Vista Firewall to be Crippled
UltimaGuy writes "The firewall in Windows Vista will, by default, have half its protection turned off because that is what enterprise customers have requested, according to the software giant. The firewall will be set to only block incoming traffic even though it will be capable of blocking outgoing traffic. Microsoft also claims that configuring the Vista firewall to block outgoing connections from rogue applications and malware will require a varying degree of technical knowledge, depending on each user's security requirements."
Given the vast number of home users MS has, this would seem to make sense. Really, how many *average* home users know what ports their programs use? Further, how many of those customers will want to fight with their firewall to get things working before they get frustrated and just turn it off? Turning the firewall off is far worse than having a firewall that only blocks inbound connections.
I do hope that MS continues to allow you the ability to work with the firewall on an application level. It's much simpler to browse to "program xyz" and tell the firewall to allow whatever ports this program needs. Determining and then defining UPD vs TCP and ranges of ports is just not going to work for most non-technical people.
Lastly, I think the request of the larger corporate customers and government makes sense. They don't want to micro-manage their machines.
I don't understand the complaint here. MS is listening to their customers. Supposedly that is a good thing for a business to do, of course there is a limit. Secondly MS probably doesn't have a smoother way to make managing the firewall any easier than anyone else out there. It's a tough problem, especially for non-technical users.
Blocking outbound by default is mostly going to protect the rest of the internet from your owned box spamming/ddosing/etc them. (I guess you're outbound connection could get hosed too).
On a side note, from TFAYes MS, its hard to setup properly - thats why you have to have it turned on by default
At least it's better then Apple's Firewall (turned off by default, PITA to block outbound traffic).
There are shills on slashdot. Apparently, I'm one of them.
Don't most enterprise customers use scripted installs/images? Why would the default configuration matter at that point?
because that is what enterprise customers have requested
So, if Microsoft listens to their customers, they make slashdotters angry but if they block bittorrent, they make slashdotters angry.
I think that I'm starting to get this...
More
Whenever I install a firewall that will block outgoing applications, and make sure everything needed is allowed already such as IM, email etc. The first thing a user does when they see that screen is click "Yes always allow Trojan.I.Steal.Credit.Card.Numbers.and.kick.puppie s.Trojan"
:)
Atleast the incoming is blocked like it should be, it would be nice if there was a way to flash bright red so obnoxiously, and make the user think for a second. Like how firefox makes you wait before clicking yes. Possibly by moving the yes button around and saying "YOU PROBABLY DONT WANT TO ALLOW THIS" and then repeat. "ARE YOU ABSOLUTELY POSITIVE"
then deny it regardless of what the user says
The phrase "more better" is acceptable English. suck it grammar Nazis
Crippled would be if the functionality were not present, or so badly broken that it does not work properly. Including the functionality but not enabling it by default is not crippling. Microsoft has a long history of enabling wide-open security settings by default, so this is really nothing new, if anything it's halfway to an improvement.
You see? You see? Your stupid minds! Stupid! Stupid!
Yeah, it was the "enterprise customers" all right: I imagine the phone calls from Symantec, Kaspersky, FSecure et al: hey Microsoft, leave them damn ports open or we'll outta business pretty soon! (relax. It's just a lame joke)
Hello! I'm a disaster waiting to happen!
I believe MS outlined 7 different versions for different markets... home, enterprise, small business, entertainment center, etc. Why wouldn't they configure the firewall in each of these by default to be what's appropriate for
its target market, rather than letting the desires of the Fortune 500 wag my
mother's machine in a less than completely safe way? Given the world's recent
experience with various forms of malware, erring on the side of safety certainly seems to be justified.
Why the hell would anyone other than a dial-up user need to have a firewall enabled under Windows? Everyone with broadband should have some other device between their computer and the big, bad internet to handle firewall duties. Corporate networks had better damned well have some security at the gateway to the WAN/internet.
One would expect that Entreprise customers could set this anyway they want via Group Policy
I wouldn't call this crippled. All you have to do is turn it on. I guess that my copy of Civilization 4 is crippled too, because I had to install it.
Seriously, though... blocking incoming traffic is more than half that battle. It is my understanding that blocking outgoing traffic is mainly useful after your system has been compromised.
You know a software is off to a bad start when the product isnt even out yet and they're already talking about bugs & features.
If you look like your passport photo, you're too ill to travel. - Will Kommen
I think that blocking incoming traffic is by far the most important thing on Windows boxes. We don't want another Code Red/Nimda.
Who here, honestly blocks outgoing traffic too on their home networks? I could, but I don't bother. Why? I run a tight enough ship to know that there won't be weird traffic going out, and I can't be bothered with the extra admin needed to keep everything happy and working.
Get your own free personal location tracker
Up to a point, I have to agree with you. The average home user is just not used to the level of annoyance it takes to train and maintain an outgoing firewall. I installed ZoneAlarm on my parent's computer, and get calls or emails routinely asking if they should OK a particular program's desire to access the internet. And many corporate users don't really care about the defaults - they are going to have IT manage it anyway.
But I have to ask, what is the point of Microsoft splitting Vista into however many different versions if not to have a granular response to problems like this? Many of XPs problems are related to its homogeneity...
Using plain ol' text since 1968
So why have 21 different versions of Vista if NOT to have a consumer version with as much protection as possible with as few services running as possible? A business office version you assume will be configured by an IT guy that has difficult to admin - but very flexible and detailed - firewall options. Yes.
But to not a have a 1 button "Protect me on the internets" button for grandma? That's MS effectively selling off its consumer base to big corporations at their request.
=Tod
Bill Gates - Creationist?!?
1) Most home users get annoyed at having to click on the options to allow outgoing connections, and they generally aren't concerned about applications "calling home."
2) The biggest culprit for applications that call home is Microsoft, and the Windows firewall doesn't block Microsoft applications anyway. (The biggest reason I have a 3rd-party firewall is to block outgoing connections from IE, Explorer, and Windows Media player)
3) Serious attacks come from incoming connections (or Trojans, which a traditional firewall can't stop anyway.) so this doesn't matter for them.
Given that Microsoft has announced different versions of Vista for enterprise, home users, power users and so on, why would they cripple the firewall across the entire line? It seems to me that with all the versions they're planning, it would be a simple matter to keep the firewall off for those versions sold to enterprise customers, and leave it alone for everyone else. And speaking as someone who has had to deal with the fuckery of the windows firewall in an enterprise environment, I can't say I'm disappointed by that.
Some system level protection is always important(like starting off with a secure OS!) however I can tell you from my experiences remotely managing XP systems that the local firewall can be a major headache. In our office we have hardware based firewalls or firewall feature set routers at/on every subnet router. Its much easier managing a handful of hardware devices versus hundreds of individual software based firewalls that don't work half the time anyway.
crippled? how about "industry standard for home and light commercial use"?
what's wrong with INBOUND:BLOCK ALL - OUTBOUND:ALLOW ALL?
every NAT/router/firewall/shiny magic internet thing i;ve seen, oh, in the last 7 eons of mankind's glorious history is set up just so.
Default outbound blocking wouldn't matter in the home environment. The most likely malware targets are all running as Admin anyway, so smarter malware will just add themselves to the allowed list.
On a technical side however, I don't see why this is a yes-or-no proposition. What would prevent the installer to ask a question like: "Do you want the firewall to block outgoing traffic? Yes/No" (with some blurb explaining to non-geeks why they might/might not need it, what implications it might have, and how to change one's decision later on).
the other half by design
First of all, inbound is not even half of the problem. Considering the recent development of malware, outgoing is by far the prefered way of attacking for today's malware. Simply because of the increasing number of NAT routers.
Second, I HOPE AND PRAY that they FINALLY add a "delay" to the "allow application to open connection" button. There's almost no current malware that does NOT create a thread to check in 5 ms intervals whether one of those allow-request windows is open and answer it in the prefered way for the malware before opening a connection, to make sure they get permissions.
If this loophole isn't closed, any MS-firewall in learning mode is as good as no firewall at all. Actually it would be worse, because it gives you a false sense of security where there is none.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Vapor OS, Vapor Firewall. makes sense to me.
at least the "object file system" promised in Cairo will be there. won't it?
I also hear they will be shipping the stability promised in Window 95
time to start lining up at Fry's
OEM customers (e.g., Dell, HP, Gateway, etc) often ship their PCs with dozens of what I call "shovel-ware" (trial versions of useless software that OEMs pile on heaps on the desktop). Often this shovel-ware likes to call home occasionally to notify you of "new updates available for download" and other such nonsense.
I'm sure it's very embarrasing (and costly) to the OEMs when they get support calls from their own customers when the microsoft outbound firewall blocks the shovelware and flashes up a dialog box. So they probably just asked microsoft to ship the firewall so that the outbound firewall doesn't validate the application (which makes it too easy for end users to "accidentally" disable the shovelware and too easy for experienced users to get a list of all the shovelware polluting their machines from the "allowed" list and uninstall it). Of course microsoft doesn't want to have too many configs out there, so they just make this the default setting out of the box.
</TINFOILHAT>
Sure microsoft is listening to their customers, it's just their OEM customers...
Let's sacrifice the quality for people who don't know what they need to please those that don't know what they want!
Sarcasm!
"I'm not religious, but at the same time I don't get why science always has to have something to prove."
I always come to slashdot with the broad, and sometimes naive assumption that the articles provided will be neutral. Whether or not the responses to these articles are neutral is another story, and any biased there towards OSS, away from MS, agaisnt Apple, or whatever, is just fine in my book. Thats what makes the internet great.
;)
That said, I strongly detest the wording of this headline and the tagline below it. Especially from CmdrTaco.
When I read the topic in RSS, I thought that some features would be removed from the exisitng firewall, or that some key features would require a paid subscription to be activated. When I read the summary, however, I realized that was not the case. The attitude on slashdot towards Microsoft (as well as any other non-OSS business model that seems to work) is jaded and negative enough without being given a predisposition via headlines like this.
The summary in 1.5: Negative, misleading headlines need to go.
So, mod me down for offtopic, mod me down for Troll, mod me down for Redundant. My Karma can take it. Or, if you agree, mod the other way
Right now I get mad props at work for keeping bagel, netsky, and mydoom at bay through attachment and AV blocking, spam filtering, and a little bit of shell scripting. Here I was afraid that those would go away and I'd have to find something else to justify my existence within the next couple years. Now it looks like I'm in good shape til at least 2010. Thanks Microsoft!
ps - Other AV programs probably do this, but in case anyone's interested the firewall built into McAfee VirusScan Enterprise v8 blocks SMTP and IRC communication outbound by default unless the executable firing up the communication belongs to a specific set of known email and IRC clients. Good times...
Yes, my only tool is a hammer. And you're starting to look like a nail.
whine, whine again.
"Do you wish to allow 'Amanda Peet Naked.You_must_allow_to_see_her_naked.jpg.scr' to access the internet?"
[yes] [no] [cryptic help page]
-M
when you see the word 'Linux', drink!
So it's not really crippled, it can be configured for outbound protection. Maybe the "varying degree of technical knowledge" implies that it's not as straightforward as a nice GUI configuration window and hence "crippled" in that respect.
Saying it is "crippled" would imply that the outbound protection code exists, but it is permanently disabled, i.e. not configurable at all.
Government's idea of a balanced budget: take money from the right pocket to balance...oh who am I kidding?
It's good to see level-headed, non-biased Slashdot articles. Crippled would mean that the firewall doesn't even have the ability to block outgoing data, it does, it's just not enabled by default.
This just in, most Linux distributions don't have firewalls enabled by default. News at 11!
OK, folks...at what point does the Windows bashing just become so silly that it's wrong. Oh, wait...we reached that point long ago.
/. can do is whine that it isn't turned on by default. Last time I checked, lots of Linux distros come setup this way as well, yet I don't see anyone moaning about that.
The headline is just wrong. The Vista firewall is no more "crippled" than iptables is "crippled" in Fedora. Microsoft is making the default behavior identical to the XP firewall, but getting bidirectional port filtering/blocking is merely a matter of turning it on. The whole "requiring various degrees of technical expertise" is a ridiculous red herring coming from a website where Linux users constantly preach their technical superiority to the common lowly user. Pardon me, would you like some elitism with that pedantic whine?
For the vast majority of users, bidirectional firewalling is overkill. For those who want it, it can be turned on. This isn't a story, it's propaganda masquerading as news. I swear, Microsoft tries to improve things (adding the ability to do outbound blocking), and all
Microsoft is the competitor, not the enemy. Quit making this whole crusade a personal affair and this silly anti-MS bias will disappear.
In the end they will lay their freedom at our feet and say to us, Make us your slaves, but feed us. - Fyodor Dostoyevsky
I work at an ISP doing Tech Support.
On a daily basis, I get calls from users of Norton Internet Security or McAfee Security Center (or whaever "I don't know, whatever came with my computer") who, for some reason, can't get Internet Explorer/Outlook Express to work. They don't know what a firewall *is* let alone how to configure it.
If I suggest they turn of that firewall and try it, everything is suddenly happy again.
Many of them don't understand. "It worked fine yesterday/last week/last year and I haven't changed anything..."
I specifically despise the Norton firewall as it seems to be the most popular problem causer.
I am glad that Microsoft isn't turning this feature on by default because many clueless lusers will accidentally block the programs that they're trying to use and then not understand why it doesn't work anymore.
Frequently these users try to blame us at the ISP, not realizing that it's their own fault. Firewalls are my most frequent frustration, and I'm glad this one will behave the way it will.
Naturally.
That's not ZoneAlarm's fault, part of its basic functionality is to prompt the user to see if it's ok to allow the traffic. The fact that the user is an ignorant moron is no reason to remove a layer of protection. MS's enterprise customers have requested this because upper management is tired of the prompts to allow traffic, and doesn't understand (or care) about why they're there.
The user cares and understands why ZoneAlarm is there: he does not want his system infected. The problem is that the user does not know the internal workings of their applications or OS, and thus are not in the position to really judge which connections are good and which are bad.
This is where ZoneAlarm errs: the user should not HAVE to know which IP addresses and port numbers are bad. Heck, as a techie, even I dont even want to have to know -- I have more interesting things to do. There are obviously patterns which allows us to judge roughly which connections to block. But ZoneAlarm should detect those patterns (heck, maybe even by quering a zonealarm.com server or your-techie-nephew.com for info), and tell the user what he DOES want to know: the probability the connection is dangerous.
If ZoneAlarm is meant for the general audience, it fails miserably in terms of GUI. It also wouldn't hurt if applications could inform the user and ask for a retry if the firewall blocks the connection. The firewall should then of course also support that in a user-friendly way, instead of browsing through a zillion settings. As previous posters pointed out, users now generally quickly learn to accept everything to not having to bother their nephew every single damn time, otherwise stuff will probably break.