Slashdot Mirror


Microsoft Lists SP2 Incompatibilities

thejuggler writes "ZDNET has a story about how the new XP SP2 causes conflicts with over 50 applications and causes problems with others including some of Microsoft's own products. The 'glitch' as they are calling it seems to be that the Windows firewall system is turned on by default and blocks unsolicited connections to your computer. You have to unblock certain ports as your applications require to make the apps work again. They are calling this a glitch, but I thought we wanted everything blocked by default so we would have to choose what was unblocked?" The BBC has a story as well.

45 of 539 comments (clear)

  1. SP2 incompatible by bunburyist · · Score: 5, Interesting

    I've not seen it mentioned anywhere, so maybe it's just a drive incompatibility issue, but when I installed SP2 RC1, I could no longer play DVDs - I would receive an error telling me that the TV OUT on my card must be disabled first. I rolled back to SP1 and bingo, everything would play fine again.

    1. Re:SP2 incompatible by Doppler00 · · Score: 1, Interesting

      Maybe Microsoft has snuck in some DRM (digital restriction management) "enhancements" in this new release? I would not be surprised.

    2. Re:SP2 incompatible by PedanticSpellingTrol · · Score: 1, Interesting

      Looks to me like they're trying to turn DVD playback to a television into an "exclusive feature" of Windows Media Center Edition.

    3. Re:SP2 incompatible by NanoGator · · Score: 1, Interesting

      " How would this possibly be the fault of the DVD player software if it stopped working "after" the SP2 install and not before?"

      Maybe the software only works in SP1 because there was a flaw in it. You can sit there and shake your head if you like, but I actually have a DVD that will not play on my computer because it doesn't have Macrovision. I agree it's more likely that MS just broke something, but in this silly case (TV out?!) I wouldn't rule out Macrovision silliness.

      "Are you an MS shill or something?"

      Don't be an ass. Somebody should amend Godwin's law to include calling somebody a shill.

      --
      "Derp de derp."
    4. Re:SP2 incompatible by jrockway · · Score: 4, Interesting

      Solution? Ignore the flags. Install mplayer.

      Oh but that's ILLEGAL. Please tell me why it's illegal to play a DVD i bought on a computer i bought. Thanks.

      --
      My other car is first.
    5. Re:SP2 incompatible by utamaru · · Score: 2, Interesting

      Simple. All DVD players by law have to include Macrovision to prevent someone recording to VHS or another DVD, awile PCs don't output Macrovision. M$ is probably saving their ass from DMCA.

  2. hmm... by Savves · · Score: 1, Interesting

    wouldn't they have found this "glitches" earlier by the SP2 beta testers..?

    1. Re:hmm... by obeythefist · · Score: 2, Interesting

      I noticed that a couple of applications don't work with my Athlon's (hammer core) NX bit enabled. But clicking "Add" to the "permitted apps" list is a simple once-off operation like a firewall.

      Trillian and Warlords:Battlecry III were the only apps with this "problem" to date. For some reason they're bypassing some Windows API's and directly executing code from memory they're not supposed to. This isn't Microsofts fault either - I love watching Windows and my CPU working together to ensure code that runs is not doing anything dodgey.

      But I can agree with the consultants a while ago - with SP2 for XP, buying anything but Athlon K8 is a bad security decision.

      --
      I am government man, come from the government. The government has sent me. -- G.I.R.
  3. Activation by n9uxu8 · · Score: 2, Interesting

    Lord knows CodeWarriors IDE activation is flumoxed by sp2... Dave

  4. forgot to mention Intel Landesk by stonebeat.org · · Score: 2, Interesting

    Intel Landesk (an MS SMS competitor) also has issues when SP2 is installed. But why would MS care about that? According to them everyone should be using SMS.

  5. My first reaction? by Anonymous Coward · · Score: 1, Interesting

    Good! at long last all those applications that want to phone home are getting busted. WTF is an application doing opening ports on the localhost anyway?

  6. Default Port Blocking is wrong when... by Jack9 · · Score: 2, Interesting

    Your just decide to implement a 100% turnaround in how your OS policy worked before (without making a big deal of it, of course...I'm sure it was documented somewhere). This is almost akin to "Oh yeah, and XP only reads DOS partitions now...er again...er yeah, just like you wanted!". This blunder is complicated by MS applications not always documenting what ports they are using because that's proprietary information and of course you can always buy the product and ask the licensed technical support.

