Response

Bryan, over at BlendMart had this to say in response to one of our discussions about patching and firewalls and what not:

“On a side note… to the folks commenting at Life of a one-man IT department, just because all your ports are closed and you don’t have Internet facing servers on your network is no excuse to delay patching your machines. All it takes is one laptop user, one home dialup user, one VPN user to infect and disable your entire network.”

He left a similar comment on the post below, and I responded back, but I wanted to elaborate further. You see, of course, Bryan is right. You should install this patch in addition to having a correctly configured firewall. As I said, it’s never a bad idea. Of course, as a one-man shop I can tell you that there are simply times where you miss a patch, because you’re out of the office, or you just have too many other priorities to get to before you patch. This is why having a firewall and having all of you unnecessary ports closed is vital, to any home or workplace user.

Now, in as small an office as ours, I can personally monitor and lock down everything on our network. We don’t have any internet servers, we don’t allow dialup or VPN and our laptops are in locked configuration to only access the internet through our network. The second any of that changes, so does the risk, and therefore so does the way I handle patches. Every network is different and you may not handle things the same way that I do. That’s as it should be. If your network got Blasted because you didn’t patch and someone snuck in an infected laptop, or used VPN from an infected machine, shame on ya’, but there may be circumstances that caused it to happen. (although you still had a month, they’d have to be some pretty outrageous circumstances!) On the other hand, if you got infected without Blaster even having to find a secondary way in, because you didn’t patch OR run a proper firewall, double shame on ya’!

Ultimately, that was my point. Running a firewall and blocking ports doesn’t guarantee a secure network, there are a ton of steps beyond that, but if you’re not even doing that while you’re connected to the internet, you’re just asking for trouble.

Similar Posts

  • |

    Linked – Emerging content formats challenge e-discovery

    As an industry, we’re always behind, but this is telling –   “As new types of content materialize from various applications and devices, the e-discovery process will become more difficult. According to a recent report from Osterman Research, any electronic information is potentially subject to e-discovery, including text messages, social media posts, data in collaboration…

  • Further thoughts

    As a bit of a follow up to last night’s Gnomedex comments, let me say this. I do think it’s the attendees that make a conference great. The great thing about Gnomedex is that the attendees are interesting people who I enjoy meeting and talking to. That’s really even more important than who the speakers…

  • Whew!

    OK I was up until 4AM making sure everything here worked and writing the full article on the problems I had with That Hosting Company. It seems everything is ok with the exception of comments from Sunday and Monday. Sorry, those seem to be gone. Given that much work, I’m taking most of the rest…

  • Tired Monday morning

    Wow, I’m exhausted, and it’s only 9AM. We actually had a good weekend, but a very busy, social weekend for us. Friday night we had my brother, sister in law and their three year old over to watch the HS football game that takes place across the street from our house this time of year….

  • Age issue?

    Jeremy posted today about someone calling him a “whiz kid” and how, at 24, he doesn’t really feel like a kid. Here’s the thing, without knowing much about the person who said it, it’s hard to tell where the idea comes from. In my office I’m seen by some as a “whiz kid” because I’m…

  • Blogback

    Ah so I see my point about real-time blogging at conferences being a bad idea has reached Robert Scoble’s eyes today. He says: So, your boss doesn’t want you to take notes next time he pays you to go to a conference? No, actually, I’m sure my boss does want me to take notes, since…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)