Surprise! You May Have More Firewall Than You Need
Windows Vista's firewall doesn't come with outbound filtering turned on--but does it matter?
Erik Larkin, PC World

But Microsoft was right: You don't need outbound filtering.
Sure, many good, free firewalls (like ZoneAlarm and Agnitum) and security suites for XP offer this extra layer of defense, which can be useful for stopping malware such as a keylogger that tries to transmit stolen passwords to a remote server, or a bot that tries to fetch malicious instructions from an IRC (Internet Relay Chat) channel. With these firewalls, you get a pop-up warning that a program is trying to connect to an Internet destination, and you have the opportunity to say no.
The problem is, such protection doesn't mean much. For one thing, if you have a good antivirus program, if you're smart enough not to open unknown e-mail attachments, and if you don't use Internet Explorer 6, you already have strong layers of defense against Internet-based attacks.
For outbound blocking to be worthwhile, you must know--or be willing to research--every program and program component that needs to connect out for any valid reason, such as to get necessary program updates. Choose wrong, and something breaks. Or more likely, you become conditioned to clicking 'OK' in response to all prompts, and do so when it causes a problem.
Where outbound filtering can be useful is in catching those extra-chatty programs that send more info than they should--like Microsoft's original WGA Notifications, which last year sent many unnecessary PC details back to Redmond. But again, to know whether the data being sent is a benign check for program updates or a list of all your installed programs, you have to be willing to dig deep with additional, highly technical programs that can capture and scan network traffic.
Though it's great for experts to help keep software vendors on their toes with this kind of analysis, the average cautious PC user doesn't need the hassle. Still, if you want to become a de facto network expert and dig in, here are some tips:
- To bring up the interface for enabling Vista's outbound Filtering software (and for creating rules for it), click Start, type
wf.mscin the Start Search box, and hit <Enter>. - The wf.msc interface is by no means user friendly, and I don't recommend it. The free Vista Firewall Control program makes configuring the firewall much easier and adds functionality that will prompt you when new programs try to connect to the Internet, much as many third-party firewalls do.
- If you want to supplement your firewall, the Ethereal program can capture and scan network traffic for subsequent expert analysis. It's free.
Erik Larkin is an associate editor for PC World. You can send him e-mail at privacywatch@pcworld.com. Read previously published Privacy Watch columns.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
PCW Download Guide
PCW's Mobile Life Guide
Related Security Articles
- Vendors, Cops, Profs Team to Study Cybercrime Tech vendors and the Secret Service are among those working with an evaluation of trends and best practices for security.
- Microsoft Readies Flood of Patches The 11 patches include 4 critical fixes, plus updates to Windows, Office, and IE.
- Mafiaboy Grows Up; a Hacker Seeks Redemption Eight years later, the infamous teen hacker wants to move from his history of downing sites to using his skills for good.
- Google in Curious Alliance With Click-fraud Detection Firm Google has agreed to cooperate with its longtime adversary Click Forensics on click-fraud reports.
- PCI App Security: Who's Guarding the Data Bank? Compliance strategies for PCI's new application security requirements.
Best Prices on Security Software
Norton Internet Security 2008Price: $13.98
Internet Security 2008 - 3-User (Full Product, PC)Price: $11.49
Norton Internet Security 2009Price: $25.49
Norton 360 2.0 ( PC)Price: $44.99
Kaspersky Internet Security 2009Price: $25.95
Internet Security Suite 2008 - 3-UserPrice: $14.95
- HP LaserJet Printers Satisfy your needs by combining fax, copy and scan capabilities with high-quality laser printing. Visit the Resource Center for more info...
- Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...
- CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.







"Surprise! You May Have More Firewall Than You Need" Comments