{"id":11740,"date":"2011-05-24T10:05:30","date_gmt":"2011-05-24T15:05:30","guid":{"rendered":"http:\/\/www.shamusyoung.com\/twentysidedtale\/?p=11740"},"modified":"2011-05-24T10:05:30","modified_gmt":"2011-05-24T15:05:30","slug":"stolen-pixels-260-the-dark-fortress","status":"publish","type":"post","link":"https:\/\/www.shamusyoung.com\/twentysidedtale\/?p=11740","title":{"rendered":"Stolen Pixels #260: The Dark Fortress"},"content":{"rendered":"<p><table   class=\"\" cellpadding='0' cellspacing='0' border='0' align='center'><tr><td><img src='https:\/\/www.shamusyoung.com\/twentysidedtale\/images\/splash_psn.jpg' class='insetimage'   alt='splash_psn.jpg' title='splash_psn.jpg'\/><\/td><\/tr><\/table><\/p>\n<p>I have crafted for you a <a href=\"http:\/\/www.escapistmagazine.com\/articles\/view\/comics\/stolen-pixels\/8897-Stolen-Pixels-260-The-Dark-Fortress\">comic about Sony<\/a> and their PSN hi-jinks. <\/p>\n<p>One thing I found strange about the <a href=\"?p=11656\">security announcement<\/a> was the part where they promised &#8220;additional firewalls&#8221;.  A firewall just blocks types of traffic, or traffic from certain locations.  See, you can&#8217;t &#8220;stack&#8221; firewalls. Or at least, doing so shouldn&#8217;t make things any more safe. Using two firewalls for the same entry point would be like mashing two metal detectors together and making people walk through both at once. It doesn&#8217;t let you find twice as much metal, or find metal twice as fast. It doesn&#8217;t make one super-sensitive metal detector. <\/p>\n<p>You should have exactly one firewall on every machine, and that firewall should only allow traffic that the machine is specifically designed to handle. The webserver should only allow web traffic, and block everything else. The database should only allow database traffic, and block everything else. The mail server shouldn&#8217;t accept web traffic and the FTP server should only speak to a narrow band of trusted IP addresses, ideally machines inside of Sony offices. <\/p>\n<p>So what is the deal with adding &#8220;more firewalls&#8221;?  Were there machines with NO firewalls on them?  Or are they stacking firewalls? Or was this the layman&#8217;s way of saying, &#8220;We closed a bunch of ports that we shouldn&#8217;t have left open in the first place&#8221;? <\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have crafted for you a comic about Sony and their PSN hi-jinks. One thing I found strange about the security announcement was the part where they promised &#8220;additional firewalls&#8221;. A firewall just blocks types of traffic, or traffic from certain locations. See, you can&#8217;t &#8220;stack&#8221; firewalls. Or at least, doing so shouldn&#8217;t make things [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[102],"tags":[],"class_list":["post-11740","post","type-post","status-publish","format-standard","hentry","category-weekly-column"],"_links":{"self":[{"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/posts\/11740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11740"}],"version-history":[{"count":0,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/posts\/11740\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}