Response

Bryan, over at BlendMart had this to say in response to one of our discussions about patching and firewalls and what not:

“On a side note… to the folks commenting at Life of a one-man IT department, just because all your ports are closed and you don’t have Internet facing servers on your network is no excuse to delay patching your machines. All it takes is one laptop user, one home dialup user, one VPN user to infect and disable your entire network.”

He left a similar comment on the post below, and I responded back, but I wanted to elaborate further. You see, of course, Bryan is right. You should install this patch in addition to having a correctly configured firewall. As I said, it’s never a bad idea. Of course, as a one-man shop I can tell you that there are simply times where you miss a patch, because you’re out of the office, or you just have too many other priorities to get to before you patch. This is why having a firewall and having all of you unnecessary ports closed is vital, to any home or workplace user.

Now, in as small an office as ours, I can personally monitor and lock down everything on our network. We don’t have any internet servers, we don’t allow dialup or VPN and our laptops are in locked configuration to only access the internet through our network. The second any of that changes, so does the risk, and therefore so does the way I handle patches. Every network is different and you may not handle things the same way that I do. That’s as it should be. If your network got Blasted because you didn’t patch and someone snuck in an infected laptop, or used VPN from an infected machine, shame on ya’, but there may be circumstances that caused it to happen. (although you still had a month, they’d have to be some pretty outrageous circumstances!) On the other hand, if you got infected without Blaster even having to find a secondary way in, because you didn’t patch OR run a proper firewall, double shame on ya’!

Ultimately, that was my point. Running a firewall and blocking ports doesn’t guarantee a secure network, there are a ton of steps beyond that, but if you’re not even doing that while you’re connected to the internet, you’re just asking for trouble.

Similar Posts

  • It’s a worm

    Gee you know it’s pretty serious business when a worm shows as the headline on the Drudge Report, eh? For the record, after reading through the SlashDot synopsis and following the various links it appears to be a worm using an old MS SQL vulnerability that Microsoft released a patch for back in June and…

  • Meanwhile, back at the office today.

    Yeah I’m back at work today, rather disappointing I must say. I really like being out of the office, forgetting about this place. Doesn’t seem like there were any major catastrophes while I was gone, but it’s early yet, I’m sure someone will bring me something to make me want to scream and rip their…

  • Important IT lessons

    I re-learned two important IT lessons today. One occurred after we got up this morning to take a trip to the Zoo. I had gotten a new camera bag for my birthday, and spent a fair amount of time fitting the Nikon D50 into the bag, along with the extra zoom lens, and a few…

  • O’Reilly

    O’Reilly ended his presentation with a William Gibson quote: “The future is here now, it’s just not evenly distributed yet” That pretty much sums up what he talked about, the internet as the ultimate collaboration tool. Examples of places that are already letting users build the value included Google’s PageRank, Amazon’s reviews, etc. None of…

  • Olympics

    I think maybe it’s time to change how the networks broadcast the Olympics. I know this year it seems as though the ratings aren’t what they used to be, and I think it has a whole lot to do with the fact that they are showing things well after they’ve already happened. Come on, this…

  • Personal news

    One of the new things I’m going to be getting into this year is an involvement with a non-profit organization called Friends of the Columbus Library. They do a lot of fundraising and volunteer coordination for the Columbus Metro Library System and their Board this year has been looking for more direct involvement with people…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)