3 ms·
Actually OSX didn't enable it by default last time I checked. And the last windows machine I touched had about 300 exceptions to the default deny incoming rule
by JupiterMoon 10y ago
Actually OSX didn't enable it by default last time I checked. And the last windows machine I touched had about 300 exceptions to the default deny incoming rule -- that the user had not opened themselves. Ubuntu would need some kind of phone-os like permission system for default deny to be both secure and be grandma friendly.
- daveguy 10y agoYou're right. OSX firewall is off by default -- also a poor decision. The outgoing exceptions on Windows probably because a Windows machine default deny for both incoming and outgoing which does require exceptions. Windows doesn't phone home for additional exceptions -- it asks you. The default on Ubuntu should be like all other linux distros where where all unsolicited incoming connections are blocked. Related incoming connections are allowed and outgoing connections are allowed. This would not require any difficult configuration on the part of the average home user. It seems to me that most people who are blindly defending Ubuntu's current setup do not understand how networking and firewalls work and the better options. That or they do not understand how wide open the Ubuntu defaults are. There is certainly a more secure easy to use option that Ubuntu is ignoring, but which all of the other linux distros use by default.
- slavik81 10y ago> That or they do not understand how wide open the Ubuntu defaults are. Fair enough. I'd love to learn. What threats does the firewall even defend against? > The default on Ubuntu should be like all other linux distros where where all unsolicited incoming connections are blocked. I don't understand why I should care. Evil hackers can send all they want, but the only things listening on my end should be those that I explicitly installed or enabled. The firewall seems redundant as the set of running applications and my set of firewall exceptions should match exactly.
- spydum 10y agoFirewall is a component to a layered defense. One of the points about Ubuntu was starting the service immediately after install, was it not?
- JupiterMoon 10y ago> Fair enough. I'd love to learn. What threats does the firewall even defend against? Many Debian/Ubuntu packages have a dependency on postfix. Even some trivial ones. Installing these packages installs postfix (which at least asks you to configure it during install). Having a firewall active means that your grandmother won't have services you didn't realise she had running listening.
- JupiterMoon 10y agoI fear that if Ubuntu enabled firewall with default deny on incoming packages by default packages would start adding the allow rules in their install scripts..