Re: SLFS book chapter proposals

Robert Day <[email protected]> Sat, 27 Dec 2003 13:55:40 -0500
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Sat, 2003-12-27 at 13:08, jmh wrote:

> 
> I'm wondering if the goal shouldn't be to ultimately replace
> LFS with a version that includes the security elements. That
> might allow a core book in a couple of years with the gcc 
> 3.4.4 (was that it?) and the other core parts that are not 
> yet ready for release. In the interrim the ideas about
> patching existing systems and apps would provide some 
> immedate means of educating people like me about how
> to build such a system and allow those working on producing
> that knowledge in a book form to work out their presentaions
> and the strucutre of a new LFS book.
> 
> Just seems to me that securing a system is about as 
> fundamental as one can get and it's becoming an necessary 
> part of any OS. Rather than thinking of [SH]LFS as a 
> separate effort perhaps it's better to consider it a natural 
> evolution of LSF. Maybe that steps on toes, I don't know who 
> from the LFS efforts are involved in this or if they see no 
> reason to want to get involved and would resist any such 
> evolution in LFS.
> 
> My 2 cents and worth almost half of that ;-)
> 
> jmh


Only probs I would have with that is that for the average home user,
Secure systems are a moot point, or overkill...  ie your average home
users' desktop, hiding behind a Firewall/Router box, does not need the
full blown security of what we see SLFS as...  we think SLFS should be /
will be the ultimate Secure system taken from the ground. Other texts
out there deal with securing an existing app, or an existing distro.. 
what I think we should look at is security from the ground up, with as
much security as we can fit in without hindering the system to the point
that it cannot be used for much.  That point alone I think describes
SLFS as I think it should be. Another security text that expands on what
is already there the community does not really need. What the Linux
world is missing, or what I have never seen, is a document that
describes, and teaches, security at it's lowest level, and is complete
as it can be. If we can create a document that teaches the LFS folks,
and the rest of the crowds, Security in Linux and how to properly
impliment it from the ground to the applications, then we will have
something to be proud of, and something that the community at large can
really use.

That's where I see it anyhow..   there appears to be some digression in
this dept, so we're gonna have to get that settled before we can do
anything else.  

  Rob Day (BOFH)

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page