Frank said:
You are correct, but if you keep your system clean and block incoming,
you won't have any outgoing to block.
While that's technically true, Frank, I don't really think it's a
particularly wise stance, security-wise, particularly since all too many
of the people reading these newsgroups are because precisely because
they don't know how to keep their computers secure.
As you know, WinXP SP2's firewall does not protect the user from any
Trojans or spyware that he/she (or someone else using his/her computer)
might download and install inadvertently. It doesn't monitor out-going
traffic at all, other than to check for IP-spoofing, much less block (or
at even ask the user about) the bad or the questionable out-going
signals. It assumes that any application the user has on his/her hard
drive is there because he/she want it there, and therefore has his/her
"permission" to access the Internet. Further, because the Windows
Firewall is a "stateful" firewall, it will also assume that any incoming
traffic that's a direct response to a Trojan's or spyware's out-going
signal is also authorized. Also, remember that antivirus applications
are primary re-active in nature; they won't be able to identify and/or
block a virus, Trojan or worm until _after_ the malware has been
discovered and new virus definition files distributed.
Where computer security and privacy of personal data are concerned,
I have to strongly recommend a belt-and-suspenders approach. ZoneAlarm,
Kerio, or Sygate are all much better than WinXP's built-in firewall, and
are much more easily configured, and there are free versions of each
readily available. Even the commercially available Symantec's Norton
Personal Firewall is superior by far, although it does take a heavier
toll of system performance then do ZoneAlarm or Sygate. Having a
secondary means of detecting the presence/activities of potential
malware is simply common sense.
--
Bruce Chambers
Help us help you:
You can have peace. Or you can have freedom. Don't ever count on having
both at once. - RAH