Re: next version
Jeffrey Watts <[email protected]>
| Newsgroups | gmane.linux.lsb.discuss |
|---|---|
| Message-ID | <[email protected]> |
On 5 May 2003, Dan Stromberg wrote: > In the trade press, it is often said that no one knows how much linux is > really out there. Microsoft naturally uses this uncertainty to its > advantage. > > When UCI started discussing a licensing agreement with redhat, redhat > wanted to know how many installations we had on campus. We were wholly > unable to tell them. I understand that that can be a problem, but what if you turn it around? Ask UCI (go Anteaters!) if they know exactly how many Microsoft installations they have, and what version they're running. They will have a number, but is it accurate? There will be many illegal installations, and there will be many untracked legal ones. This isn't a Linux issue - it's a IT management issue. Most IT departments (especially in academia where staff and faculty are often encouraged to do their own thing) don't have a firm grasp on what is where. For example, many sysadmins at Sprint have been covertly running Linux on our corporate-supplied laptops that are supposed to be running Windows2000. I've been doing so for five years. Our management has a similar problem to yours, and they've been pretty progressive. They've asked our Linux team (which I'm on) to set some standards for security and maintenance (for Linux workstations), and the policy is going to be that if you do run Linux, you need to either have it comply, or you need to seek an exception. If you do neither, you'll have to answer to management. > There's a need for a simple protocol that can identify a computer, over > the internet, as a linux computer, and perhaps even which distribution, > so we can get accurate counts. It should punch through any firewall by > default, and be drop dead simple to audit, to deter security problems. I'm sorry, but there are large numbers of people and organizations that will NOT allow this. I can assure you that Sprint will not. Punching through a firewall? Are you serious? Even if you can get everyone to agree to do this, how are you going to implement this? How are you going to connect to my "system ID server" on my private network when the IP is one of the 10.x.x.x, etc? I know you didn't specifically say that this server would be required, but when you're talking about the LSB that is the logical implication. Also, what would be the point of it if it weren't? I doubt many of the distro vendors would enable such a service by default, given how popular security by obscurity is these days. If no one enables it by default, it's of no use for you. > The usual argument against this is that it allows attackers to know what > kind of computer they're going after, making their attack easier. > However, this argument does not hold water. nmap, queso, xprobe, p0f, > scapy and (other) port scanners make an attacker's id job easy anyway, > while the lack of a formal protocol preserves the difficulty for an > administrator. > > In other words, an attacker is happy with a best guess, and already has > one, while an administrator or linux PR person needs something better. > The additional certainty in the hands of an attacker makes little > difference. The problem here is that you're describing a general solution to a very specific problem. You're advocating that EVERYONE make their systems identify the OS version and distribution version to ANYONE that wants the information (regardless of a firewall or security concerns), just so a local sysadmin can scan their network. As you pointed out before, nmap and others can already tell you, given a set of subnets, how many computers of which broad OS types are out there. Working with the netadmin, you could easily have him or her scan UCI's network and identify how many Linux machines are there. So what you really are asking for is a distribution calling card. Here's where I get practical. Instead of advocating that all of the LSB-compliant Linux distributions require a daemon that can't be shut off, perhaps you ought to have your IT department do a better job of hardware and software inventorying? You've already said that nmap can identify which systems are running Linux. Why don't you simply go to their owners and ask what they're running? More importantly, why haven't you been doing this already? Remember, someday the Business Software Alliance will make a visit to UC Irvine, and if you can't accurately account for every installation of Windows they will happily eat your lunch. If you don't know what is installed where, you've got a bigger problem. > I've given two reasons for the inclusion of such a protocol, and one > response to the usual counterargument. I appreciate your idea - it's definitely a great idea as a good Open Source project (heck, it might already exist). But I personally don't think it's a practical addition to the LSB. Perhaps others will disagree. Jeffrey. o-----------------------------------o | Jeffrey Watts | | [email protected] o-----------------------------------------o | System Administrator | "Anyone who says you can have a lot of | | Network Systems Management | widely dispersed people hack away on a | | Sprint Communications | complicated piece of code and avoid | o----------------------------| total anarchy has never managed a | | software project." | | -- Andrew Tanenbaum | | Regarding Linux - USENET, 1992 | o-----------------------------------------o