    --

    Often wrong but never in doubt.
    I am Jack9.
    Everyone knows me.
    1. Re:Default Port Blocking is wrong when... by EvanED · · Score: 3, Interesting

      According to this Register article, it's not like MS made SP2 come out of the blue. App vendors have had plenty of time to start thinking about the changes they might need to make.

    2. Re:Default Port Blocking is wrong when... by Tarkwyn · · Score: 3, Interesting

      Most of us conscientious 'app vendors' have been diligently studying the various release candidates coming out of Redmond.

      Before beating on the ISVs make sure you check out a legitimate bug in SP2. This particular bug wasn't present in RC2 and has caused a good few slashdot-friendly vendors some undue heartache (notably PuTTY).

      Yes, there are vendors out there who ought to have been more prepared, but MS certainly needs to take a good deal of responsibility for these current issues.

      --
      Tarkwyn.
  7. Re:News Flash: Firewall Blocks Inbound Traffic by halowolf · · Score: 5, Interesting
    Yes it was exactly my response. They had games listed that require internet access to play them online like Unreal Tournament.

    What I think is the "real" issue here is that customers that have installed SP2 simply don't have a clue about what a firewall is, what it does, and how to use it. The problem is also no doubt being exacerbated by programs that needlessly try to access the network.

    But I always take the time to say "shame on you" to programs that needlessly try to access the network when their primary function has absolutely nothing to do with networking, ESPECIALLY when their networking options are turned "off".

  8. ya kidding me? by Stevyn · · Score: 1, Interesting

    At the top of the list was visual studio .net. Are you kidding me? Their new software "concept" that's going to revolutionize can't be created using a computer running sp2? Does this mean .net is inheriently insecure, or just this remote dcom debugging? I'm ignorant on what that is so my point won't be to spread FUD about .net, just to say "what the shit?"

    It seems to me that when a company spends this much time working on a service pack they can't yell down the hall for the .net guys to make a patch for sp2. Even if they made a patch, they should have put it in sp2 as an option. It seems like poor management to surpise people that even their own software won't work with sp2.

    I still commend microsoft for closing those old holes and throwing perfect compatibilty in the wind in this case. Sometimes you just got to bite the bullet and focus on new security. Hell, look at OSX. IIRC, photoshop didn't work initially with OSX, but apple had to balls to let OSX create the demand.

    Now that last statement may sound contradictory, but notice that apple doesn't control adobe where as microsoft controls microsoft.

  9. Re:Time for change? by GoofyBoy · · Score: 3, Interesting

    If I don't know how to open up ports on a firewall or even what a firewall is, how the hell am I going to know figure out how to install Gentoo?!?!?

    --
    The surprise isn't how often we make bad choices; the surprise is how seldom they defeat us.
  10. Re:Time for change? by King_TJ · · Score: 4, Interesting

    I'm sorry, but I'd almost have to call your post a "troll" - even though you're not necessarily wrong about everything you said....

    Realistically, how is a Linux distro like Gentoo a real "alternative" at all, for the average PC user wanting a "workstation OS" that runs all of their purchased "off the shelf" software packages??

    Just as one little example, a good friend of mine recently wiped Windows XP off his Dell Latitude laptop and replaced it with the latest Gentoo Linux distro. He could only stand it for about 3 days before deciding it just made his laptop *less functional* than it was worth, and went back to XP.

    It's not that he dislikes Linux! He thinks it's great! (So do I, for that matter.) It's just that Linux is based on a *server-centric* OS (Unix), and all the attempts to reconstruct it as a desktop workstation OS with user-friendly GUI are less than fully realized.

    I'm all for competition, but as much as some people want it to be, I don't think Linux is really the direct competition for Windows XP right now. If anything, it's poised more as a sensible alternative for something like Windows 2000 or 2003 Server.....

    If you want a Unix type OS done right as a workstation, I think Apple already pulled it off better than anyone else -- but that's getting into a whole new hardware AND software investment.

  11. Re:The sad thing is.. by Geoffreyerffoeg · · Score: 2, Interesting

    That shouldn't happen. Of course the system should allow unfettered connections to localhost, and the system's own public/LAN IP. Firewalls should wall off the outside.

    I'm sure a simple update to add "if (connection.ip != INADDR_LOOPBACK)" to the firewall code. Frankly, I'm surprised it wasn't already in there.

