<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Microsoft Firewall Bashing&#8230; Didn&#8217;t Agnitum Already Try This?</title>
	<atom:link href="http://www.computerdefense.org/2007/02/microsoft-firewall-bashing-didnt-agnitum-already-try-this/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.computerdefense.org/2007/02/microsoft-firewall-bashing-didnt-agnitum-already-try-this/</link>
	<description>Sharing my thoughts with the world.</description>
	<lastBuildDate>Wed, 16 Nov 2011 02:58:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Tyler Reguly</title>
		<link>http://www.computerdefense.org/2007/02/microsoft-firewall-bashing-didnt-agnitum-already-try-this/comment-page-1/#comment-7708</link>
		<dc:creator>Tyler Reguly</dc:creator>
		<pubDate>Thu, 26 Apr 2007 01:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.computerdefense.org/?p=262#comment-7708</guid>
		<description>Tony,

Gralla isn&#039;t talking about a Wizard... he&#039;s talking about run-time interaction... He wants the user to be prompted... that leads to complacency (btw to imply that Windows is all about complacency is just insulting)... 

There&#039;s no need to hunt and peck for software... Myself and others have made rulesets available that you can easily apply. I have, on numerous occasions, requested additional software that people would like to see rules added for. I&#039;ve added every request I&#039;ve seen. 

I wouldn&#039;t call it time consuming... the list I created, which has every program I could think of that your average user would use and a few extras and it took me 15-20 minutes... If you can&#039;t take 15-20 minutes of your time to ensure that extra bit of protection... then you probably shouldn&#039;t have the extra protection... 

I&#039;d compare it to self defense classes for women... They put in the time and when they are attacked on the street they are prepared to defend themselves and get away from their attacker.... Women who don&#039;t take these classes aren&#039;t... They weren&#039;t wiling to put in the time, most likely because they felt safe and that they didn&#039;t need to invest the time... That was a choice they made... Hopefully this doesn&#039;t come across as a &quot;you get what you deserve&quot; statement because that&#039;s not how I&#039;m intending it... I&#039;m just saying.. how safe you are, is how much time you are willing to invest... This applies to everything.. computers included... and it&#039;s about damn time people realize it.</description>
		<content:encoded><![CDATA[<p>Tony,</p>
<p>Gralla isn&#8217;t talking about a Wizard&#8230; he&#8217;s talking about run-time interaction&#8230; He wants the user to be prompted&#8230; that leads to complacency (btw to imply that Windows is all about complacency is just insulting)&#8230; </p>
<p>There&#8217;s no need to hunt and peck for software&#8230; Myself and others have made rulesets available that you can easily apply. I have, on numerous occasions, requested additional software that people would like to see rules added for. I&#8217;ve added every request I&#8217;ve seen. </p>
<p>I wouldn&#8217;t call it time consuming&#8230; the list I created, which has every program I could think of that your average user would use and a few extras and it took me 15-20 minutes&#8230; If you can&#8217;t take 15-20 minutes of your time to ensure that extra bit of protection&#8230; then you probably shouldn&#8217;t have the extra protection&#8230; </p>
<p>I&#8217;d compare it to self defense classes for women&#8230; They put in the time and when they are attacked on the street they are prepared to defend themselves and get away from their attacker&#8230;. Women who don&#8217;t take these classes aren&#8217;t&#8230; They weren&#8217;t wiling to put in the time, most likely because they felt safe and that they didn&#8217;t need to invest the time&#8230; That was a choice they made&#8230; Hopefully this doesn&#8217;t come across as a &#8220;you get what you deserve&#8221; statement because that&#8217;s not how I&#8217;m intending it&#8230; I&#8217;m just saying.. how safe you are, is how much time you are willing to invest&#8230; This applies to everything.. computers included&#8230; and it&#8217;s about damn time people realize it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony Lucio</title>
		<link>http://www.computerdefense.org/2007/02/microsoft-firewall-bashing-didnt-agnitum-already-try-this/comment-page-1/#comment-7706</link>
		<dc:creator>Tony Lucio</dc:creator>
		<pubDate>Thu, 26 Apr 2007 00:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.computerdefense.org/?p=262#comment-7706</guid>
		<description>I think you miss Gralla&#039;s point, which he made in his article, where he states the nominal home user should not be required to possess the knowledge of a systems administrator to have a decent firewall with minimal outbound protection.  Gralla   is correct in saying the Vista firewall allows ALL outbound connections by default, so a rule must be created to block any (or every) specific program or service.  I agree that wizards for any program foster user complacency (and isn&#039;t that what Windows is all about?).  But shouldn&#039;t minimal protection be afforded to the masses, who will never learn the difference between a NAT and a NAS?  VistaFW can be configured to deny outbound connections by default, and then you must determine which Windows Services have to be allowed in order to minimize the number of ports open on your PC.  I am doing this now, and it is a time-consuming, hunt-and-peck process.  I really don&#039;t mind, I will understand this firewall better, but it is very annoying, especially when all Microsoft had to do was provide a decent rules-based firewall in the first place, a not so very difficult task to begin with.</description>
		<content:encoded><![CDATA[<p>I think you miss Gralla&#8217;s point, which he made in his article, where he states the nominal home user should not be required to possess the knowledge of a systems administrator to have a decent firewall with minimal outbound protection.  Gralla   is correct in saying the Vista firewall allows ALL outbound connections by default, so a rule must be created to block any (or every) specific program or service.  I agree that wizards for any program foster user complacency (and isn&#8217;t that what Windows is all about?).  But shouldn&#8217;t minimal protection be afforded to the masses, who will never learn the difference between a NAT and a NAS?  VistaFW can be configured to deny outbound connections by default, and then you must determine which Windows Services have to be allowed in order to minimize the number of ports open on your PC.  I am doing this now, and it is a time-consuming, hunt-and-peck process.  I really don&#8217;t mind, I will understand this firewall better, but it is very annoying, especially when all Microsoft had to do was provide a decent rules-based firewall in the first place, a not so very difficult task to begin with.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Xierox</title>
		<link>http://www.computerdefense.org/2007/02/microsoft-firewall-bashing-didnt-agnitum-already-try-this/comment-page-1/#comment-7556</link>
		<dc:creator>Xierox</dc:creator>
		<pubDate>Tue, 24 Apr 2007 07:03:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.computerdefense.org/?p=262#comment-7556</guid>
		<description>Good post.</description>
		<content:encoded><![CDATA[<p>Good post.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

