On Mon, 12 Mar 2001, Tim Seifert wrote:

> _Replying to a message_
> 
> By:  Jeffrey E. Harris <[EMAIL PROTECTED]>
> To:  Jeffrey E. Harris <[EMAIL PROTECTED]>
> On:  Sunday, March 11, 2001, 11:11:47 PM
> Re:  [Miami] Re: Cable Modem tests
> 
> 
> Hi Jeffrey,
> 
> TS>> You do have to deliberately elect to share files and printers, for
> TS>> one thing.  And, Windows stupidities aside, they oughtn't to be
> TS>> shared to the web, as a default action for MODEMs.  Though, LAN type
> TS>> of internet connections to the web are likely to be available, by
> TS>> default.
> 
> JEH> That's the problem.  The sharing capability that Microsoft provides in its
> JEH> consumer products, Windows 9X and ME, are simply password protected -
> JEH> there is or is not a password and the password controls either read only
> JEH> or read and write.  It was never designed to be a very secure mechanism,
> JEH> and unfortunately, short of putting up a firewall, there is no way to
> JEH> distinguish between a LAN connection and a Internet connection.
> 
> Passwords are often sent in the clear, too.  So anybody able to snoop the
> network, can capture the passwords.  They're often /only/ hidden from the
> person typing them in.
> 

Not exactly.  Windows networking passwords are sent encrypted, at least
where a Windows NT or 2000 machine is involved.  I believe the same is
true for other Windows operating systems.  Web passwords, however, are
sent clear text, as are FTP passwords.  Web passwords, though, can be
protected by encrypting the connection with SSL.

> JEH> Windows NT and 2000 provide better security, but still there is no
> JEH> difference between access over the Internet and over a LAN.
> 
> Windows seems to have a bad time determining what is local, or internet
> traffic.  If you look at the indicator, on the bottom of the IE web
> browser, it's often wrong (particularly when browsing the net, on a
> computer behind a gateway).
> 

As far as I can tell, Windows does not know and does not care.  The only
real difference between a LAN and Internet connection for a machine behind
a gateway is that the packets are forwarded off the local network, but the
user's machine does not need to know or care where the packets go once
they are sent to the gateway address as long as they return from the
target address. And that is true for any TCP/IP connection.  The only real
way to shut off Internet access is to use a firewall to block access to
the ports that file sharing occurs on.

> TS>> But, it is possible that simply leaving your file sharing in a
> TS>> publically accessible condition may be sending stuff out onto the
> TS>> internet that makes a pest of itself, all by itself.
> 
> JEH> There is no question about that.  I myself discovered that Microsoft's
> JEH> critical notifier service, which is designed to alert users when Microsoft
> JEH> releases a new patch for their software, was trying to access the Internet
> JEH> about every 30 seconds (and the only way I knew was that I have my
> JEH> firewall - on my other system - configured to deny access to the Internet
> JEH> by default).  I quickly uninstall that service *chuckles*. 
> 
> I was thinking more about networking handshaking, stuff that annoyed
> /other/ people.
> 

A firewall will deal with that too.  Unfortunately, Microsoft networking
is a big believer in broadcasts, which is possibly part of what you are
referring to.

> My own critical update notifier, is set for 5 minutes.  I can't change it
> and I can't remove it; it re-instates the original settings, each boot up.
> 

What software are you using that does that?

> TS>> e.g. the usual Windows networking behaviour, such as the typical
> TS>> spurious NetBIOS connection attempts we all get while on the net.
> TS>>
> TS>> Mostly "that's" harmless.  Though, if you're vulnerable, you might
> TS>> end up accidentally sharing your files with a complete stranger, who
> TS>> may take advantage of that.  Hackers, on the other hand, are always
> TS>> on the prowl for such a gifted opportunity.
> 
> JEH> Yes, and that's one of the major problems in the Windows design.
> JEH> Fortunately, MS appears to be moving away from NetBIOS and more to pure
> JEH> TCP/IP.
> 
> I'm not so sure that's a good idea.  If you don't want file access across
> the net, now you can simply disassociate the file sharing protocol (e.g.
> NetBIOS) from the TCP/IP protocol.  If everything is using TCP/IP you have
> to wade into firewalling at a much more technical level.
> 

This is true, but one would hope that firewall authors would abstract the
settings in a way that makes it easy for users to implement - check this
box to enable filesharing, uncheck the box to disable it.

> JEH> <rest of text deleted>
> 

<text on deleting sigs deleted!  But implemented!>

We probably need to kill off this thread, and go private, since we have
strayed way off the focus of the mailing list!

> -- 
> Bye,
> Tim.
> 

jeh

-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to