<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:icbm="http://www.postneo.com/icbm/"
		>
<channel>
	<title>Comments on: IPv6 Firewalls</title>
	<atom:link href="http://technosailor.com/2007/02/15/ipv6-firewalls/feed/" rel="self" type="application/rss+xml" />
	<link>http://technosailor.com/2007/02/15/ipv6-firewalls/</link>
	<description>Web Technology and Real Life Merge</description>
	<lastBuildDate>Thu, 18 Mar 2010 02:16:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0-alpha</generator>
	<item>
		<title>By: Paul Robertson</title>
		<link>http://technosailor.com/2007/02/15/ipv6-firewalls/comment-page-1/#comment-63468</link>
		<dc:creator>Paul Robertson</dc:creator>
		<pubDate>Wed, 21 Feb 2007 01:17:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.technosailor.com/ipv6-firewalls/#comment-63468</guid>
		<description>Well, I think the discussion on diabling the protocol is more interesting, not being able to firewall off v6 clients will likely lead to abuse on the radio side of things.  

As for personal firewalls, outbound blocking allows you to stop trojans from calling home- so it&#039;s useful even if it&#039;s not on by default on the Mac and you can&#039;t do it in Windows without 3rd party software.  

Firewalls are useful in stoping target of opportunity attacks.  Limiting what devices can access an open port is good for reducing vulnerability.  Especially for new vulnerabilities in nework services for which there isn&#039;t yet a patch.

Firewalls stop real attacks all the time, so I&#039;m not sure why the folks enabling v6 devices haven&#039;t started to work out the issues and build in some protection.

If you don&#039;t have a real trusted and validated computing base, then you&#039;re pretty much stuck with arbitrating access as a security mechanism.  What&#039;s the alternative?

Paul</description>
		<content:encoded><![CDATA[<p>Well, I think the discussion on diabling the protocol is more interesting, not being able to firewall off v6 clients will likely lead to abuse on the radio side of things.  </p>
<p>As for personal firewalls, outbound blocking allows you to stop trojans from calling home- so it&#8217;s useful even if it&#8217;s not on by default on the Mac and you can&#8217;t do it in Windows without 3rd party software.  </p>
<p>Firewalls are useful in stoping target of opportunity attacks.  Limiting what devices can access an open port is good for reducing vulnerability.  Especially for new vulnerabilities in nework services for which there isn&#8217;t yet a patch.</p>
<p>Firewalls stop real attacks all the time, so I&#8217;m not sure why the folks enabling v6 devices haven&#8217;t started to work out the issues and build in some protection.</p>
<p>If you don&#8217;t have a real trusted and validated computing base, then you&#8217;re pretty much stuck with arbitrating access as a security mechanism.  What&#8217;s the alternative?</p>
<p>Paul</p>
]]></content:encoded>
	</item>
</channel>
</rss>
