Marcus Ranum: Firewalls and Six Dumb Ideas About Security
Before there was a firewall industry, there was a consultant at Digital Equipment Corporation with a very practical problem: how do you plug a company into the internet without letting the internet into the company?
Marcus Ranum's answer became a product, then a toolkit, then the setup behind the first White House email server. Over the next quarter century he built a company, wrote a book, ran security at Tenable and produced one of the most quoted rants in the business, a list of the six dumbest ideas in computer security.
Then he did something almost nobody in security does. He stopped, and started making things with his hands.
Marcus Ranum at a Glance
- A New Yorker, Ranum worked as a Unix engineer and consultant through the 1980s and into the early 1990s, including a year tuning a large distributed database for the University of Maryland.
- As a consultant at Digital Equipment Corporation he designed and implemented the DEC SEAL internet firewall in the early 1990s, a product his conference bios call the first commercial firewall, and managed its deployment at customers worldwide.
- At Trusted Information Systems he wrote the TIS Firewall Toolkit under an ARPA grant on behalf of the Executive Office of the President, and configured and ran whitehouse.gov for its first year.
- He went on to architect TIS's Gauntlet firewall, serve as chief scientist of V-ONE through its IPO and, early in 1997, found Network Flight Recorder, which he ran as president and CEO.
- He published The Myth of Homeland Security in 2003, and his 2005 essay "The Six Dumbest Ideas in Computer Security" became a classic of the genre.
- He was Tenable's chief security officer in the 2010s, keynoted conferences from Dublin to Vienna and gave a 2009 TEDx talk called "Internet Nails."
- Retired by 2021, he documents his woodturning and resin work on Badger Forge, the site that now lives at his old domain, and writes a blog called stderr.
The Life of Marcus Ranum
Before the Firewall Industry
Marcus J. Ranum came out of the Unix world of the 1980s as a software engineer, system manager and consultant, "active in the UNIX networking and security community," as his résumé put it. From September 1990 he spent a year as a consultant tuning a large distributed database system for the University of Maryland's Institute for Advanced Computer Science.
Then he went to Digital Equipment Corporation, again as a consultant. Companies were starting to wire themselves to the internet, and somebody had to design the thing that sat at the border. Ranum designed and implemented it: the DEC SEAL, or Secure External Access Link, a product he then helped deploy at customer sites around the world.
His conference bios have long called it the first commercial firewall product. When he was booked to keynote a Dublin cybercrime conference in 2012, Silicon Republic put it this way: "In 1990, while at Digital, he developed the Secure External Access Link which later became the first commercial firewall, the AltaVista Firewall."
The White House Gets Email
At Trusted Information Systems, where he became a senior scientist in November 1993, Ranum designed and implemented the TIS Internet Firewall Toolkit under a grant from ARPA on behalf of the Executive Office of the President. His résumé later called it "the de facto standard Internet firewall software."
He also configured and managed whitehouse.gov for its first year of operation, and Silicon Republic credited him with building the domain's first internet email server. The toolkit didn't stay in Washington: his résumé counted more than 4,000 sites running it and over a dozen commercial products built on technology licensed from TIS.
He went on to architect and manage TIS's own commercial product, the Gauntlet firewall. His papers from those years carry titles like "Thinking About Firewalls" and "A Toolkit and Methods for Building Internet Firewalls," and he taught tutorials at USENIX and SANS on firewalls, Unix internals and security policy.
Chief Scientist, Then CEO
In October 1995 Ranum became chief scientist at V-ONE Corporation, a security startup heading for the stock market. He helped write the business section of the prospectus, devised the "message" for the road show and presented the company's technology to investors and analysts as part of the IPO team.
Early in 1997 he founded his own company, Network Flight Recorder, and ran it as president and CEO. The name said what it was for, a flight recorder for networks, and intrusion-detection technology joined firewalls on the list of innovations credited to him. His job description on his résumé: "Responsibilities - all of them."
The Myth of Homeland Security
By the early 2000s Ranum was as well known for his writing as his code. In 2003 Wiley published his book The Myth of Homeland Security, whose title left little doubt about his view of the post-9/11 security boom.
Then, on September 1, 2005, from Morrisdale, Pennsylvania, he posted "The Six Dumbest Ideas in Computer Security." Number one was "Default Permit," the habit of allowing everything through a firewall except a short list of known bad things. Number two was "Enumerating Badness," the attempt to catalogue every threat, which he argued stopped making sense "sometime around 1992" when "the amount of Badness in the Internet began to vastly outweigh the amount of Goodness."
The essay became a classic. Five years later a commenter on Brian Krebs's blog called it mandatory reading, and it remains online in the Internet Archive after Ranum repurposed his domain for something very different.
Tenable and the Lecture Circuit
In the 2010s Ranum was chief security officer of Tenable Network Security, the Nessus company. He held that title when the Irish security community invited him to keynote its 2012 cybercrime conference, and when he gave a 2016 keynote at AppSec California on starting a metrics program.
His talks were the opposite of vendor pitches. He gave a 2009 TEDxMidAtlantic talk with the title "Internet Nails." At AusCERT in 2013 he asked whether borrowed land-war terms like "active defence" and "preemptive warfare" mapped onto anything real in cyberspace.
At DeepSec in Vienna in 2016 his keynote, "Security in my Rear-View Mirror," looked back on more than 30 years of IT security and the way old ideas keep getting re-invented and marketed as new.
He also had a sense of humor about the industry. A four-minute parody he posted in 2010, "Hitler and Cloud Computing Security," has been watched more than 240,000 times.
Badger Forge
By 2021 Ranum had retired, and when the TAG Cyber channel caught up with him that year it was to ask what he'd been up to during his retirement. Part of the answer lives on his old domain, ranum.com, now the home of Badger Forge, "Metal with Marcus," a workshop blog of rolling pins turned from baseball-bat blanks, resin-soaked burl bowls and a shop dust-collector manifold for 3-inch PVC pipe.
He also writes "stderr," a blog on the Freethought Blogs network that he's kept up since 2016, where his self-description runs: "computer security specialist, consultant, gamer, crafty artist, photographer, soap and cosmetic experimenter, and all-around surrealist." Recent posts range from fighter jets and capital punishment to AI art.
Marcus Ranum: Default Deny
Ranum's career is a reminder that the firewall wasn't inevitable. Somebody had to decide that the right default was "deny," build the box that enforced it and then spend years explaining why the industry kept drifting back to "permit."
These days his blog ranges far beyond firewalls, and his workshop turns maple and walnut into bowls and rolling pins.
The six dumbest ideas, unfortunately, are still in production.
QUOTE:
"Amateurs hack systems, professionals hack people."