
Today, an ID password prompt is the only truly ubiquitous computer
security solution in the world. Password prompts are a supported
feature in nearly every system and application on the market today.
Therefore, all access should be denied unless explicitly allowed.
Firewalls in particular should be based on this principle. Firewalls
should be capable of stopping everything out of the box. Many com-
panies that have failed to remember this have been burned. A major
firewall vendor, for example, shipped with SNMP services running
in the default configuration for some time until a vulnerability
exploiting the service became public.
Stateful inspection firewalls ...