RE: Benifits of ASP CMS Hosted
"Paul D. Bain" <[email protected]>
| Newsgroups | gmane.comp.cms.cms-forum.general |
|---|---|
| Message-ID | <[email protected]> |
At +0200Thursday 5/13/04 09:13 AM, P. Bain wrote:
> Sure, if they have enough staff who know web administration using
>open source tools such as Apache, Tomcat, and MySQL / PostgreSQL. But many
>small businesses and trade associations do NOT. They have an IT staff that
>consists of one or two MCSE's (morons) who know nothing more than MS IIS, a
>notoriously insecure web server, and MS SQL Server, whose security record
>is almost as blemished as that of IIS. Furthermore, neither IIS nor SQL
>Server runs on Linux or FreeBSD, which are _much_ more secure than f_cking
>MS Windows.
>
>
>[Dominic Cronin] Sheesh - take it to alt.linux.advocacy! You can secure an
>MS system;
*NO*, you CANNOT secure an MS system. Your statement to the
contrary reveals that you know nothing of computer security. Ask a security
_expert_ (i.e., one does _not_hold an MCSE certification) whether it is
possible to secure a MS operating system. At least 90 percent of them will
say, "No."
I know several smart security experts. None of them hold a MCSE cert
because they knew, even in the mid-90's, that open source (OS) would
prevail over proprietary operating systems. How did they know that? Because
they are smart. So make sure that the security expert who you consult does
_not_ hold a MCSE. Those who hold an MCSE were not smart enough to realize
that Linux / FreeBSD would ultimately prevail over proprietary operating
systems. They did not realize that they should be studying OS instead of MS
operating systems.
> you can fail to secure whatever variety of LAMP++ you favour.
Agreed. But it is much easier to secure certain OS systems than it
is to secure MS systems. Examples would be Debian Linux and OpenBSD.
Applying security patches to a Debian system is quick, easy, and almost
never breaks the system (i.e., causes things to stop working as they
should), which is _not_ the case for MS systems. Indeed, that's one of the
reasons that Windows systems administrators often do not apply the security
patches from MS -- they do not want to break their systems.
> If
>this is an argument about to-host-or-not-to-host, then of course security is
>an issue, the argument being that you can pay your hosting provider to
>provide a secured turnkey solution, which includes employing appropriately
>qualified staff, whatever the platform.
Am I the only person on this list with a Slashdot user ID below
25,000? Where are all of the smart people?
-- Paul Bain