Educause Security Discussion mailing list archives

Re: When is a firewall not a firewall?


From: Jere Retzer <retzerj () OHSU EDU>
Date: Fri, 5 Sep 2003 12:59:31 -0700

Gary Dobbins wrote

During the period of time during Windows startup, between the IP stack
coming up and the firewall service starting, Windows is fully exposed
to the net.  On one test I just ran, XP dutifully responded to probes
for at least 10 seconds, while it was busy preparing the "welcome
screen" for login.

This illustrates one reason why I believe that security should be built into the OS from the ground up. Otherwise, you 
can wind up with vulnerable software that operates with higher privileges than the software that protects it.

Jere Retzer

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/cg/.

Current thread: