Which enterprise firewall to go for?

Ok. I'll bite. Is there any example of a backdoor in a mainstream open source project. Anyone who tries has been caught.

I like your style, it's very cool, but you are reversing the burden of proof. These is your claim/s :

The only product with more backdoors than Huawei is Fortinet! :ROFL:
Security products cannot be secure when they have inherent risks like backdoors. Someone like ICSA say they test for it but they only test against a knowledge base of known ones where the vendor has been caught with their pants down. In reality any closed source product has that as a liability. The vendor can have backdoors without your knowledge and you have no way of knowing or any way to mitigate that risk.

Wie beweer, moet bewys.
 
I like your style, it's very cool, but you are reversing the burden of proof. These is your claim/s :



Wie beweer, moet bewys.
What a cop out. There is no open source exploit that has a back door as the raw code is there for review. What you stated was hypothetical BS and you unable to back it up.
As far, as proof, you do know that Fortinet has been on the FBI and CISA watchlist. This is only one of many red flags around closed source security products. Refer: https://www.cisa.gov/uscert/ncas/cu...exploitation-fortinet-fortios-vulnerabilities
Maybe is time to be more open minded and less prone to Silicon Valley propaganda.
 
What a cop out. There is no open source exploit that has a back door as the raw code is there for review. What you stated was hypothetical BS and you unable to back it up.
As far, as proof, you do know that Fortinet has been on the FBI and CISA watchlist. This is only one of many red flags around closed source security products. Refer: https://www.cisa.gov/uscert/ncas/cu...exploitation-fortinet-fortios-vulnerabilities
Maybe is time to be more open minded and less prone to Silicon Valley propaganda.
I am not sure what exactly you are stating there.

If you are saying that back doors don't exist in open source software, well that's just plain wrong. Read the Github Octoverse report, 17% of all vulnerabilities discovered were maliciously placed, and some take up to 4 years to be discovered. Also, the study was only conducted over a two year period (2018-2020).

It's not only code, think Kleptography, PRNGs like DUAL_EC_DRBG come to mind (which ANSI and NIST punted, and were used by both open source and proprietary software for years).

Nothing is ever absolute, one is not neccessarily more secure than the other. which is why you should consider revising your statement.
 
people here worrying about all the highly technical things , when the biggest security threat comes from the inside of your organisation.
 
I am not sure what exactly you are stating there.

If you are saying that back doors don't exist in open source software, well that's just plain wrong. Read the Github Octoverse report, 17% of all vulnerabilities discovered were maliciously placed, and some take up to 4 years to be discovered. Also, the study was only conducted over a two year period (2018-2020).

It's not only code, think Kleptography, PRNGs like DUAL_EC_DRBG come to mind (which ANSI and NIST punted, and were used by both open source and proprietary software for years).

Nothing is ever absolute, one is not neccessarily more secure than the other. which is why you should consider revising your statement.
Haven't a clue what you implying. Open Source is worse than closed source? Name an exploit and not a vulnerability in open source. If some twat plants malicious code its in open view. Closed source its not. The review process in major projects picks this up and bans the tosser before it goes into prod.
Here is the full extract of what you quoting:
Analysis on a random sample of 521 advisories from across our six ecosystems finds that 17% of the advisories are related to explicitly malicious behavior such as backdoor attempts. Of those 17%, the vast majority come from the npm ecosystem. While 17% of malicious attacks will steal the spotlight in security circles, vulnerabilities introduced by mistake can be just as disruptive and are much more likely to impact popular projects. Out of all the alerts GitHub sent developers notifying them of vulnerabilities in their dependencies, only 0.2% were related to explicitly malicious activity. That is, most vulnerabilities were simply those caused by mistakes.
BTW: If someone has a core security product based on javscript, then they deserve to be hacked. You should reconsider your evaluation of open source based on a report that has a significant finding about javascript.
 
Haven't a clue what you implying.
Clearly, this is one thing that we both can agree on.

Open Source is worse than closed source?
Did I ever state that?
I did state that considering both open and closed source software, one is not necessarily more secure than the other.

Name an exploit and not a vulnerability in open source.
It's really a silly question, because there are many, so I'll do better: I will give an example of a hack that cost money, ever heard of Equifax? That was due to Apache Struts. And what about Heartbleed (OpenSSL), are you saying that there was no exploit code for it?

If some twat plants malicious code its in open view. Closed source its not.
I remind you that I have never stated that proprietary software is more secure than open-source software. You seem to somehow have a deep-seated desire to prove somehow that open-source software is more secure than proprietary software. It's not a debate that I'm going to be drawn into, because it's not profitable. I might add that I personally use about 75% open-source software every day in my work.

