Re: Which is better firewall -- Win XP or Comcast?

From: Bruce Chambers (bruce_a_chambers_at_h0tmail.com)
Date: 01/10/05


Date: Mon, 10 Jan 2005 06:19:48 -0700

Jack wrote:
> Which provides the better firewall -- Windows XP or Comcast? I've got to
> disable the Windows XP firewall on my XP machine if I want to use the
> Comcast one.
>
> Jack
>
>

    WinXP's built-in firewall is merely _adequate_ (that's far short of
"really very good") at stopping incoming attacks, and hiding your ports
from probes. What WinXP SP2's firewall does not do, is protect you from
any Trojans or spyware that you (or someone else using your computer)
might download and install inadvertently. It doesn't monitor out-going
traffic at all, other than to check for IP-spoofing, much less block (or
at even ask you about) the bad or the questionable out-going signals. It
assumes that any application you have on your hard drive is there
because you want it there, and therefore has your "permission" to access
the Internet. Further, because the Windows Firewall is a "stateful"
firewall, it will also assume that any incoming traffic that's a direct
response to a Trojan's or spyware's out-going signal is also authorized.

     ZoneAlarm, Kerio, or Sygate are all much better than WinXP's
built-in firewall, and are much more easily configured, and there are
free versions of each readily available. Even the commercially
available Symantec's Norton Personal Firewall is superior by far,
although it does take a heavier toll of system performance then do
ZoneAlarm or Sygate.

        I can't say much about Comcast's firewall, except to say that I'd not
want to trust an unknown 3rd party to hold the keys to my house.

-- 
Bruce Chambers
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html
You can have peace. Or you can have freedom. Don't ever count on having 
both at once. - RAH


Relevant Pages

  • Re: Guide to secure installtion of IIS 5
    ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.inetserver.iis.security)
  • Re: Is secedit.exe left by a hacker?
    ... > tested on port 445. ... > I have a Linksys router that I use as a firewall to my ... Secedit.exe is the name of a legitimate Windows file, ... investigate the files on your computer - antivirus with the latest updates ...
    (microsoft.public.win2000.security)
  • Re: Is secedit.exe left by a hacker?
    ... >> tested on port 445. ... >> I have a Linksys router that I use as a firewall to my ... >investigate the files on your computer - antivirus with ... >windows and everything else. ...
    (microsoft.public.win2000.security)
  • Re: How to Maintain an IIS Server?
    ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
    (microsoft.public.inetserver.iis.security)
  • Re: password protection
    ... and cable] and should really consider Windows 2000 / XP. ... sure you're also running antivirus and firewall, ... Internet] to bypass this security. ...
    (microsoft.public.security)