Re: Secure Linux From Scratch

Robert Day <[email protected]> Wed, 24 Dec 2003 12:44:38 -0500
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Wed, 2003-12-24 at 12:05, Archaic wrote:
> On Wed, Dec 24, 2003 at 01:52:26AM +0200, Christos Gioran wrote:
> > 
> > In fact, although libsafe's whitepaper claims that way, Immunux's whitepaper 
> > on StackGuard at the GCC procedings of 2003 notes that libsafe imposes some 

> 
> Both should be mentioned regardless of performance hits for the simple
> reason that you never want to count on one wall of safety when two can
> be had. Another example would be a home user being reckless just because
> they are behind a firewall. All fine and good until that one layer is
> pierced.

Not to be the person who takes things too literally here, but I just
can;t help it ;)

Why go with three layers, when 10 can be had?  A Port-Forwarding
Hardware Firewall / router box that only forwards opened ports to the
servers behind the network, hard-coded eeproms with port > ip maps so
that it cannot be penetrated, and no external configurations, etc. The
Linux box with it's own firewall limiting incoming connections to the
open ports only, and outgoing connections to the NAT server, with
authenticated services running chrooted on a triple-hardened software
base, with honeypots setup to re-route unexpected incoming traffic, and
double encrypted data on an encrypted partition of a locked server
cabinet etc. etc. 

Basically, the point is, Somewhere, you have to say Enough. I think
there will be a wave of agreement when I say we have to find a soft
balance between security and useability. Ultimate security is the pure
and simple non-existance of the computer in question. As soon as the
computer even exists, there is a security hole. Sure it is VERY small,
and NO one cares if you breach security on a disconnected system with
not even an OS on it, but, it can be done.  With that in mind, the
computer, however secure it is due to it's disconnection from everything
and lack of software, it is also useless as far as computers go.  The
level of security is inversely proportional to the level of useability.
This MUST be remembered.  If you want to build a locked-tight,
as-secure-as-it-can-be server, SLFS is NOT going to be the book you
read. You should already have the SLFS base knowlege, and you will be
building your own system using your own tested packages, and have no
need for SLFS. On the other hand, as a home user, or maybe a small-time
admin for a small netowrk, or even a mid-sized net where you have to
deal with Linux and Windows boxes, you don;t have eons of security
experience but Do have the need for a secure box that the average skrpt
kiddie has not a hope in hell of cracking, and most decent hackers would
either not be able to penetrate, or would have a VERY hard time getting
into. But, the serious hacker, the guy who can make hundreds of
trhousands a year doing security penetration for major corporations, the
guy who knows security like I know how to smoke my cigarette, he is
gonna find a way in if he wants to (although why would he right?)

The line must be drawn.  Here's a bone, go fight over it everyone ;)

  Rob Day (BOFH)

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page