  12. Designed for newbies by ktorn · · Score: 4, Interesting

    Turning on the firewall by default is a design for newbies, and rightly so.

    My mother doesn't know what a firewall is, nevermind how to switch it on.
    Those who know what it is, and how to configure it, will be able to open the required ports or allow the required programs access to those ports.

    The clueless might not be able to use some programs, but if that means viruses and worms will not spread as much as before then it's something I think we all can live with.

  13. Re:Not a big deal... by WhatAmIDoingHere · · Score: 3, Interesting

    In IE, just go to "tools"/"Popup Blocker"/"Settings" and there's about the same settings as in Firefox.

    --
    Not a Twitter sockpuppet... but I wish I was.
  14. not broken by scubacuda · · Score: 2, Interesting
    They're not broken programs, they're programs that "may behave differently".

    (i.e. "broken"!)

  15. Re:Like we didn't see this coming... by obeythefist · · Score: 3, Interesting

    Okay Mr. FUD, let's look at Linux. Say you had a linux install. And you ran Mozilla and you used that to browse websites, mozilla came *bundled* with your operating system.

    This is all well and good.

    Now you install a Firewall, perhaps one bundled with your Linux distro.

    Suddenly, Mozilla doesn't work anymore! You can't browse the internet!

    Is this the fault of your Linux distributor? Why are people saying that Windows is useless because the new firewall *blocks* traffic unless you open the right ports? Why aren't people saying the same for Linux, when Linux works *exactly* the same way?

    Or do you just like to spread anti-MS FUD so you can get karma on slashdot?

    --
    I am government man, come from the government. The government has sent me. -- G.I.R.
  16. Mac OSX manages this just fine by goombah99 · · Score: 5, Interesting
    On mac OSX the sharing-related services GUI and the Firewall GUI are coupled. Turn on Apache and it unblocks port 80 automatically. Turn on SSH and it unblocks 22 automatically. and so on for FTP, AFP. turn off he services and the ports get bliocked automatically.

    At present if you want other ports to open, other than these default services, you have to open the ports manually. however I would imagine this coupled action is handled by some .plist xml configuration file. So its probably possible for an application to add its own services to the sharing menu and have them coupled to the firewall if you turn the service on.

    On my mac I do manually block the incoming and outgoing license manager ports for MS Office. If you dont and want to share the app on your laptop and desktop then you will lose any open edited docuements if you inadvertently plug them into the same network. I wonder if this lic manager is the reason why MS gave the firewall the ability for apps to open ports in the firewall and to have outbound connections?

    --
    Some drink at the fountain of knowledge. Others just gargle.
    1. Re:Mac OSX manages this just fine by FireFury03 · · Score: 4, Interesting

      you're clueless, right?

      No

      firewalls can also be used to get some sort of acl functionality out of them (you might want to enable ssh access to only a few known ip's on the internet), can do packet inspection, perform rate limiting tasks, prevent DoS attacks

      Right, because how many Windows personal firewall users are going to be doing that? I haven't seen Microsoft's offering but I'd be quite supprised if it could be configured any mroe specifically than "block this port" and "open that port".

      protect the internet from _your_ machine should some malware be running

      IMHO blocking outbound traffic from personal firewalls is of dubious use at best - once the machine has been compromised the malware can quite happilly disable your firewall (a number of viruses are known to disable ZoneAlarm automagically) or look at the firewall rules to see which port it can make connections on.

      Running a firewall to block outbound traffic only seems sane if it's a completely separate device since once the device running the firewall is in a position to send malicious data the security of the firewall should already be considered void. As far as I can tell, all it does it provides a false sense of security, which is a very bad thing.

    2. Re:Mac OSX manages this just fine by pellaeon · · Score: 3, Interesting

      Right, because how many Windows personal firewall users are going to be doing that? I haven't seen Microsoft's offering but I'd be quite supprised if it could be configured any mroe specifically than "block this port" and "open that port".

      So now we're suddenly talking about Microsoft's firewall only? Well, I haven't seen it either, but I'm pretty sure there's a personal firewall available somewhere that can do at least some of these things. Configuring your OS/services well still doesn't protect you from a DoS on your computer though.

