Avid Pro Audio Community

Avid Pro Audio Community

How to Join & Post  •  Community Terms of Use  •  Help Us Help You

Knowledge Base Search  •  Community Search  •  Learn & Support


Avid Home Page

Go Back   Avid Pro Audio Community > Pro Mixing > Avid Pro Mixing General Discussion
Register FAQ Today's Posts Search

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-24-2024, 11:44 AM
Goombot Goombot is offline
Member
 
Join Date: Oct 2012
Location: Burbank, CA
Posts: 434
Default Firewall

Random topic but does anyone who is mixing at home use a Firewall for extra security?
Reply With Quote
  #2  
Old 01-24-2024, 11:56 AM
Darryl Ramm Darryl Ramm is offline
Member
 
Join Date: Nov 2010
Location: USA
Posts: 19,657
Default Re: Firewall

Does anybody who has an Internet connection at home not use a firewall? The firewall built into their cable router? The default firewall built into their computer?

Is there a question here about specific firewalls? Specific security requirements? Operation of firewalls/port forwarding etc?
Reply With Quote
  #3  
Old 01-24-2024, 12:05 PM
JFreak's Avatar
JFreak JFreak is offline
Moderator
 
Join Date: Jan 2003
Location: Tampere, Finland
Posts: 24,907
Default Re: Firewall

Darryl got it right. When you open a door without rules, it is you to blame when unexpected things happen
__________________
Janne
What we do in life, echoes in eternity.
Reply With Quote
  #4  
Old 01-24-2024, 12:13 PM
Goombot Goombot is offline
Member
 
Join Date: Oct 2012
Location: Burbank, CA
Posts: 434
Default Re: Firewall

Just wondering if there was any additional security that people are using to protect projects while working on them at home
Reply With Quote
  #5  
Old 01-24-2024, 12:31 PM
JFreak's Avatar
JFreak JFreak is offline
Moderator
 
Join Date: Jan 2003
Location: Tampere, Finland
Posts: 24,907
Default Re: Firewall

Additional security?

Dodn't take thois wrong as I try to be polite and on point.

There is no additional security, at least no more than additional helth by eating something.

You need to understand that you have 100% security (and health in this analogy) and bit by bit you are giving those percentages away.

I am, and ptobably Darryl as well, more than happy to guide you in keeping those percentages on your pocket. But there is no store that can sell extra.
__________________
Janne
What we do in life, echoes in eternity.
Reply With Quote
  #6  
Old 01-24-2024, 02:30 PM
Darryl Ramm Darryl Ramm is offline
Member
 
Join Date: Nov 2010
Location: USA
Posts: 19,657
Default Re: Firewall

Quote:
Originally Posted by Goombot View Post
Just wondering if there was any additional security that people are using to protect projects while working on them at home
I would not operate a computer without a firewall, in my case the primary one is on the Mac itself. Start by turning on the computer internal firewall and the one on your internet router. But firewalls are just one part of any good security posture and would not be at the top of my list. It might be useful to hear from folks who have thought about security specifically for Pro Tools and remote project use.

I work on audio stuff as a hobby, my day job is more enterprise tech/startups but there are mostly general things that you probably want to consider... (in no particular order)...

Use a password manager, and use it properly, starting with only using generated long passwords, with no password reuse. Uninstall Avid Link (is a bloated mess and has a huge attack surface) any any other unneeded bloatware from your computer. Try to harden the network behind the router firewall, so if a WiFi run that as securely as possible or use wired Ethernet. At least do things like turn on as high a level of encryption as you can, turn on new device notification, etc. Try to harden your computer, make sure the login password/PIN is secure enough, turn on 2FA, turn off all but essential cloud sharing (i.e. needed for the client), turn off guest accounts, turn off file sharing/serving/web serving etc. Do not allow users to share accounts. Keep your OS up to date (can be a conflict with Avid glacial OS qualifications and a bad idea if that also would require updating Pro Tools mid-session) but at least take the minor security releases for an OS. Check firewall/computer logs for connection and login attempts (Not actually checking logs/notifications is a huge hole in many real security environments, right behind not having or not saving logs to start with... so work out if additional logs need to be turned on/saved/where they are). Make sure the computer or network/WiFi name does not give away private/personal info (shout out to the folks running the "FBI Van" SSID WiFi near one of my favorite coffee shops). Be very careful with personal information and what you do/click on in Emails and similar messages. Get personal apps, email, messages etc. off of work computers, don't access websites you don't need to from work computers (including private email etc). Keep backups/archives under sufficient security (not in the top drawer of your desk), and keep them removed from/isolated from/ideally offsite to protect against theft, and maybe data encryption ransom attacks. Minimize web browsing from work computers, but keep web browsers up to date, and turn up web browser security settings, removed unneeded web browsers, install EFF Privacy badger and uBlock Origin (I run Firefox and not Chrome because I value privacy). Maybe don't access DUC from your work computer :-(. etc., etc.

