Firewalls and Internet Security - Repelling the Wily Hacker (Book)

New Image

Security is, in general, a tradeoff with convenience, and most people are not willing to forgo the convenience of remote access to their computers. Inevitably, they suffer from some loss of security. It is our purpose here to discuss how to minimize the extent of that loss. The situation is even worse for computers hooked up to some sort of network. Networks are risky for three major reasons. First, and most obvious, there are now more points from which an attack can be launched. Someone who cannot get to your computer cannot attack it; by adding more connection mechanisms for legitimate users, you are also adding more vulnerabilities. A second reason is that you have extended the physical perimeter of your computer system. In a simple computer, everything is within one box. The CPU can fetch authentication data from memory, secure in the knowledge that no enemy can tamper with it or spy on it.