RE: Third-Party Vendors

"Ridgeway, Alan" <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
>But I find it odd, you would talk about Win2k (or any windows platform) in the same post in which you address security.

Then you missed my point.
The original point said Linux was far superior to any OS.
Ya, Window 2000 has security issues in the base OS. Here here is a suprise SO DOES LINUX.
Guess what, SO DO Major UNIX vendors. I am on the security mailing lists of Microsoft, Red Hat, Debian, HP-UX, AIX, Tru-64.
I get as many security e-mails from each OS as I do from Microsoft. 
But the point was as far as writing a policy, and distributing it to all the workstations and
managing that policy, Novell and Microsoft do a lot better job then Linux at this point.
It is easy to take a swipe at the suggestion of MS, I notice is was hard for you to contradict my example with
RELEASED AND AVAILABLE software.

>And, Novell may be bringing these things to a linux box near you shortly.

I was pointing out that Linux is great in many areas. But here are some areas in which IT IS CURRENTLY not the best OS for the job. Novell NDS on Linux is currently vaporware. Hey, it's that what we accuse MS of doing ?

>if you will excuse me I have to go purge a couple
hundred SoBig worms from my in-box...

Sounds like you need better defense in depth. My mail server AV signatures caught the problem.

>> Access Control Lists: I know they are comming, or I can apply a kernel
>> patch, but most utils don't reconigze them yet. Hence it does not "really"
>> work.

>Hardly a necessity. ACLs often quickly devolve into an unmanagable morass
>of unmaintainable, forgotten, confusing, and in some cases dangerous
>quagmire.  They are often used as substitute for proper organization
>of the file system and made necessary by the ad-hoc nature of
>windows platforms

Tell that to the latest build of FreeBSD. Tell that to Sun regarding Solaris.




-----Original Message-----
From: John Andersen [mailto:jsa-qezjBH/[email protected]]
Sent: Friday, August 22, 2003 2:21 PM
To: [email protected]
Subject: Re: [Annoyances] Third-Party Vendors


On Friday 22 August 2003 10:24, Ridgeway, Alan wrote:
> >> If you ask me, Linux in it's own right is far superior to any other OS
> >> in it's own right.
>
> Except for the following:
>
> Access Control Lists: I know they are comming, or I can apply a kernel
> patch, but most utils don't reconigze them yet. Hence it does not "really"
> work.

Hardly a necessity. ACLs often quickly devolve into an unmanagable morass
of unmaintainable, forgotten, confusing, and in some cases dangerous
quagmire.  They are often used as substitute for proper organization
of the file system and made necessary by the ad-hoc nature of
windows platforms

> Write a policy and enforce across 1000 machines. You could use CFengine,
> but it still is not as nice as what Netware or Win2K offers.

Some of the netware tools were really great for this kind of stuff, but
even they could become unmanageable.  And, Novell may be bringing
these things to a linux box near you shortly.

> Silent install across 1000 machines. Again I could script or use Cfengine,
> but I would not say it superior to Netware or Win2K in this area.
>
> How about the Secure by Default of OpenBSD.

This is highly distro dependent, with some doing a way better
job than others.  RedHat seems to install by default in the
least secure mode.

But I find it odd, you would talk about Win2k (or any windows
platform) in the same post in which you address security.
-now, if you will excuse me I have to go purge a couple
hundred SoBig worms from my in-box...

 
-- 
_____________________________________
John Andersen
_______________________________________________
annoyances mailing list
[email protected]
http://michelangelo.renaissoft.com/mailman/listinfo/annoyances
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.