      IMHO blocking outbound traffic from personal firewalls is of dubious use at best - once the machine has been compromised the malware can quite happilly disable your firewall (a number of viruses are known to disable ZoneAlarm automagically) or look at the firewall rules to see which port it can make connections on.

      And some compromises will not achieve sufficient access to disable the firewall or view its config. How about home-dialing malware that would in this situation be prevented from running, or spyware?

      IMHO having a firewall running is useful even if only to provide an extra stumbling block for malware.

      Running a firewall to block outbound traffic only seems sane if it's a completely separate device since once the device running the firewall is in a position to send malicious data the security of the firewall should already be considered void. As far as I can tell, all it does it provides a false sense of security, which is a very bad thing.

      Ok, how about a home network then? Many people use one Windows computer using "internet access sharing" to enable other computers to connect to the internet. In this case the internet-connected computer running a personal firewall would be a seperate device and could defend itself (and the internet) much better against the internal compromised machine.

      Err on the side of safety, I say.

      --
      -- /bin/coffee missing. universe halted.
    3. Re:Mac OSX manages this just fine by FireFury03 · · Score: 3, Interesting

      Configuring your OS/services well still doesn't protect you from a DoS on your computer though.

      Depends what sort of DoS you're getting - I don't really see a firewall as a solution to any of them though:

      - SYN flood: this problem was solved years ago through the introduction of SYN cookies - anyone who isn't using SYN cookies these days has no business allowing anyone connect to them anyway.

      - Bandwidth flood: A firewall ain't gonna help you here - even if you're blocking the packets, they have already traversed your (reasonably low bandwidth) internet connection... The only thing that's going to help here is to block the packets on the ISP side of the connection.

      - Slashdotting (i.e. many concurrent connections - may be legitimate connections but they're gonna kill your server anyway): Most services will let you limit the number of connections they will serve at the same time - a firewall is not the answer (unless it's on the ISP side of your internet connection).

      IMHO having a firewall running is useful even if only to provide an extra stumbling block for malware.

      It's a stop-gap solution - when 99% of computers block outbound traffic by default the malware will all automatically work around the firewalling. Malware is a very fast evolving problem, just like spam - simple stuff like this will only have an effect for a very limited amount of time. I think it's exceptionally bad that it will produce a false sense of security, and the very protocols that worms will be using are likely to be open anyway since they're protocols that people need to use.

      Ok, how about a home network then? Many people use one Windows computer using "internet access sharing" to enable other computers to connect to the internet. In this case the internet-connected computer running a personal firewall would be a seperate device and could defend itself (and the internet) much better against the internal compromised machine.

      I wouldn't suggest that a firewall is useless in this situation, however I was talking about personal firewalls and would argue that once you start protecting a whole network instead of a single machine you can nolonger consider it a "personal" firewall.

    4. Re:Mac OSX manages this just fine by pellaeon · · Score: 2, Interesting

      Do you know how to stop Windows from using ports 137-139? I think many people don't know. I myself have no idea (as I don't use Windows) if it's even possible. If it's not, it's something you need a (personal) firewall for to block access to these ports (which I _do_ know to be exploitable).

      Having a firewall block these ports by default can only be a good thing, since many people just _won't_ take the time to learn how to configure and harden an OS by themselves. Given the lack of knowledge concerning security for most people, a personal firewall that's on and blocking by default can't be useless.

      And 'false sense of security'? Many people don't care about security, but need to be protected (sometimes even from themselves) anyway.

      Besides, if this 'personal' firewall is all you have protecting your network, even if it's only by being on by default, you're still better off security-wise.

      --
      -- /bin/coffee missing. universe halted.
    5. Re:Mac OSX manages this just fine by mchawi · · Score: 2, Interesting

      Once the system has been compromised you are in trouble - that is true.

      However personal firewalls have a -lot- of benefit at least from a business standpoint. Many firewalls, including SP2 have additional features that help protect your network. As a for instance, limiting the number of outgoing TCP connections that can be opened per second. If you've ever seen some of the viruses take out network bandwidth - this is one of many ways to help.

      Basically if you look at a personal firewall as a 'solution' - it is going to fail. If you look at it as one tool of many to make up your corporate security solution, it gives you power.

      As another 'for instance' here - if you have an active directory domain, and you find that a new virus is using port X that you have open for application Y - you can turn that port off from the GPO. This means that you can reconfigure the personal firewall on all the computers and clean up the issue without your network going down the tubes as it spreads itself.

