<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Comments on 1394</title>
	<link>http://www.metafilter.com/1394//</link>
	<description>Comments on MetaFilter post Comments on 1394</description>
	<pubDate>Thu, 20 Apr 2000 00:11:10 -0800</pubDate>
	<lastBuildDate>Thu, 20 Apr 2000 00:11:10 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Post number 1394</title>
		<link>http://www.metafilter.com/1394/</link>	
		<description>Do security apps like &lt;a href=&quot;https://www.releasesoftware.com/_networkicecorporation/cgi-bin/pd.cgi?page=product_info&amp;pid=P379E44A900000A397F000001&amp;category=Featured&quot;&gt;this one&lt;/a&gt; actually work?  Anyone here with a DSL or ISDN, or other &quot;always on&quot; connections, have any tips on security at home?</description>
		<guid isPermaLink="false">post:www.metafilter.com,2000:site.1394</guid>
		<pubDate>Wed, 19 Apr 2000 23:31:44 -0800</pubDate>
		<dc:creator>milhous</dc:creator>		<category>computers</category>		<category>security</category>		<category>DSL</category>		<category>ISDN</category>		<category>brokenlink</category>
	</item>	<item>
		<title>By: bvanveen</title>
		<link>http://www.metafilter.com/1394/#3752</link>	
		<description>I have dsl at home and have had a pretty good experience with &lt;A HREF=&quot;http://www.symantec.com/sabu/nis/&quot;&gt;Norton Internet Security 2000&lt;/A&gt;. Basically it sits in your tray and monitors incoming and outgoing transactions based on the level of protection, 3 of them, that you select. I have had to disable it a couple times for specific reasons, but overall I am very satisfied with it. It also has a built in banner ad blocker if you choose to activate it. They have a 30 day trial version and you can also download the fully functional version after purchase. Good luck and feel free to email me with any specific questions.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3752</guid>
		<pubDate>Thu, 20 Apr 2000 00:11:10 -0800</pubDate>
		<dc:creator>bvanveen</dc:creator>
	</item>	<item>
		<title>By: Yeet</title>
		<link>http://www.metafilter.com/1394/#3754</link>	
		<description>I have a cable modem at home and I am using &lt;a href=&quot;http://www.zonealarm.com&quot;&gt;ZoneAlarm&lt;/a&gt; for a while. I am very satisfied with the software.
It is easy to configure and use. And the most important of all, it is free.
BTW you can check the security of
your computer&apos;s connection by going to &lt;a href=&quot;http://grc.com/default.htm&quot;&gt;grc.com&lt;/a&gt; and clicking on the ShieldsUP icon.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3754</guid>
		<pubDate>Thu, 20 Apr 2000 00:50:02 -0800</pubDate>
		<dc:creator>Yeet</dc:creator>
	</item>	<item>
		<title>By: Bryan</title>
		<link>http://www.metafilter.com/1394/#3757</link>	
		<description>I notice these are PC apps...what options exist for the Mac platform, or are any needed?  My apologies for my total ignorance on the subject.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3757</guid>
		<pubDate>Thu, 20 Apr 2000 02:26:04 -0800</pubDate>
		<dc:creator>Bryan</dc:creator>
	</item>	<item>
		<title>By: Dean_Paxton</title>
		<link>http://www.metafilter.com/1394/#3759</link>	
		<description>Black Ice Defender is an excellent program for your home/PC needs.  I can say that I do like this one, I&apos;ve tested and evaluated many, many of these programs and this is tops.  It gives a lot of false positives, but it&apos;s really kind of fun to watch...

For Mac users, I&apos;ll check with some of my Mac friends, I know a couple of security consultants that have Mac experience.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3759</guid>
		<pubDate>Thu, 20 Apr 2000 04:37:58 -0800</pubDate>
		<dc:creator>Dean_Paxton</dc:creator>
	</item>	<item>
		<title>By: Succa</title>
		<link>http://www.metafilter.com/1394/#3761</link>	
		<description>Best solution: get a firewall/proxy server.  You&apos;ll need nothing more than a cheap 486 or Pentium, Linux, and some free software.  You&apos;ll never have to worry again.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3761</guid>
		<pubDate>Thu, 20 Apr 2000 07:26:38 -0800</pubDate>
		<dc:creator>Succa</dc:creator>
	</item>	<item>
		<title>By: Steven Den Beste</title>
		<link>http://www.metafilter.com/1394/#3762</link>	
		<description>I have a cable modem and I completely agree with the recommendation about Norton Internet Security 2000. I used it when it was &quot;AtGuard&quot;, before Symantec purchased it, and I upgraded recently.

One of the morel surprising things is just how often people try to taste my system looking for various trojans. I would say that I typically get a crack attempt about five times per week, and about a month ago I got hit seven times in one day -- by seven different people.

