Subject: Re: r/o filesystem restrictions for firewall?
To: Berndt Josef Wulf <wulf@ping.net.au>
From: Jon Lindgren <jlindgren@slk.com>
List: netbsd-help
Date: 10/24/2000 06:49:06
On Tue, 24 Oct 2000, Berndt Josef Wulf wrote:

[snip]

> I understand your concerns, but whilst you get rid of the harddisk, it
> is still possible to penetrate the system in many other ways. In
> in my books the harddisk drive is the least of my problems.
> 
> The best you can do is, use a trusted operating system... ;-), remove
> all programs and disallow all services not needed for the proper
> operation of the firewall. 
> 
> Most firewalls are succesfully broken into not because of flawed 
> binaries or operating systems, but incorrect configuration.

That is true, however, I don't want to let the intruder setup shop in my
kitchen after he's broken into my house ;-)  Perhaps not a perfect
metaphor, but...

> And after going through all this pain, you will be very disappointed
> if the system was brought down due to a INSIDER job...

Absolutely - this box is as secure as it can be, physically.  Plus, it'll
just be me and my girlfriend, both rather trusted individuals.  But that's
also part of my idea - if there is no possible way, short of burning a new
CD, to easily get in and do some damage, it's more likely to hold off any
attemps.  Then again, maybe I'm just going overboard.

Thanks again for the suggestions and criticism.

-Jon
 --------------------------------------------------------------------
 "Trout are freshwater fish, and have underwater weapons."
 "Zing, zing zing zing!"
 "Keep away from the trout."
 -- The opinions expressed are not necesarily those of my employer --
 "Who stole my lawn?"