Is Obsolescence Good Computer Security?
caesar-auf-nihil asks: "I was recently considering a switch from dial-up to something faster (either cable or DSL) but my friend recommended against it since he said I was more secure staying with Dial-Up. His argument was that my connection's slowness and 'not always on' connection gave me better security since I was less of a target for many security threats. Now, I have never gotten infected, nor do I believe my machine is infested with spyware and/or controlling programs as it runs fine, but I wonder if the obsolescence argument is really good or not. Does Dial-Up really protect you or is this a false sense of security and I should just go ahead and pick a faster service and make sure my firewall is a good one and my virus definitions are always up to date?"
Its only true in the way that you will be mugged less if you walk naked down one back alley every night instead of twenty. Go ahead and get the faster connection, and get a hardware device (nat box at least, a real firewall would be better though) between you and your uplink line, and you'll be better off than you were before. You can't do that (using common hardware) with your modem in the first place.
No, is the simple answer.
You could get hit by a worm just as easily - they attack by IP address and are indescriminate about where they attack - they don't care how fast your connection is.
As for spyware and the rest, if you're using a slower net then probability is that you'll browse less and be subjected to less risk, but in general the argument used is complete and utter rubbish - there's no additional security to be gained by dialup.
Jolyon
Please read my Canon EOS tech blog at http://www.everyothershot.com
"Don't cruise the net as root, or the admin user on a windows box. If you have to use Windows as your OS get a real firewall product, hardware even better than software, don't run unnecessary services, don't use IE unless its for the MS site itself. Don't use Outlook. Keep your system patched. Avoid sites like the free game and pr0n sites that are forever infesting computers. Get a useful book on security. Keep proper backups so that you can recover if all else fails"
Dude, wow, wow, wow... Is all this supposed to make him switch to broadband with an easier mind?
You don't need to freak him out. All this can be said in a much simpler fashion:
- Leave autoupdates on your windows ON, it'll take care of itself
- Download and install : ZoneAlarm for your firewall, and AVG Free for antivirus. Both free, user friendly and do their job.
- Download and install Firefox for your browsing needs.
And dial-up is indeed fake sense of security, so there.
That's
Not to mention you can't exactly throw a Linksys router (hardware firewall) inbetween you and the wall when you are on dialup.
Perhaps you've never seen one of these.
We used to sell them to customers too far out in the sticks to get anything but dialup but whom wanted extra security or the ability to network multiple machines. We even had an entire office once that did all of their billing to an AS/400 via a dialup. It was all terminal based so the dialup worked just fine. At peak hours they had 11 people all doing billing at the same time. And you know what's really sad? They could do it faster on that terminal system then any GUI that has come since.
Ditto when I worked in the insurance field. We absoletely hated the new version of our agency management system when they moved to Windows. When will interface designers learn that it's faster if you don't have to take your hands off the keyboard every three seconds?
I want peace on earth and goodwill toward man.
We are the United States Government! We don't do that sort of thing.
Generally speaking, sharing any connection is best achieved with an external router and not via a computer. That way if your Gentoo machine falls over or you need to reboot, it won't take out the connection for everyone else. YMMV.
Generally speaking, sharing a connection with Linux will give you useful hands on experience with iptables and it's a million times more flexable then any hardware router and about $60 cheaper.
I want peace on earth and goodwill toward man.
We are the United States Government! We don't do that sort of thing.
In a home environment, this is likely not a real problem. In a business environment, anything beyond about 15 active users is usually too much for a Linksys-type router, since the processor and memory capabilities of these are usually pretty low. I think Netgear has a few for small/medium businesses, but if all you want is a NAT box, Linux/*BSD work quite well on some pretty low-end hardware. 100 users on a DSL/Cable circuit could be handled by an old Pentium 133 picked up on eBay for $25. At work, we have a FreeBSD box (though on a much faster Opteron 244) doing NAT, firewalling, monitoring, load balancing, and intrusion detection for 2 Gigabit segments, 3 T1s, and a Frame Relay circuit. On average, this box is at 0.4% CPU utilization when you aren't actively monitoring something.
--That's the point of being root, you can do anything you want, even if it's stupid.
I've heard this argument before (no really). On the face of it, it has something going for it - OK, now why is it wrong?
;-)
Well if the PC isn't connected, it can't download updates to Windows (patches) and its Anti-Virus/Firewall/Anti-Spam etc. So when it is connected it will probably be a poor position security wise. From a practical perspective has anyone tryed to keep a PC "all patched up" over dial-up? Takes forever to download the patches, it isn't actually practical. So no, getting proper security utilities in place (and setting them up correctly) then connecting via ADSL (or similar) will probably improve the security. One tip though - don't get your friend to set it up.
After I switched my father to Linux, I kept an eye on the logs.
Time from dial up connection to blaster hit: 8 seconds
Time from dial up connection to Nimda Hit: Two and a half minutes
So no, it's not safer.
Downloading the tools to correct a worm or virus you get also take longer, leaving your machine more vulnerable while you are online longer retrieving the tool to fix the worm. Also as mentioned, dial up users are natively discouraged from updating their systems since updates (win-doze, anti-virus, up2date, yum, etc..) are larger files designed for broadband users, meaning they are much wider open, and will be wider open for a longer period while they are online.