      Not -all- reasons for a firewall involve some sort of root/administrator hack.

  17. Scary quote by roystgnr · · Score: 3, Interesting
    From the support.microsoft.com link:
    The number of ports that the process uses may affect how this issue is resolved:

    * If the process uses more than 1024 ports, the number of ports probably will not change.
    * If the process uses less than 1024 ports, the program may be using a range of ports. Therefore, opening individual ports may not reliably resolve the issue.

    It just fills you with confidence in their network security qualifications, doesn't it? I'm sure their audience won't be too confused (even most online gamers know the difference between "port number" and "number of ports"), but that just makes it even stranger that they hired a technical writer who can't make that distinction clearly.
    1. Re:Scary quote by rokzy · · Score: 2, Interesting

      outsourcing. who needs people who can speak English when the web has plenty of free translation sites?

  18. ISPs are screwed by jhoegl · · Score: 2, Interesting

    ISPs will take the brunt of this issue on the phones. Once SP2 is released, ISPs will be innondated with calls asking why their software doesnt work. And believe me, those answering the phones will be annoyed. As a former ISP tech, I have had to deal with the MyDoom, the SQL worm, and all the huge viruses that hit two years ago. Luckally, there have not been any major virii released since September of 2002. However, the first person the people call is always the ISP, its not because they dont know whom to call, but because they know they can get advice for free.

  19. Re:News Flash: Firewall Blocks Inbound Traffic by surprise_audit · · Score: 4, Interesting

    On the other hand, the list of "programs that behave differently" includes Excel, Office 2003, Office XP, Outlook, Visual Basic, Visual C++ and Visual Studio. I can see various personal firewalls and p2p apps like Kazaa being broken by port issues, and maybe the Office suite because of email & calendaring, &c, but why on earth would VB & VC++ be affected??

  20. OOPS I just found a security issue on the mac! by goombah99 · · Score: 2, Interesting
    Trying to answer my own question above, I discovered that any admin user can, without a password, alter the firewall plist to open and close any ports on the fire wall under program control.

    This is the same security issue (not a security hole per se) that microsoft was being critisized for. That is a rogue program can open and close ports on the firewall.

    here, try it yourself. the following patch will add a port setting called x-windows to your fire wall and open up ports in the 6000 range.

    Dang, the lameness filter wont let me show the patch. oh well figure it out for yourself. its easy. just look in:

    /Library/Preferences/com.apple.sharing.firewall.pl ist

    --
    Some drink at the fountain of knowledge. Others just gargle.
  21. Egad! by Anonymous Coward · · Score: 1, Interesting

    I left a network of 80 computers with XP auto-update feature turned on. I came to work this week to find SP2 installed, yet the version listed in the control panel is "XP 2002 SP1". Kinda sneaky. Sure enough all the new firewall stuff is there. I visit windowsupdate, and v5 is now the default. No updates left to be installed. No mention of ServicePack2 except in Internet Explorer -> Help -> About. Whats the deal? HOw does one uninstall? No mention in Add/Remove Programs.

  22. Re:Forgive my ignorance by Erik+Hollensbe · · Score: 3, Interesting

    for a standard setup and ports 1-1024 it's not as big of a deal, really, as your "friendly neighborhood cracker" needs to crack your machine completely to open ports. (Should be obvious, but if your user has root, you just lost all benefit of the firewall as it can be modified)

    However, if the cracker just manages to get user privilidges on the box, *ka-blam*, if you don't block inbound you are a mail relay, a DoS zombie, you name it. An easy way to prevent that is to block everything incoming that you don't use.

    Heck, with the way some rootkits work, and the relative naievete of the cracker, blocking hte lower ports may prevent something more sinister happening automatically and give you time to shutdown/clean/whatever the system before things get too screwed up.

    A good firewall plan always starts with "block everything".

    Another neat trick is to use NAT and port forwarding to send all incoming traffic on the firewall from the internet to a host on the local net that doesn't and will never exist. Depending on implementation and how you use it, this prevents the cracker from even touching the box (save a hole in the networking stack) and installing services on it, even if cracked, is fairly pointless. Of course this trick is useless if you don't follow firewalling best practices and block all incoming traffic from the outside that appears to come from internal-only network blocks.