(I do much of the above on my computers regardless of their use)

There is an enormous spectrum out there of what can be done to improve security. I've worked in enough tighter security environments with SOC2 or stricter compliance needs, with mandatory SSO, private corporate VPNs tunneled to your computer, RSA authentication cards, FIFO/YubiKey/Titan authentication dongles. Corporate locked down and monitored Chromebooks, Tailscale's lovely VPN solution (a fancy, very well done wrapper for WireGuard VPN tunnel), etc., etc., etc. It's a never ending spectrum of stuff but many of those are not things a single person can just pick up and make a decision to use, and sadly in the cases of many poorly run security teams often won't deliver what many folks expect it to. But great to see done well when it is... also while realizing that there is no perfect protection, but most folks/companies are doing well if they just mitigate the more obvious risks.

As with making backups, the best plans start with what are you trying to protect against and then looking at ways of tightening security to help with that. As an example is it protecting client content? How does that content get onto and off of the computer? What else could possibly access it? Is it encrypted at rest (what happens if somebody steals the disk or the computer), how are encryption passwords and keys managed, etc. (and yes some of this might conflict with ease of use or maybe Pro Tools performance). Management of passwords and keys is a universal question that should always come up.

I hope that good larger companies (media companies/labels) have some useful sensible requirements here for remote workers if they allow them at all. But no they likely don't want to and should not discuss them publicly.
Reply With Quote
  #7  
Old 01-24-2024, 10:12 PM
EGS's Avatar
EGS EGS is offline
Member
 
Join Date: Nov 2004
Location: Chicago
Posts: 3,701
Default Re: Firewall

Quote:
Originally Posted by Goombot View Post
Random topic but does anyone who is mixing at home use a Firewall for extra security?
Of course. I use all the standard router & Windows firewalls. I also keep my OS updated, run security scans pretty often, and keep a few recent known-working boot drive images too. Having said that, I run Chrome browser and Pro Tools at the same time all the time.
__________________
Desktop build: PT 2020.5 / Win 11 / i9-11900K @ 5.1GHz / 64GB / 4TB NVMe PCIe 4 / Gigabyte Z590 Vision D / PreSonus 2626
Laptop: PT 2020.5 / Win 11 / i5-12500H / 16GB / 1TB NVMe / Lenovo IdeaPad 5i Pro / U-PHORIA UMC1820
Ancient/Legacy (still works!): PT 5 & 6 / OS9 & OSX / Mac G4 / DIGI 001
Click for audio/video demo
Click for resume
Reply With Quote
  #8  
Old 01-25-2024, 08:30 AM
EddieJones's Avatar
EddieJones EddieJones is offline
Avid
 
Join Date: Dec 2014
Location: Santa Cruz
Posts: 4,621
Default Re: Firewall

Make sure you keep the router firmware updated. Most breaches are though you accidentally giving up your security details.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Mac Firewall on or off? Dizzi45Z macOS 1 06-12-2012 01:21 AM
Firewall Question David McRell Aspera DigiDelivery 1 04-25-2006 09:31 AM
firewall? kmshroom 003, Mbox 2, Digi 002, original Mbox, Digi 001 (Mac) 3 02-08-2004 08:13 AM
Firewall ? Marc Cooreman Pro Tools TDM Systems (Mac) 2 01-03-2001 09:34 AM


All times are GMT -7. The time now is 09:02 AM.


Powered by: vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Limited. Forum Hosted By: URLJet.com