Firewall Wizards mailing list archives
Re: Proverbial appliance vs software based firewall
From: Gary Flynn <flynngn () jmu edu>
Date: Tue, 15 Oct 2002 12:27:49 -0400
Anton Aylward wrote:
On Tue, 2002-10-15 at 00:26, Jared Valentine wrote:While it is correct that all security comes down to "software" at some point, I would argue that hardware is much more secure. The difference between the two is that the hardware manufacturer can build off of a trusted base/OS. They can look at the OS line by line and strip out everything not essential for the operating of that firewall.
So could some customers and they could do it with their specific needs in mind.
I think that you "DON'T GET" Marcus's comment. Hardware in this sense is still software - embedded systems. Nothing in the Gartner paper contradicts that.
Another way of looking at it is the difference between software installed and configured by the vendor vs software installed and configured by the customer...or maybe even proprietary vs open source (sorry, couldn't resist). The effectiveness probably depends on the needs and capabilities of the target market. I'm sure NSA would like the opportunity to inspect and tune their own kernel and OS configuration while a small company consisting mostly of web developers would rather leave that chore to the vendor (and therefore trust them with their security). One could make similar arguments either way for "appliance" web servers, mail servers, or other turn-key systems. -- Gary Flynn Security Engineer - Technical Services James Madison University Please R.U.N.S.A.F.E. http://www.jmu.edu/computing/runsafe _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Proverbial appliance vs software based firewall Dominic Malig (Oct 14)
- Re: Proverbial appliance vs software based firewall Marcus J. Ranum (Oct 14)
- Re: Proverbial appliance "Its software, Jim!" Anton Aylward (Oct 17)
- Re: Proverbial appliance "Its software, Jim!" Paul D. Robertson (Oct 17)
- Re: Proverbial appliance "Its software, Jim!" Mike Frantzen (Oct 17)
- Re: Proverbial appliance "Its software, Jim!" Stephen D. B. Wolthusen (Oct 17)
- Re: Proverbial appliance "Its software, Jim!" Marcus J. Ranum (Oct 26)
- Re: Proverbial appliance "Its software, Jim!" Anton Aylward (Oct 17)
- Re: Proverbial appliance vs software based firewall Marcus J. Ranum (Oct 14)
- Re: Proverbial appliance vs software based firewall Mikael Olsson (Oct 14)
- RE: Proverbial appliance vs software based firewall Jared Valentine (Oct 15)
- RE: Proverbial appliance vs software based firewall Anton Aylward (Oct 15)
- Re: Proverbial appliance vs software based firewall Gary Flynn (Oct 15)
- Re: Proverbial appliance vs software based firewall Anton Aylward (Oct 15)
- Re: Proverbial appliance vs software based firewall Ryan M. Ferris (Oct 15)
- Re: Proverbial appliance vs software based firewall Volker Tanger (Oct 16)
- Re: Proverbial appliance vs software based firewall Christopher Hicks (Oct 16)
- Re: Proverbial appliance vs software based firewall Paul D. Robertson (Oct 16)
- Re: Proverbial appliance vs software based firewall Bennett Todd (Oct 16)
- Message not available
- Re: Proverbial appliance vs software based firewall Marcus J. Ranum (Oct 26)
- RE: Proverbial appliance vs software based firewall Anton Aylward (Oct 15)
- Re: Proverbial appliance vs software based firewall Marcus J. Ranum (Oct 26)