  23. /Library/Prefereces permissions by SuperKendall · · Score: 3, Interesting

    The directory /Library/Preferences has perms of g+w, so group users can write to it - thus as the other poster noted you can potentially overwrite the file. At least, TextEdit sure does.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  24. Re:Like we didn't see this coming... by obeythefist · · Score: 3, Interesting

    Like you can configure Windows firewall as a part of the installation process (I've applied SP2 at home).

    As Mr FUD is suggesting, Windows users won't configure the firewall at install time (which is why those apps don't work). To be fair we'll also assume that you won't configure your linux firewall at install time.

    Any good firewall will block outgoing traffic just as well as it blocks ingoing traffic, by default. The new windows firewall in SP2 blocks outgoing traffic (the SP1 version of the firewall was inbound blocking only).

    So, without configuration, you'll find all those linux distros you've listed share this same problem - when you install an unconfigured (all ports closed 2-way) firewall on them, some applications will break.

    You can't go and say that it's a "non-existent" problem, because you have to assume that any user who can't configure a firewall under Windows couldn't do it under Linux either. What we're really seeing here is Windows moving closer to Linux's security methodology - secure by default. So the problems mentioned in the article are directly applicable to any Linux distro that is secure by default - yet people are hanging it on MS despite this.

    --
    I am government man, come from the government. The government has sent me. -- G.I.R.
  25. Mac Address Spoofing by SquireCD · · Score: 2, Interesting

    I've noticed that SMAC version 1.1 and 1.2 no longer works with SP2 installed. Neither does editing my mac address with regedt32.

    This might just be my computer but it's worth thinking about before installing SP2.

  26. Re:You nailed it. by blane.bramble · · Score: 4, Interesting

    For example, everyone should know: what the Internet is; that not everyone on it is trustworthy, and most importantly to READ BEFORE YOU CLICK.

    My 7 year old daughter knows to do this - I have taught her that if any box appears on the computer to read the message, and if she doesn't understand it or know why the message appears, to ask me. As an example, a while ago she was trying to play a game (probably from the BBC web-site). After a few minutes she came and told me the game wouldn't work - it turned out everytime she clicked on it, she got the standard IE "do you want to run this, blah blah, may cause damage to your computer", so she clicked Cancel (not wanting the computer to be damaged...). After 4 or 5 goes round this she decided it was time to ask for help.

    Why is this so difficult to get into other peoples heads?

  27. I think Microsoft have done the right thing by pandrijeczko · · Score: 4, Interesting
    It seems to me that the listed applications do not work purely because of the default firewall settings in SP2 in which case Microsoft have done the only thing that they could.

    The fact is that the majority of Joe Public is far too stupid & lazy to want to bother understanding how a computer works so Microsoft has had to force their hand into making their systems more secure.

    Whilst I consider Microsoft "it's own worst enemy" by portraying its OSes as error free and requiring minimal management in advertising, they have taken the right action here because hopefully this starts to make it more difficult for viruses and worms to propagate meaning that we all benefit.

    If there's one big advantage we have in the Linux world over the Windows world is that our proportion of idiot users is virtually zero - I for one hope it stays that way also.

    --
    Gentoo Linux - another day, another USE flag.
  28. Word 2000 broke on several of our machines by Tanami · · Score: 2, Interesting

    Of the three machines we've got here with the Windows XP / Office 2000 combination, two of them stopped opening documents after installing SP2 (just hangs). Office seems to have latest service pack itself, so nothing else to do but rollback and disable auto-update.

  29. Which defeats the whole purpose by Moraelin · · Score: 3, Interesting

    I'll tell you a story.

    I once had to install Windows 2000 on a box, and as Loki would have it, I had no Zone Alarm or Sygate Personal Firewall on a CD at hand. Just as Joe Average would.

    So I could go download it somewhere else, or I could do a scapegoat installation just to download a firewall. I chose to just sacrifice an install to the gods of Hacking. I _knew_ I'd get hacked, but that was OK, since I'd reformat immediately after anyway. (Takes less time than whining on /. about MS security, btw.) Joe Average wouldn't know, and wouldn't reformat.

    (And I'm not disappointed. It takes less than a minute to get my uplink bandwidth saturated with mysterious outbound packets.)

    Still, it will serve to illustrate what happens after you get your machine 0wn3d by some l337 skr1p7 kiddi3.

    So I decide to play with it a bit longer, and see what happens with a firewall and an 0wn3d machine.