NIS2K is superb. You definitely don&apos;t need a second computer to act as a firewall.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3762</guid>
		<pubDate>Thu, 20 Apr 2000 07:32:17 -0800</pubDate>
		<dc:creator>Steven Den Beste</dc:creator>
	</item>	<item>
		<title>By: jbeaumont</title>
		<link>http://www.metafilter.com/1394/#3765</link>	
		<description>A lot of times these programs open up ports on your machine in order to scan them.  These ports normally would be shut off, but these programs open them up...
</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3765</guid>
		<pubDate>Thu, 20 Apr 2000 08:05:44 -0800</pubDate>
		<dc:creator>jbeaumont</dc:creator>
	</item>	<item>
		<title>By: jbeaumont</title>
		<link>http://www.metafilter.com/1394/#3766</link>	
		<description>Oh one more thing - the best thing you can do for your home security on your machine is (if you&apos;re running windows) to turn off file and print sharing.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3766</guid>
		<pubDate>Thu, 20 Apr 2000 08:06:18 -0800</pubDate>
		<dc:creator>jbeaumont</dc:creator>
	</item>	<item>
		<title>By: Dean_Paxton</title>
		<link>http://www.metafilter.com/1394/#3767</link>	
		<description>jbeaumont is right, it depends on which M$ product you are running, but these ports are closed by default with a few exceptions.  I personally don&apos;t use anything commercial, I use a freeware port scanner that keeps an eye on the ports I tell it to, but preforms no actions.  

If I saw someone tapping on those ports, and my hard drive was spinnig wildly, I&apos;d probably just yank the PC off the network!  Sure is hard to hack then...  To find out which ports to be wary of, check out &lt;a href=&quot;http://www.infosyssec.com/&quot;&gt;Infosyssec&lt;/A&gt;, &lt;a href=&quot;http://www.securityfocus.com/&quot;&gt;Security Focus&lt;/a&gt;, or &lt;a href=&quot;http://www.infowar.com/&quot;&gt;Infowar.com&lt;/a&gt;.  Finally, the Sans Institute has a &lt;a href=&quot;http://www.sans.org/newlook/resources/IDFAQ/ID_FAQ.htm&quot;&gt;wonderful resource&lt;/a&gt; on intrusion detection.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3767</guid>
		<pubDate>Thu, 20 Apr 2000 08:26:51 -0800</pubDate>
		<dc:creator>Dean_Paxton</dc:creator>
	</item>	<item>
		<title>By: baylink</title>
		<link>http://www.metafilter.com/1394/#3770</link>	
		<description>I&apos;m surprised no one&apos;s mentioned Gibson Research&apos;s scanner page.  Go to &lt;a href=&quot;http://greenspun.com/ct/baylink/META-FIREWALL?send_to=http://www.grc.com&quot; onMouseOver=&quot;window.status=&apos;http://www.grc.com&apos;; return true&quot;&gt;Shields Up&lt;/a&gt;, and it will scan your machine for the most common vulnerabilities.  

Note: if, as Succa suggests, you run a small, cheap Linux box (a 386/40 will do wuite handily) as a masquerade router, not only will the outside world be almost completely unable to hurt you (assuming you lock the router down correctly), but you&apos;ll be able to run multiple client behind your cable modem without the carrier noticing.

One other scanner I&apos;ve recently run across is &lt;a href=&quot;http://greenspun.com/ct/baylink/META-FIREWALL?send_to=http://dev.whitehats.com/scan/ddos/ddos.html&quot; onMouseOver=&quot;window.status=&apos;http://dev.whitehats.com/scan/ddos/ddos.html&apos;; return true&quot;&gt;The Whitehats Distributed Denial of Service scanner&lt;/a&gt;.  I must admit to being unfamiliar with them; Jerry Pournelle mentioned them in his &lt;a href=&quot;http://greenspun.com/ct/baylink/META-FIREWALL?send_to=http://www.jerrypournelle.com/mail/currentmail.html&quot; onMouseOver=&quot;window.status=&apos;http://www.jerrypournelle.com/mail/currentmail.html&apos;; return true&quot;&gt;mail column&lt;/a&gt;.

(I&apos;d observe that Jerry Pournelle is an ex-Byte columnist and science fiction writer, for those who didn&apos;t know that, but I&apos;m sure some snide bastard^W^Wkind soul would say &quot;no shit&quot;... so I won&apos;t.  :-)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3770</guid>
		<pubDate>Thu, 20 Apr 2000 08:51:08 -0800</pubDate>
		<dc:creator>baylink</dc:creator>
	</item>	<item>
		<title>By: milhous</title>
		<link>http://www.metafilter.com/1394/#3785</link>	
		<description>When i started this post, i forgot to ask -- benefits or downsides to using NT with all of this crazyness.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3785</guid>
		<pubDate>Thu, 20 Apr 2000 10:39:29 -0800</pubDate>
		<dc:creator>milhous</dc:creator>
	</item>	<item>
		<title>By: Steven Den Beste</title>
		<link>http://www.metafilter.com/1394/#3790</link>	
		<description>If anyone is interested in finding out just how secure their particular system is, there are couple of sites which will make a benign attempt on your system (at your request and with your permission) to see just how much you are revealing. No matter what, they cause no harm. The testing process is completely safe.

&lt;a href=&quot;http://www.secure-me.net/secureme_go&quot;&gt;This is the better one&lt;/a&gt; but you go into a queue and it may take a couple of hours for them to get to you. They send you email when they&apos;re done. You have to leave your computer online until they get to you.

&lt;a href=&quot;http://grc.com/default.htm&quot;&gt;This one is less comprehensive&lt;/a&gt; but it runs interactively and reports to you as it finishes individual steps of the process. Click the &quot;Shields Up!&quot; link.

My Win 98 system running &quot;Norton Internet Security 2000&quot; passed both tests with flying colors; I got top marks.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3790</guid>
		<pubDate>Thu, 20 Apr 2000 11:11:24 -0800</pubDate>
		<dc:creator>Steven Den Beste</dc:creator>
	</item>	<item>
		<title>By: cCranium</title>
		<link>http://www.metafilter.com/1394/#3810</link>	
		<description>Re: Succa&apos;s post

Proxy/Firewall solutions are definetely the best, but rather than a Linux distro, consider OpenBSD (www.openbsd.org).  It&apos;s quite probably the least hackable system out there, and unlike most Linux distros, it comes with everything locked down, so if you&apos;ve never used a Unix-like OS, you&apos;re secure-by-defualt.  If you want to open a specific port, you have to do it manually.

re: NT

I don&apos;t know how well NT works with the various security utils out there, but if NT or Win2000 are an option for you, set your filesystem to NTFS, dedicate a specific directory that can be open to the world, and modify the permissions for the rest of your computer.  It&apos;ll be difficult enough for crackers to get in that you&apos;ll avoid most of the script-kiddie cracking software out there, and it takes very little time to do.  Anyone wanting to get into your box is going to have to do some research, and if they&apos;re willing to research, they&apos;ll already know about any bugs and exploitations in any software out there.

No matter what security solution you use, make sure you&apos;ve got a good virus scanner, one that checks all data coming in (Norton VirusShield readily comes to mind) and keep it updated.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3810</guid>
		<pubDate>Thu, 20 Apr 2000 14:46:52 -0800</pubDate>
		<dc:creator>cCranium</dc:creator>
	</item>	<item>
		<title>By: dhartung</title>
		<link>http://www.metafilter.com/1394/#3828</link>	
		<description>I believe they&apos;re essential. Either run something like BlackICE, Norton, or the free ZoneAlarm (new version 2.1 out, now it makes a text log), or have a firewall in your router/bridge/gateway depending on how your broadband access is configured (sometimes you don&apos;t have any choice).

I&apos;m using ZoneAlarm at home, and the only problem is too many false positives. I hope 2.1 is a tad better behaved. At a customer, I have a Netopia router (DSL modem) with firewall capabilities, and I&apos;ve got it locked down pretty good. You can also buy boxes that will do this (say, if you want to share that DSL connection).</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3828</guid>
		<pubDate>Thu, 20 Apr 2000 18:46:21 -0800</pubDate>
		<dc:creator>dhartung</dc:creator>
	</item>	<item>
		<title>By: plinth</title>
		<link>http://www.metafilter.com/1394/#3846</link>	
		<description>If you have DSL or Cable in an always on configuration, you mighr consider &lt;A HREF = &quot;http://www.linksys.com/scripts/features.asp?part=BEFSR41&quot;&gt;Linksys&apos; Router&lt;/A&gt;.  It&apos;s about $160(US) has 4 ports and is configurable through a web browser.  It&apos;s about as cheap, much smaller, and much easier to maintain than a dedicated 486 box to do the same thing.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3846</guid>
		<pubDate>Fri, 21 Apr 2000 05:51:02 -0800</pubDate>
		<dc:creator>plinth</dc:creator>
	</item>	<item>
		<title>By: baylink</title>
		<link>http://www.metafilter.com/1394/#3852</link>	
		<description>Um, duh.  Oops; someone *had* mentioned Shields UP before I did.  I guess I&apos;m blind this week.  

Thanks for not jumping my crap, folks.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3852</guid>
		<pubDate>Fri, 21 Apr 2000 07:43:31 -0800</pubDate>
		<dc:creator>baylink</dc:creator>
	</item>	<item>
		<title>By: Dean_Paxton</title>
		<link>http://www.metafilter.com/1394/#3869</link>	
		<description>&lt;a href=&quot;http://security.ellicit.org/programs/gnit_rc1.zip&quot;&gt;GNIT&lt;/a&gt; is what I use for Windows NT, they just released the new version a week or so ago.  It&apos;s free, it&apos;s all set for the &quot;danger&quot; ports, and it&apos;s cool.  That&apos;s my advise for ANY WinNT/2000 box.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2000:site.1394-3869</guid>
		<pubDate>Fri, 21 Apr 2000 11:31:58 -0800</pubDate>
		<dc:creator>Dean_Paxton</dc:creator>
	</item>
	</channel>
</rss>
