Firewall Wizards mailing list archives
Re: Proverbial appliance vs software based firewall
From: "Marcus J. Ranum" <mjr () ranum com>
Date: Sat, 26 Oct 2002 13:29:49 -0400
Paul D. Robertson wrote:
death importance, so I personally don't think the 'appliance' label applies to any firewall or security product in existance.That battle has been lost...
What people don't seem to understand is that "appliance" is a _PACKAGING_ concept. It's got nothing to do with anything else. It doesn't say anything about the quality, security, or maintainability of the software/hardware mix inside the device. Those are separate questions that are very important to ask. ;) "Hardened" is the other one that makes me want to puke. Most vendors call something "hardened" if they've disabled all the guest accounts in /etc/passwd on a copy of FreeBSD. Now, where I come from, "hardened" means that it has a security design that makes a strong case for how the system is not trivial to penetrate, and that it has the absolute minimum of stuff necessary to do the job. That doesn't mean deleting the compilers and X-windows apps - that means starting with a kernel, a static-linked copy of fsck and init and building upwards from there. mjr. --- Marcus J. Ranum http://www.ranum.com Computer and Communications Security mjr () ranum com _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: Proverbial appliance vs software based firewall, (continued)
- Re: Proverbial appliance vs software based firewall Mikael Olsson (Oct 14)
- RE: Proverbial appliance vs software based firewall Jared Valentine (Oct 15)
- RE: Proverbial appliance vs software based firewall Anton Aylward (Oct 15)
- Re: Proverbial appliance vs software based firewall Gary Flynn (Oct 15)
- Re: Proverbial appliance vs software based firewall Anton Aylward (Oct 15)
- Re: Proverbial appliance vs software based firewall Ryan M. Ferris (Oct 15)
- Re: Proverbial appliance vs software based firewall Volker Tanger (Oct 16)
- Re: Proverbial appliance vs software based firewall Christopher Hicks (Oct 16)
- Re: Proverbial appliance vs software based firewall Paul D. Robertson (Oct 16)
- Re: Proverbial appliance vs software based firewall Bennett Todd (Oct 16)
- Message not available
- Re: Proverbial appliance vs software based firewall Marcus J. Ranum (Oct 26)
- RE: Proverbial appliance vs software based firewall Anton Aylward (Oct 15)
- Re: Proverbial appliance vs software based firewall Marcus J. Ranum (Oct 26)
- Re: Proverbial appliance vs software based firewall Mikael Olsson (Oct 27)
- RE: Proverbial appliance vs. software based firewall Bill Royds (Oct 27)