Thursday, December 23, 2004

Use a Firewall or Throw Your Computer in the Trash

So, how long do you think it would take someone evil to invade your computer via the Internet if you had no firewall protection? Five weeks, five days, five hours, five minutes, or five seconds? The answer in a minute...

The reason I know the answer is I read a report by a research company in conjunction with USA Today who tried a test to determine the answer to the question I just posed to you. They took some brand new computers, installed different operating system such as Windows XP, Apple, and Linux.

The computers were then connected to the Internet via a fast DSL connection, which, like fiber optics and cable modems, meant they were always connected to the Internet, even if no one was using them (of course they were left running. Turning a computer off does disconnect it from the Net). Some had firewalls running, some didn't.

OK, the answer to my question is...37 seconds. Yup, that is right. One computer on the test was invaded in 37 seconds. The average time for the unprotected computer to be invaded was 4 minutes and 30 seconds. Yes, the hackers are out there in droves, running automated programs to detect unprotected computers. For example, a computer running Windows XP with Service Pack One, was attacked 341 times per hours or 8,177 times a day. The Apple computer was attacked just slightly less...339 times per hour.

The good news is that Windows XP computers running Service Pack Two using the built-in firewall was only attacked 3.9 times per hour. And the Windows XP running Zone Alarm was attacked only 2.1 times per hour.

Even more good news was that there was not one successful invasion of any computer that used a firewall. But, here's the rub...only 33% of computer users using the Internet have a firewall!!

I recently had first hand experience with this very same scenario. I moved my web site and e-mail post office software for corkrum.com to a new computer running Windows 2000. I am very aware of computer hacking so I had a firewall up and running right away. But, while I was setting up the new computer with some new and upgraded software for my web services, I had to monitor the firewall to make sure everything was working correctly. I watched the hack attempts happening on the spot.

Someone actually got into my computer using Windows Messaging which was accidentally left open. All I got was an advertisement for software to protect against this kind of invasion, but I immediately shut down Windows Messaging and the ads stopped.

In our home, I use a hardware firewall which protects all computers but the web server and a software firewall for the web server. I also have a software firewall in my laptop for when I am out on the road.

I pray that you have a firewall, especially if you are connect via fiber optic, cable, or DSL. If not, you are a prime candidate to have your computer and identity hijacked, your bank accounts drained, and your computer used for some evil purposes like Denial-of-Service attacks on other computers. Want more good news? Both software firewalls mentioned here are FREE!!

I invite you to read the full article in USA Today.

Tomorrow, I will talk more about computer security and pass along the advice of one the country's resident security geniuses.

No comments: