"Workstation" Product defaults to wide-open firewall

Bastien Nocera bnocera at redhat.com
Mon Dec 8 16:17:48 UTC 2014



----- Original Message -----
> 
> Am 08.12.2014 um 17:10 schrieb Bastien Nocera:
> >>> Security is about compromises. The net result of the old firewall
> >>> settings
> >>> was people disabling the firewall.
> >>
> >> And the net result of the new firewall settings is you disabling the
> >> firewall for them,
> >
> > It's not disabled
> 
> it is practically
> 
> the only port unprivileged code can listen on is > 1024, you opened that
> 
> >> The new firewall settings essentially amount to disabling the firewall.
> >
> > It doesn't
> 
> it does
> 
> the only port unprivileged code can listen on is > 1024, you opened that

And you're not interested in protecting any of the services running as root?

"There's a packaging bug for you, just put rpcbind on that unencrypted Wi-Fi please"


More information about the devel mailing list