Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Anything wrong with that?

If you want to protect against the kind of attach he hypothesizes to have experienced, yes. Trying to catch root backdoor on your machine by running a firewall on that same machine won't be much help. He called it an "external firewall", so I imagine it was a separate machine that noticed the outgoing requests.



That I understand, but I was wondering if there were inherent problems with the standard FW.


Yes, there are inherent problems with the built-in firewall. The bad guys know it is there so any exploit that they install will likely modify the firewall to cover their tracks. External firewalls can be trusted more than built-in software.


I would be surprised if the built-in firewall even blocks any outgoing connections by default. I'm not on my MBP at the moment so I can't check for sure.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: