Re: next version

Dan Stromberg <[email protected]>
Newsgroups gmane.linux.lsb.discuss
Message-ID <[email protected]>
On Fri, 2003-05-02 at 18:37, Christopher Yeoh wrote:
> At 2003/5/2 14:44-0700  Dan Stromberg writes:
> > 
> > I have a suggestion for the next version of the LSB (or perhaps a
> > related standard).  How do I go about running it past the right eyes?  I
> > really think this would help linux acceptance in more than one way.
> 
> There is an LSB futures group that helps to manage additions to the
> LSB spec.
> 
> http://www.linuxbase.org/futures/
> 
> Modifications to features already in the standard could be discussed
> here.
> 
> Regards,
> 
> Chris

In the trade press, it is often said that no one knows how much linux is
really out there.  Microsoft naturally uses this uncertainty to its
advantage.

When UCI started discussing a licensing agreement with redhat, redhat
wanted to know how many installations we had on campus.  We were wholly
unable to tell them.

There's a need for a simple protocol that can identify a computer, over
the internet, as a linux computer, and perhaps even which distribution,
so we can get accurate counts.  It should punch through any firewall by
default, and be drop dead simple to audit, to deter security problems.

The usual argument against this is that it allows attackers to know what
kind of computer they're going after, making their attack easier. 
However, this argument does not hold water.  nmap, queso, xprobe, p0f,
scapy and (other) port scanners make an attacker's id job easy anyway,
while the lack of a formal protocol preserves the difficulty for an
administrator.

In other words, an attacker is happy with a best guess, and already has
one, while an administrator or linux PR person needs something better. 
The additional certainty in the hands of an attacker makes little
difference.

I've given two reasons for the inclusion of such a protocol, and one
response to the usual counterargument.

I hope you'll consider it.

-- 
Dan Stromberg DCS/NACS/UCI <[email protected]>
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQA+tnv2o0feVm00f/8RAsjiAJ0eK9WGBv/cbDgnGmeYo3QYvppoNACdG4lv
SQxBCx8Yq3vgfYbm1a7n6Fc=
=3jF0
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.