Also, to quote Schneier:
Open source means that the code is available for security evaluation, not that it necessarily has been evaluated by anyone. This is an important distinction.
 
What a cop out. There is no open source exploit that has a back door as the raw code is there for review. What you stated was hypothetical BS and you unable to back it up.
This is only true if you compile the code yourself. no package managers, binaries or vendor devices. Else it is easy to roll a backdoor in.

Enterprise products come with some guarantees, support and hardware replacements.
They also have specs to match use case.

It is more about liability than cutting edge. Stability and predictability.

Holes will always come up, and that is the cat and mouse game everyone plays.
 
This is only true if you compile the code yourself. no package managers, binaries or vendor devices. Else it is easy to roll a backdoor in.

Enterprise products come with some guarantees, support and hardware replacements.
They also have specs to match use case.

It is more about liability than cutting edge. Stability and predictability.

Holes will always come up, and that is the cat and mouse game everyone plays.
Enterprise products have a history of purposefully implementing backdoors without consent.
Enterprise products force your to pay for a fix.
Guarantees, support, and hardware replacement is not the exclusive domain of enterprise products. They just try to give that impression.
Again, please provide an example of an exploit of open source in the wild. It's as rare as hens teeth.
 
Clearly, this is one thing that we both can agree on.
Let us call it straight then.
You and I both have seen enterprise product salespeople in front of customers maligning open source to sway a deal for their own commission and benefit. All fair in love and war and then add the myths of no support, no guarantees, no hardware, inferior code quaility, etc. You name it, anything that will stick.
Never mind that most enterprise products start their lifecycle as an open source fork.
Edit: MAC is an example. In actual fact, I'm scratching my head thinking of the last project written new from the ground up and Windows comes to mind. Well, NT and then Gates stepped in and cocked it up with his interface ideas.
 
Last edited:
It's really a silly question, because there are many, so I'll do better: I will give an example of a hack that cost money, ever heard of Equifax? That was due to Apache Struts.
Ok. Equifax?
While the failure to update Struts was a key failure, analysis of the breach found further faults in Equifax' system that made it easy for the breach to occur, including the insecure network design which lacked sufficient segmentation, potentially inadequate encryption of personally identifiable information (PII), and ineffective breach detection mechanisms.
Very murky as I would say there are significant other security failings there and it was an exploit of a vulnerability (a mistake) and not a malicious backdoor.
 
That was due to Apache Struts. And what about Heartbleed (OpenSSL), are you saying that there was no exploit code for it?
Heartbeat? What about it. Again a mistake and not a backdoor. Also, used by every enterprise product under the sun because they in actually fact don't roll their own...
Proves the case about open source being better if the closed source guys are dependent on it.
 
We require an firewall with site to site vpn support now, so the untangle box is not going to cut it anymore.

Supplier quoted me the following.

XGS 2100 SECURITY APPLIANCE - EU/UK POWER CORD
XSTREAM PROTECTION FOR XGS 2100 12MONTHS

Total Coming 74k, I can't pay that just to have site to site vpn.

Any other suggestions? I know mikrotik is cheap a but the GUI is not great :(
Take a look at the Netgate appliances and you can add support directly via Netgate site

 
I betcha no-one got fired for purchasing all those "enterprise products" though, and it was fixed quickly enough (yes, it took a few iterations:sneaky:) for them to maintain their ICSA certification, which is why its important, and raises the question: Would it have been fixed as quickly if it wasn't as pervasive in "enterprise products"?
4/10 for trolling on something that’s a licensing issue.
The fix is simply, don’t use it.
 
Enterprise products have a history of purposefully implementing backdoors without consent.
Enterprise products force your to pay for a fix.
Guarantees, support, and hardware replacement is not the exclusive domain of enterprise products. They just try to give that impression.
Again, please provide an example of an exploit of open source in the wild. It's as rare as hens teeth.
I am not sure what you mean about paying for a fix. Any product needs to be in maintenance window with a paid for cover be it for hardware and software. Running old hardware/software in Enterprise is crazy. Also in the security field, the vendor often lets their Enterprise clients know of vulnerabilities and/or issues.
If you are using Enterprise products in SME space, then this is a different conversation.
Never said that support is only for Enterprise products, the SLA is the critical thing.
 
I am not sure what you mean about paying for a fix. Any product needs to be in maintenance window with a paid for cover be it for hardware and software. Running old hardware/software in Enterprise is crazy. Also in the security field, the vendor often lets their Enterprise clients know of vulnerabilities and/or issues.
If you are using Enterprise products in SME space, then this is a different conversation.
Never said that support is only for Enterprise products, the SLA is the critical thing.
Here we go. Let us open that can of worms: https://packetpushers.net/youtube-vendor-tech-support-scam/
 
Top
Sign up to the MyBroadband newsletter
X