by Readers

Letters to the editor: “Firewalls tumbling down”

Opinion
Aug 8, 20055 mins

Also, Cisco’s AON, open source vs. Windows security debate

Firewalls tumbling down

Regarding “Are firewalls expendable?”: Removing perimeter security would be like taking down the walls and fences of a prison and requiring everyone who was once external to the prison walls to each have a level of security equal to the prison walls.  In essence, each device and application would need its own high level of security, requiring immediate patching when a vulnerability is uncovered. If you take a look at one application’s security issues, Windows, you can see that issue is huge. 

I would need to read up more on the group’s efforts and thoughts, but based on my 20 years in the IT field, I would say they are in for a rough time.

Lou Orlando

Technology specialist

Monmouth Junction, N.J.

Regarding “Are firewalls expendable?”: I suspect the debate is being marred by the assumption that de-perimeterization is equivalent to the death of the firewall. This is like saying that eliminating city walls meant eliminating locks, doors and borders.

The Jericho Forum wants to develop a world without corporate perimeters by requiring ISPs and network providers to deliver cleaner network services. One might call this macro-perimeterization. At the same time, individuals and corporations will be moving perimeters inward to protect their critical information assets. One might call this micro-perimeterization.

None of us on the Jericho Forum want to achieve anarchy. Try to imagine the discussions that went on in the council of London when the first “idiot” proposed tearing down the city wall. The noise from the naysayers was probably deafening and just as ill considered. Actually we are envisioning a world where everyone has implemented security models that negate the need for an electronic city wall.

The challenge of de-perimeterization will require governments, vendors, users and corporations alike to work in a new, more empowering manner that relies on new models and means of electronic trust. We cannot continue to operate under the assumption that the Visigoths are at our city walls; we need to take control of the “countryside” and bring order inside our electronic borders.

Adrian Seccombe

Chair, Trust Model Working Group

Jericho Forum

Guildford, U.K.

Are firewalls expendable? No, not if you are at all rational.

But one part of this recent publicity stunt is that it is finally recognized that internal networks are becoming increasing hostile and PCs (especially Windows), servers (all types), applications and appliances need firewalls in addition to perimeter defenses.  It is no longer sufficient just to watch the perimeter.

David Anderson

Calgary, Alberta

While the Jericho Forum is absolutely correct that new security solutions need to be developed to protect resources within the network, promoting the notion that companies should retire their firewalls is irresponsible and negligent.  A thorough inspection of the data security records of some of the forum’s members (for example, Eli Lilly) might lead some to believe that they’ve already retired their firewalls – I would not recommend taking security advice from someone with their track record. The notion that companies should not secure their network perimeters is entirely brain-dead and dangerous to the security and privacy of everyone’s information – shocking in a year that has seen so many high-profile cases of data security breaches, including from the very entities that are promoting this idea.

Troy Casey

Atlanta

Cisco’s AON

Regarding Kevin Tolly’s column, “Cisco’s AON: Ultimate vendor lockout or something more?”: I do not believe that Cisco is saying the network is dumb, but perhaps that the next evolution is switching intelligence based on XML. As for open standards, I believe it unrealistic at this point to be saying what other networking vendors are going to support AON.  Cisco is in business to make money and when you release a new product, does it make sense to illustrate that you can get this technology anywhere?  Give it time and a standard will appear.

Adam Goldberg

Hoboken, N.J.

More security needed

Your article “Open source vs. Windows: Security debate rages” leaves out many areas of security. What about on-the-fly document encryption and e-mail encryption?  For Linux to be a truly viable solution, it needs to match Windows in every area of security, including that which is available in end-user applications.  What I have seen so far is mostly manual, geek-oriented security that would be very hard to convince regular users to use.

Glenn Gettinger

Terre Haute, Ind.

List more providers

Your article “Branching out” presents a well-balanced picture of open source.  While it may not be the right choice all of the time, open source can be the best tool when used on the right job.

The one disappointment I do have is the minimal list of open source providers, even on your on-line version. I use OpenNMS for network monitoring and would rate it among the best network management system (NMS) products, plus there are reasonably priced support options. There are also several other options for NMS products from the open source community. 

Chris Lightner

Clifton Park, N.Y.