On Wed, 13 Aug 2003, Steven M. Bellovin wrote: > In message <[EMAIL PROTECTED]>, "Chris > topher L. Morrow" writes: > > >This is the point, atleast I, have been trying to make for 2 years... end > >systems, or as close to that as possible, need to police themselves, the > >granularity and filtering capabilities (content filtering even) are > >available at that level alone. > > > > It's just not possible. > > Believe it or not, I don't much like firewalls. But see slide 5 of a > talk I gave in May, 1994 (http://www.research.att.com/~smb/talks/firewalls.ps > or http://www.research.att.com/~smb/talks/firewalls.pdf) for why we > need them. We'll *always* have buggy code. ... long message trimmed .... I'm not entirely sure where you have shown that 'filtering as close to the end system as possible' is not possible. You mention that in extreme circumstances ISP's might have to step in to save the network from itself, which I agreed much earlier was the case. You did not, however, show that end systems and their local admin gruops can't police their own networks and help to make these problems much more difficult and noisy.
- Re: Port blocking last resort in fight ... mike harrison
- Re: Port blocking last resort in fight against ... Christopher L. Morrow
- Re: Port blocking last resort in fight agai... Jack Bates
- Re: Port blocking last resort in fight ... Christopher L. Morrow
- Re: Port blocking last resort in fi... Jack Bates
- Re: Port blocking last resort in fight against virus Simon Lyall
- Re: Port blocking last resort in fight against ... Petri Helenius
- Re: Port blocking last resort in fight against virus Joe Provo
- RE: Port blocking last resort in fight against virus Temkin, David
- Re: Port blocking last resort in fight against virus Steven M. Bellovin
- RE: Port blocking last resort in fight against ... Christopher L. Morrow
- RE: Port blocking last resort in fight against virus McBurnett, Jim
- RE: Port blocking last resort in fight against ... Stephen J. Wilcox
- Re: Port blocking last resort in fight agai... Mans Nilsson
- RE: Port blocking last resort in fight against virus Mark Segal
- RE: Port blocking last resort in fight against virus McBurnett, Jim
- RE: Port blocking last resort in fight against ... Matthew Kaufman
- RE: Port blocking last resort in fight against ... Randy Bush
- RE: Port blocking last resort in fight agai... Mike Jezierski - BOFH
- RE: Port blocking last resort in fight ... Jason Frisvold
- RE: Port blocking last resort in fight against ... Dave Israel
