Live data from Hacker News

Why firewalls won’t matter in a few years

etherealmind.com

41–50 of 139 posts

Re: Why firewalls won’t matter in a few years

#41
post #40

Firewalls are just some stupid crap industry made up and went with. We've known since the Orange Book days that security had to be done holistically involving every endpoint and network. Their standard for security was a strong TCB on endpoint with trusted path (see EROS or Dresden's Nitpicker); a network card with onboard security kernel, firewall, and crypto (see GNTP + GEMSOS); connections between networks through…

If this observation is meaningful, shouldn't it also be the case that firewall deployments aren't meaningful to enterprise security? Because: that seems intuitively not to be the case. To wit: on an annual site-wide pentest of any major enterprise network (this is a project every security firm does for a couple clients a year), the moment the pentester gets "behind the firewall" (ie: code execution on any application…

Stamos seemed to be making a point about the progression and resources being spent on security solutions. Firewalls are deterrents, but there seems to be a general consensus that they are not feasible for the future and the closest approximation that can be achieved to a "fully secure" system is by focusing on Applicaiton Security. During the video Stamos admits and an audience member loudly agrees that "we suck at appsec". Firewalls are stupid crap because we suck at appsec. If we didn't suck at appsec firewalls would and should not matter.

Re: Why firewalls won’t matter in a few years

#42
I also wonder how the move to IPv6 will also affect the current paradigm. Internet facing firewalls were typically also NAT machines to save IPv4 address space but all of that is gone in IPv6 meaning your global address is now exposed and a hacker can persistently try to compromise your machine if you don't firewall.

Re: Why firewalls won’t matter in a few years

#44

Firewalls are just some stupid crap industry made up and went with. We've known since the Orange Book days that security had to be done holistically involving every endpoint and network. Their standard for security was a strong TCB on endpoint with trusted path (see EROS or Dresden's Nitpicker); a network card with onboard security kernel, firewall, and crypto (see GNTP + GEMSOS); connections between networks through…

Could you expand on your last para please - it seems to promise there is a solution to software security already available ...

E-language seems a bit out dated from the intro I can find, What's an IO offload engine? What do you means about unified model (capability based / distributed implies E-language again?)

Is this using strong data types to base security capabilities on? And how does hardware for in here

I ask for interest as your comments here and on Schneier imply a lot of knowledge under the surface and am run in to catch up

Re: Why firewalls won’t matter in a few years

#45

Earlier quoted context omitted.

The browser took over that throne 10 or 15 years ago, with the rise of web 2.0. We make and download way, way more applications that run in web browsers (aka every web site) than applications that run on Windows, OSX, or any other OS.

Only by redefining what "application" means.

Please look up the definition of "application". I don't mean to be pedantic; it was enlightening to me as well.

Re: Why firewalls won’t matter in a few years

#46
post #42

I also wonder how the move to IPv6 will also affect the current paradigm. Internet facing firewalls were typically also NAT machines to save IPv4 address space but all of that is gone in IPv6 meaning your global address is now exposed and a hacker can persistently try to compromise your machine if you don't firewall.

On top of that many modern defenses are based on IP reputation, or black lists. There are several companies that track the reputation of all 4 billion IPv4 addresses. Scores are updated every 5 minutes. With several quadrillion IPv6 addresses this will be a lot harder to do.

Re: Why firewalls won’t matter in a few years

#47
post #17

Earlier quoted context omitted.

> AV How does Anti-Virus play into this as a counter to "minor tactics?" Are you expecting all end-users to personally verify all of their software? No matter how secure the network connection is, end-users need software to use their computers to do work/have fun/etc. Unless you have a completely closed system of 100% trusted software. If you're part of an organization like the NSA, that might be doable, but home use…

re antivirus. It doesn't work: they dodge it constantly. They can also use it to improve their odds of beating it by tuning the malware against it. Need I say more about why its barely a defense? Back in 1961, Burroughs designed a mainframe [1] that anticipated all these problems. They tagged their memory with bits to protect pointers or differentiate code vs data. That's two bits per word of data with almost no perf…

You may be aware already, but the LowRISC people are planning on putting tagged memory into their chip. Yay!

Re: Why firewalls won’t matter in a few years

#48
post #40

Firewalls are just some stupid crap industry made up and went with. We've known since the Orange Book days that security had to be done holistically involving every endpoint and network. Their standard for security was a strong TCB on endpoint with trusted path (see EROS or Dresden's Nitpicker); a network card with onboard security kernel, firewall, and crypto (see GNTP + GEMSOS); connections between networks through…

If this observation is meaningful, shouldn't it also be the case that firewall deployments aren't meaningful to enterprise security? Because: that seems intuitively not to be the case. To wit: on an annual site-wide pentest of any major enterprise network (this is a project every security firm does for a couple clients a year), the moment the pentester gets "behind the firewall" (ie: code execution on any application…

Hi Thomas, I recall you saying at one point that you are not a fan of static code analyzers for improving application security. Could you elaborate? "None of them found Heartbleed" might be one reason, I suppose, but it seems to me they do find a lot of more ordinary XSS, SQL injections, etc. Do you really think it's not worth using them at all?

Re: Why firewalls won’t matter in a few years

#49
post #40

Firewalls are just some stupid crap industry made up and went with. We've known since the Orange Book days that security had to be done holistically involving every endpoint and network. Their standard for security was a strong TCB on endpoint with trusted path (see EROS or Dresden's Nitpicker); a network card with onboard security kernel, firewall, and crypto (see GNTP + GEMSOS); connections between networks through…

If this observation is meaningful, shouldn't it also be the case that firewall deployments aren't meaningful to enterprise security? Because: that seems intuitively not to be the case. To wit: on an annual site-wide pentest of any major enterprise network (this is a project every security firm does for a couple clients a year), the moment the pentester gets "behind the firewall" (ie: code execution on any application…

'Game over': I think this is exactly the problem. In all the organizations I've been in, firewalls have been an excuse for negligence. 'We don't need to think about security because we are behind the firewall.'

Right now the compliance world is addicted to firewalls, to the detriment to reasonable appsec. In my fantasy world, I'd like the auditors to be telling companies 'in 5 years, you won't be allowed to firewall your business network, and if you aren't secure without the crutches, then no certification for you.' That would light a fire under management to care about software quality all over the place.

Re: Why firewalls won’t matter in a few years

#50
post #20

Earlier quoted context omitted.

Interesting. Never heard the term before.

I think it's from American football - east/west is lateral movement, north/south towards/away from the goal lines. Apparently this has nothing to do with getting sun in your eyes. http://stupidquestionarchives.blogspot.com/2008/03/football-...

I'd guess it more has to do with physical colo/datacenter layouts. Traffic moving between racks is considered east/west*. Traffic moving in and out of your routers (and through to the meet-me-room) would take place over fiber pairs up into the ceiling or down through the floor.

Just a guess.

Post reply on HN