Quantcast
Privacy Watch
Privacy Watch
Few things are more valuable than your personal data. Associate Editor Erik Larkin shows you how to protect it.
Show article:

Surprise! You May Have More Firewall Than You Need

Windows Vista's firewall doesn't come with outbound filtering turned on--but does it matter?

Erik Larkin, PC World

  • 0 Yes
  • 0 No

Illustration: Mark Matcho
When Microsoft shipped Windows Vista, it included an upgraded firewall that enabled Windows--for the first time--to filter outgoing connections from your computer. But the company elected to turn off the outbound filtering by default and even made the feature hard to access. Smart, security-conscious people cried foul, saying that Microsoft had dropped the ball.

But Microsoft was right: You don't need outbound filtering.

Sure, many good, free firewalls (like ZoneAlarm and Agnitum) and security suites for XP offer this extra layer of defense, which can be useful for stopping malware such as a keylogger that tries to transmit stolen passwords to a remote server, or a bot that tries to fetch malicious instructions from an IRC (Internet Relay Chat) channel. With these firewalls, you get a pop-up warning that a program is trying to connect to an Internet destination, and you have the opportunity to say no.

The problem is, such protection doesn't mean much. For one thing, if you have a good antivirus program, if you're smart enough not to open unknown e-mail attachments, and if you don't use Internet Explorer 6, you already have strong layers of defense against Internet-based attacks.

For outbound blocking to be worthwhile, you must know--or be willing to research--every program and program component that needs to connect out for any valid reason, such as to get necessary program updates. Choose wrong, and something breaks. Or more likely, you become conditioned to clicking 'OK' in response to all prompts, and do so when it causes a problem.

Where outbound filtering can be useful is in catching those extra-chatty programs that send more info than they should--like Microsoft's original WGA Notifications, which last year sent many unnecessary PC details back to Redmond. But again, to know whether the data being sent is a benign check for program updates or a list of all your installed programs, you have to be willing to dig deep with additional, highly technical programs that can capture and scan network traffic.

Though it's great for experts to help keep software vendors on their toes with this kind of analysis, the average cautious PC user doesn't need the hassle. Still, if you want to become a de facto network expert and dig in, here are some tips:

  • To bring up the interface for enabling Vista's outbound Filtering software (and for creating rules for it), click Start, type wf.msc in the Start Search box, and hit <Enter>.
  • The wf.msc interface is by no means user friendly, and I don't recommend it. The free Vista Firewall Control program makes configuring the firewall much easier and adds functionality that will prompt you when new programs try to connect to the Internet, much as many third-party firewalls do.
  • If you want to supplement your firewall, the Ethereal program can capture and scan network traffic for subsequent expert analysis. It's free.

Erik Larkin is an associate editor for PC World. You can send him e-mail at privacywatch@pcworld.com. Read previously published Privacy Watch columns.

  • Recommend this story?
  • 0 Yes
    0 No

"Surprise! You May Have More Firewall Than You Need" Comments

With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.

Related Security Articles

  • Mac Security Focus: Antivirus Although Apple computers are not somehow magically immune to viruses and other malware, they've been remarkably free of such...
  • On The Defensive Lock up employee data, or face the consequences.
  • Unscramble This Encrypting data can save you lots of heartache. How should you do it?
  • 5 Ways to Foil Hackers Are you the only you out there? When it comes to protecting your identity, a bit of prevention is worth a megabyte of cure.
  • Mac Security Focus: Firewalls Firewalls monitor and regulate the data moving on and off your computer or network. They can keep criminals out while allowing...
  • Web Demo: Discover the Benefits of VoIP Is your company looking for a world class VoIP communications solution that will meet all of your business requirements? If so, join us for our Live Online Demo where you will receive a "guided tour" to the AltiGen Solution.
  • PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
  • A Windows Vista FAQ Corporate customers are deploying Windows Vista now, and Dell Services wants to help you understand the features of the new OS and how to plan your Windows Vista deployment.

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)