in firewall is actually marginally more secure than the third-party solutions.

P.S.: I could add that I have seen far, far more people reporting some sort of problem that was due to their third-party firewall than I have seen people experience any kind of concrete benefit. Draw your own conclusions...

Message Edited by Dietmar on 08-29-2004 01:34 PM

2 Intern

 • 

495 Posts

August 29th, 2004 17:00

"....firewalls aren't part of Windows. "

Now it is.

I have the McAfee firewall, and I have received warnings of some programs trying to connect to the internet - most recently DivX player - why? (the program was up to date).

Probably nothing bad would have happened,  but there are reports of dialers dialing out long distance; the customer finding out only when he receives his telephone bill from Bell Canada.

Also reports of keystroke loggers, communicating out private information (such as credit card numbers, bank info, passwords,...).

Even though it is less likely you will need this outbound protection if you already have incoming protection - there will always be those who will try to beat that inbound protection you do have.

So I do think it is also important to have outbound protection. 

895 Posts

August 29th, 2004 19:00

Bologny Dietmar, as usual your assuming way too may things and wrong.  Im not going to debate this issue with you again, but its no accident that every major site, magazine, etc, does not recommend the new windows firewall for the exact reason we are discussing here.  Kip

1.2K Posts

August 29th, 2004 22:00

Hardware firewall will cost under $100 USD, and (on the long run) will provide a better protection and flexibility without taxing system resources.

If someone has ghosts in their system, then ZoneAlarm is the one to use. I’ve heard that the last version (v.5) is worst than the previous (v.4.?), and has some bugs, though.

Sygate Personal Firewall Pro is good too. Never used Symantec/Norton Firewall, but most of the feedback is good ... unless it was installed as a part of a "package" ... then some users complain about slow system ... which is easy to explain by the number of background processes. ;)

224 Posts

August 29th, 2004 22:00

as usual your assuming way too may things and wrong.

Well, you would have to demonstrate how any of the things I said are wrong.

2 Intern

 • 

3K Posts

August 29th, 2004 23:00



@NemesisDB wrote:

Everywhere I look, people continue to praise the "outbound protection" features of 3rd party firewalls and bash window's firewall for lacking such functionality.  And they all use the same line - "It doesn't block outbound traffic." Bear in mind that if your system is properly configured (proper configuration includes eschewing the use of P2P applications, Messenger apps with Auto-Pilot features enabled so that "anyone on your 'Buddy List'" can grab anything, anytime, and a host of other downright dangerous apps), you should not have to worry about what is going out.  If you do, then you have no one to blame but yourself, and there have been more reports of trashed systems in this forum by users of the latest and greatest third party firewall who have managed to trash the system anyway, simply because they don't know what they're doing.  No firewall in the world is going to protect you from yourself.  On the other hand, if you take a moment to learn a little something about all this technology you have at your disposal, and if you exercise due care and caution regarding what you install, you should not have to worry about outbound anything.  With that in mind, and to echo the comments of others, the WinXP firewall is more than adequate for the average user who would rather spend their time and money working with creative applications, rather than unnecessary utilities they were hustled into installing out of a misguided sense of fear.

In this forum, you'll see all sorts of posts recommending the use of applications like Spybot and AdAware.  Depending on how you use a system, these applications may be invaluable when it comes to cleaning up all the trash your surfing habits have created.  While not necessary in each and every instance, they do serve a purpose as far as helping you clean up your own mess.  I've never gotten a virus on any of the multiple systems I use, nor have I ever been hacked.  Back in the days of Windows 98, I used Zone Alarm, which (depending on the version), while serviceable, was a big PITA to configure in some instances.  I have 3-5 XP Pro systems running 24/7 on a high speed connection here now, and the WinXP firewall, common sense, and a few other simple precautions have been more than enough to keep them all running very well.  Quite simply, if something is going out of any of these systems, I know exactly what it is and where it came from, and I don't need a third party firewall to figure any of this out, either.  All of the systems consistently score 100% when tested with any of the mainstream vulnerability test sites, as well as on a few locally generated tests.

I don't want to see a popup box telling me what my firewall has stopped/noticed/prevented.  All I care about is that it works.  I'll take care of what's going out, as long as the firewall takes care of what tries to come in.  In that regard, the XP firewall is all I need, thank you.

I have been running some sort of personal firewall for around 5 years.  I have yet to have any "outbound protection" features alert me to an internal threat.  Nor do you necessarily need any.

I have anti-virus software (mainly because I'm getting symantec corporate free at the moment from my school), and also run ad-aware and spybot every couple of weeks (which kill nothing but tracking cookies Then you're obviously practicing reasonably safe surfing/downloading habits).  My first pop-up blocker was SP2's.  Works great, doesn't it?  You can't beat the price, either.

So my question is, to people who consider themselves somewhat intelligent (in terms of computers), and who do run AV and anti-spyware programs ... has outbound protection ever actually caught something bad or otherwise helped you?  No and no, nor do I anticipate any such thing happening.  Alternatively, has anything ever gotten around such protective features?  If it was created by humans, it can be gotten around by humans, and don't let anyone try to tell you otherwise.  It's a combination of risk management and the law of averages, though.  Not everyone is a hacker, and not everyone is going to be hacked.  You try to exercise moderate care to prevent such a thing, based on education and experience.  You can minimize your chances of being compromised, and the WinXP firewall works fine at stopping the most obvious and most commonly used methods of attack, again, assuming you're doing your part.

No Events found!

Top