    I start the newly downloaded and installed Sygate Personal Firewall, and immediately it pops up a window telling me the name of the application _and_ what's it trying to do. I block it, and that's that. No more outbound packets. I can tell struggles long and hard to send crap, but it can't. Both its inbound and outbound pipes have been sealed shut.

    I can now toy with that machine as long as I wish, trying to disinfect it. Again, which is what Joe Average would want. If it's _not_ a sacrificial install, but some machine where his resume and a few gigs of other important data is, Joe will not want it reformatted.

    I can even surf the net looking for information on the trojan, safe in the knowledge that it's blocked. No need to pull out the network cable.

    Whereas you tell me that Apple would have allowed it to open its own ports, as it damn pleases. Inbound or outbound, whatever. And not even told me about it.

    Well, gee. Sorry, that's not the kind of security I'm looking for. Dumbing down a firewall to the point where it doesn't actually block anything, in the name of "user-friendliness" is _not_ the way to go.

    --
    A polar bear is a cartesian bear after a coordinate transform.
  30. My Problem with SP2 by kpogoda · · Score: 2, Interesting

    I installed SP2 and then it made me re-activate both Windows and Office 2003. During the reactivation, my original Product keys were no longer valid. I had to call Micrsoft support, spoke to numerous tech support and activation department employees before they gave me a new product key which could be re-activated. I felt like I was getting interrogated as to why I was re-activating the software even though I had valid and legal copies. The other interesting part, every person I spoke to was from India, the the only person not from India was Canadian. It appears as if Microsoft has almost completely off-shored major portions of their company to India.

  31. Explanation is in order by Steeltoe · · Score: 2, Interesting

    I can explain why I use a personal firewall (Kerio PF) on my XP box at home, and what advantages I think it offers over a standalone hardware firewall:

    Control: Even though I have broadband, I want control over what applications connect in and out. When a popup box appears, I am immediately informed what part of Windows or program is trying to access the outside world. I start the PF by locking everything, then clicking yes to everything I want to access the Internet and no to the others (making quick rules). I get a quick and easy overview. This gives an extra control over potential spyware and applications that shouldn't connect remotely.

    While a broadband router is more secure, it's not as easy to configure, it doesn't block on the application-level neither on the device level (for VPNs etc), it doesn't implement "web-filters" or other goodies. A very interesting feature of Kerio is that you can deny, or question wether programs should start up at all.. Nice to lock down Internet Explorer and Outlook that way for extra security.

    Fast & Easy: Getting a pop-up box, I am immediately informed and may quickly make an automatic rule, or specify a more advanced rule. When the ruleset is mature, the boxes disappear.

    While a hardware firewall is quick to setup in the LAN. Setup and configuring simply doesn't compare to a PF with a nice GUI. It's almost as fast as having an automatic firewall. A PF is also more convinient for newbies and lazy users. You don't always know what application or service is using what port, and have to spend time searching. Not everybody thinks it's fun or have the skills to search for port-numbers.

    That said, a broadband router is usually the best solution for a home-network, as you don't need a computer up-and-running all the time to have secure Internet access. But why not have both? In my eyes, not trusting XP or its applications, a PF is absolutely nescessary for control over your computer. Of course, if you don't like the pop-up dialogs, you can turn them off. That's just a GUI-event, you can read the logs instead.

    I'll recommend to stay far away from ZoneAlarm though and use Kerio PF instead. It is very powerful, tidy and secure to use. ZoneAlarm gives me the creeps, what a good example on bad and bloated design!

    To argument against PF I would say that it is very complex and located on the same host, which IS bad for security. It is also harder to know what rules are implemented, maybe the automatic rules are bad or too broad? Also, bad users will easily make the PF worthless by allowing everything. It's certainly no silver-bullet, except for letting users shoot themselves in their feet.

    An additional argument FOR PF is that security can be enhanced by making it easier for clueful users to setup a firewall with high enough level of restriction to prevent most attacks.

    Use what fits the job best, often it's a balance between convenience and security. But as said earlier, you CAN use both!

    I do agree about the false sense of security though, but most people just want to do their work/play, not have a complete network in their home. Many will never be able to figure out a hardware firewall in this lifetime. If you want security, best not use XP either, but OpenBSD or something similar. By being proprietary, XP simply cannot be relied upon and may give a "false sense of security" when everything goes OK for a while.