Full Disclosure mailing list archives

Re[2]: January 15 is Personal Firewall Day, help the cause


From: Ron DuFresne <dufresne () winternet com>
Date: Fri, 16 Jan 2004 17:26:29 -0600 (CST)

On Thu, 15 Jan 2004, Joris De Donder wrote:


There have been alot of 'complaints' or FUD replies concerneing the
efforts for personal firewall day, 1/15/04, yet not a single, "this would
work much better" replies or offerings.  do  any of the unsuporteres have

The main problem is the user. Annie for example opens/runs every
attachment she receives. Now if you say to Annie that all she needs to
do to be secure is installing (buying) a PFW (from a short list of
sponsors (*)), using an Anti-Virus program and keeping her system
updated, you actually encourage her to continue her dangerous
behavior. Fact is that even with a PFW, up to date AV and system,
Annie (who is part of the Administrators group btw) will get infected
if she keeps opening/running every attachment.
And then it's game over. This is not 1998, trojans/backdoors are
becomming more and more advanced (public rootkit projects for MS
Windows are becomming more common) and no PFW (a program that is
running on the same, now compromised, system) can prevent a 'modern'
backdoor/trojan from "getting out".

So we need to change Annies behavior. An obvious (technical) solution

        [SNIP]

We need to properly educate Annie's kids, they are the ones that will
grow up with a keyboard under their finger tips and see every automated
device and toy they get for x-mas cipped up and connected.  Annie grew up
in a time before all this, hell her VCR still has her stumped.  so we help
Annie out with PFW days and such, and try our best to guide her along one
baby step at a time, as her hair greys and her grandkinds lock down the
system she e-mails the family about reuinions and stuff...



Thanks,

Ron DuFresne
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"Cutting the space budget really restores my faith in humanity.  It
eliminates dreams, goals, and ideals and lets us get straight to the
business of hate, debauchery, and self-annihilation." -- Johnny Hart
        ***testing, only testing, and damn good at it too!***

OK, so you're a Ph.D.  Just don't touch anything.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: