Re: next version

Jeffrey Watts <[email protected]>
Newsgroups gmane.linux.lsb.discuss
Message-ID <[email protected]>
On 5 May 2003, Dan Stromberg wrote:

> In the trade press, it is often said that no one knows how much linux is
> really out there.  Microsoft naturally uses this uncertainty to its
> advantage.
> 
> When UCI started discussing a licensing agreement with redhat, redhat
> wanted to know how many installations we had on campus.  We were wholly
> unable to tell them.

I understand that that can be a problem, but what if you turn it around?  
Ask UCI (go Anteaters!) if they know exactly how many Microsoft 
installations they have, and what version they're running.  They will have 
a number, but is it accurate?  There will be many illegal installations, 
and there will be many untracked legal ones.

This isn't a Linux issue - it's a IT management issue.  Most IT 
departments (especially in academia where staff and faculty are often 
encouraged to do their own thing) don't have a firm grasp on what is 
where.

For example, many sysadmins at Sprint have been covertly running Linux on 
our corporate-supplied laptops that are supposed to be running 
Windows2000.  I've been doing so for five years.

Our management has a similar problem to yours, and they've been pretty
progressive.  They've asked our Linux team (which I'm on) to set some
standards for security and maintenance (for Linux workstations), and the
policy is going to be that if you do run Linux, you need to either have it
comply, or you need to seek an exception.  If you do neither, you'll have
to answer to management.

> There's a need for a simple protocol that can identify a computer, over
> the internet, as a linux computer, and perhaps even which distribution,
> so we can get accurate counts.  It should punch through any firewall by
> default, and be drop dead simple to audit, to deter security problems.

I'm sorry, but there are large numbers of people and organizations that 
will NOT allow this.  I can assure you that Sprint will not.  Punching 
through a firewall?  Are you serious?  Even if you can get everyone to 
agree to do this, how are you going to implement this?  How are you going 
to connect to my "system ID server" on my private network when the IP 
is one of the 10.x.x.x, etc?

I know you didn't specifically say that this server would be required, but
when you're talking about the LSB that is the logical implication.  Also,
what would be the point of it if it weren't?  I doubt many of the distro
vendors would enable such a service by default, given how popular security
by obscurity is these days.  If no one enables it by default, it's of no
use for you.

> The usual argument against this is that it allows attackers to know what
> kind of computer they're going after, making their attack easier.  
> However, this argument does not hold water.  nmap, queso, xprobe, p0f,
> scapy and (other) port scanners make an attacker's id job easy anyway,
> while the lack of a formal protocol preserves the difficulty for an
> administrator.
>
> In other words, an attacker is happy with a best guess, and already has
> one, while an administrator or linux PR person needs something better.  
> The additional certainty in the hands of an attacker makes little
> difference.

The problem here is that you're describing a general solution to a very
specific problem.  You're advocating that EVERYONE make their systems
identify the OS version and distribution version to ANYONE that wants the
information (regardless of a firewall or security concerns), just so a
local sysadmin can scan their network.

As you pointed out before, nmap and others can already tell you, given a 
set of subnets, how many computers of which broad OS types are out there.  
Working with the netadmin, you could easily have him or her scan UCI's 
network and identify how many Linux machines are there.  So what you 
really are asking for is a distribution calling card.

Here's where I get practical.  Instead of advocating that all of the 
LSB-compliant Linux distributions require a daemon that can't be shut off, 
perhaps you ought to have your IT department do a better job of hardware 
and software inventorying?  You've already said that nmap can identify 
which systems are running Linux.  Why don't you simply go to their owners 
and ask what they're running?  More importantly, why haven't you been 
doing this already?

Remember, someday the Business Software Alliance will make a visit to UC
Irvine, and if you can't accurately account for every installation of
Windows they will happily eat your lunch.  If you don't know what is
installed where, you've got a bigger problem.

> I've given two reasons for the inclusion of such a protocol, and one
> response to the usual counterargument.

I appreciate your idea - it's definitely a great idea as a good Open 
Source project (heck, it might already exist).  But I personally don't 
think it's a practical addition to the LSB.  Perhaps others will disagree.

Jeffrey.

o-----------------------------------o
| Jeffrey Watts                     |
| [email protected]         o-----------------------------------------o
| System Administrator       | "Anyone who says you can have a lot of  |
| Network Systems Management |  widely dispersed people hack away on a |
| Sprint Communications      |  complicated piece of code and avoid    |
o----------------------------|  total anarchy has never managed a      |
                             |  software project."                     |
                             |  -- Andrew Tanenbaum                    |
                             |  Regarding Linux - USENET, 1992         |
                             o-----------------------------------------o
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.