Eee PC security or lack thereof
Eee PC security or lack thereof
Posted Feb 14, 2008 8:52 UTC (Thu) by mjcox@redhat.com (guest, #31775)Parent article: Eee PC security or lack thereof
What doesn't help is that the iptables module is not available on the default Eee PC kernel, so without a firewall the various services ASUS have enabled (samba, portmap, cups, ... ) are open to the local network.
Posted Feb 14, 2008 10:16 UTC (Thu)
by tialaramex (subscriber, #21167)
[Link]
iptables vs chkconfig off
On a laptop though, it's unlikely that you have a multi-homed network scenario, so surely
"open to the local network" is basically only the alternative to "disabled". So in general
users who don't want services accessible to "the local network" should just switch those
services off altogether.
One thing I don't much care for (including in Red Hat's offerings) is adding a service,
enabling it by default, and then firewalling it so that no-one can use it. This is pointless.
Just disable the service by default, and eliminate whole classes of vulnerabilities at once.
