Bugtraq mailing list archives

RE: Bypassing Personal Firewalls


From: "John Howie" <JHowie () securitytoolkit com>
Date: Mon, 24 Feb 2003 12:11:05 -0800

Torbjörn,

... There are just too
many holes in Windows for it to be feasible to plug them all. The focus
ought to be on preventing the code execution in the first place, not on
trying to contain it.


I think it unfair to paint Windows with such a broad brush, especially as most other OSes had just as many, if not 
more, security problems in the last year. The reality is that most vulnerabilities are in applications (and usually 
third-party ones, at that) that run on the OS, and not in the OS itself. Your point about preventing code execution is 
right on the mark. Most attacks can be prevented through user education and methodical, secure, application development.

Regards,

John


Current thread: