<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7183906.post109230139879145485..comments</id><updated>2007-04-16T15:53:50.088+08:00</updated><title type='text'>Comments on May be it's just me: On hard disk erasures and calling home</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://kohomban.blogspot.com/feeds/109230139879145485/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7183906/109230139879145485/comments/default'/><link rel='alternate' type='text/html' href='http://kohomban.blogspot.com/2004/08/on-hard-disk-erasures-and-calling-home'/><author><name>GreenLeaf</name><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7183906.post-109235813173751758</id><published>2004-08-13T08:48:00.000+08:00</published><updated>2004-08-13T08:48:00.000+08:00</updated><title type='text'>My point has been (and is) that outbound blocking ...</title><content type='html'>My point has been (and is) that outbound blocking is somethign that must have been done, regardless of the *possibility* that a user *may* run with system previleges, and the virus *may* turn of the firewall and so on. I just tried to explain that (and why) most outgoing callers do not necessarily do that. Even with admin rights, spyware will most probably stay out of the firewall tampering, to keep their legitimate mask on. &lt;br /&gt;&lt;br /&gt;And what about all the computers that run *without* admin privileges? &lt;br /&gt;&lt;br /&gt;By the way, not ALL the processes are admin-terminatable. Local Security Authentication Server for instance is a system process, and admin cannot terminate it either by task manager or by programs - except for a few bugs MS had there which allowed sasser to exploit windows systems.&lt;br /&gt;&lt;br /&gt;You say:&lt;br /&gt;&gt;&gt; Who's stupid? MS for creating a firewall or the users who runs as Admins?&lt;br /&gt;&lt;br /&gt;Creating a firewall is a good thing. Running as admins is possibly stupid in case one doesn't know what one does. What about assuming that all users run as admins? lets break down:&lt;br /&gt;&lt;br /&gt;There are two possibilities: The virus allways (with admin rights or not) terminates the firewall, or it does NOT. &lt;br /&gt;&lt;br /&gt;In first case, having a firewall only protects the machine against attacks that come as inbound connections: well, this is still good, and I didn't say it's *bad*: i just said it's not good *enough* for a firewall and why it is not.&lt;br /&gt;&lt;br /&gt;In the latter case, we miss a lot of functionality that must have been there. I detailed possible evils of outbound connections in my post. Giving a pistol to kill and elephant is still better than giving nothing, but I prefer a double barrel shot-gun. &lt;br /&gt;&lt;br /&gt;Having said that, I stress on my view again, MS is NICE to give a firewall - but it's just better-than-nothing. Not as better as it could have been.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7183906/109230139879145485/comments/default/109235813173751758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7183906/109230139879145485/comments/default/109235813173751758'/><link rel='alternate' type='text/html' href='http://kohomban.blogspot.com/2004/08/on-hard-disk-erasures-and-calling-home?showComment=1092358080000#c109235813173751758' title=''/><author><name>Gandalf</name><uri>http://www.blogger.com/profile/18192591530777735584</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kohomban.blogspot.com/2004/08/on-hard-disk-erasures-and-calling-home' ref='tag:blogger.com,1999:blog-7183906.post-109230139879145485' source='http://www.blogger.com/feeds/7183906/posts/default/109230139879145485' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-7183906.post-109231029971107874</id><published>2004-08-12T19:31:00.000+08:00</published><updated>2004-08-12T19:31:00.000+08:00</updated><title type='text'>If you are still pondering:

If a program is runni...</title><content type='html'>If you are still pondering:&lt;br /&gt;&lt;br /&gt;If a program is running under Admin privileges, you can do very little to stop it; it can format your harddrive (the ultimate) and everything else imaginable in-between : Turn off All Firewalls and Security Checks, disable Antivirus software, reset the registry or uninstall all anti-sypware apps, etc. There is absolutely no stopping.&lt;br /&gt;&lt;br /&gt;So I still don't see your point in your original post: &lt;A HREF="http://www.blogger.com/r?http%3A%2F%2Fkohomban.net%2Fblog%2F2004%2F08%2Fbetter-than-nothing-but-not-good.shtml"&gt;Better than nothing, but not good enough&lt;/A&gt;.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7183906/109230139879145485/comments/default/109231029971107874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7183906/109230139879145485/comments/default/109231029971107874'/><link rel='alternate' type='text/html' href='http://kohomban.blogspot.com/2004/08/on-hard-disk-erasures-and-calling-home?showComment=1092310260000#c109231029971107874' title=''/><author><name>Hethu Nanayakkara</name><uri>http://www.blogger.com/profile/18236808652077068941</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kohomban.blogspot.com/2004/08/on-hard-disk-erasures-and-calling-home' ref='tag:blogger.com,1999:blog-7183906.post-109230139879145485' source='http://www.blogger.com/feeds/7183906/posts/default/109230139879145485' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-7183906.post-109230739234327851</id><published>2004-08-12T18:43:00.000+08:00</published><updated>2004-08-12T18:43:00.000+08:00</updated><title type='text'>I repeat:
If an application has Admin privileges, ...</title><content type='html'>I repeat:&lt;br /&gt;If an application has Admin privileges, there's no way you can stop it from formatting your hard disk.&lt;br /&gt;&lt;br /&gt;You took that literally and went on and on on a obvious FYI lesson. Yes, no one would do that, but you completely missed the point. *sigh*&lt;br /&gt;&lt;br /&gt;Let me put it in simple words:&lt;br /&gt;No matter what-on-earth kind of firewall or whatever-you-call-it solution you have on your machine, any spywhere/virus can easily turn it off if you run with Admin privileges. Simple as that.&lt;br /&gt;&lt;br /&gt;There is no workaround to stop this. If Windows allows the Admin - the real-blooded-human-admin to turn off the Firewall, so can a program.&lt;br /&gt;&lt;br /&gt;You said:&lt;br /&gt;"If MS assumes that majority of the users log-in as admin it's stupid because they have to accept that their firewall is just useless..."&lt;br /&gt;&lt;br /&gt;Who's stupid? MS for creating a firewall or the users who runs as Admins?&lt;br /&gt;&lt;br /&gt;Einstein said once: "Two things are infinite: the universe and human stupidity; and I'm not sure about the universe."  And I'm afraid he's right... &lt;br /&gt;&lt;br /&gt;It's sad to see that you have become just another whiner without giving in a Solution to the problem.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7183906/109230139879145485/comments/default/109230739234327851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7183906/109230139879145485/comments/default/109230739234327851'/><link rel='alternate' type='text/html' href='http://kohomban.blogspot.com/2004/08/on-hard-disk-erasures-and-calling-home?showComment=1092307380000#c109230739234327851' title=''/><author><name>Hethu Nanayakkara</name><uri>http://www.blogger.com/profile/18236808652077068941</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://kohomban.blogspot.com/2004/08/on-hard-disk-erasures-and-calling-home' ref='tag:blogger.com,1999:blog-7183906.post-109230139879145485' source='http://www.blogger.com/feeds/7183906/posts/default/109230139879145485' type='text/html'/></entry></feed>