Re: Security (was Third-Party Vendors)
Chris Knadle <Chris.Knadle-15hjz6xD4c1Wk0Htik3J/[email protected]>
| Newsgroups | gmane.linux.usability.annoyances |
|---|---|
| Organization | Aeroflex |
| Message-ID | <[email protected]> |
On security issues... > >But I find it odd, you would talk about Win2k (or any windows platform) in > > the same post in which you address security. > > Then you missed my point. > The original point said Linux was far superior to any OS. > Ya, Window 2000 has security issues in the base OS. Here here is a suprise > SO DOES LINUX. Guess what, SO DO Major UNIX vendors. So does Cisco. Do do handhelds. So do LinkSys routers running Linux. So does every device that is accessible by a human being and not behind a vault door that cannot stop a human from pulling the plug and creating a DoS problem. > I am on the security > mailing lists of Microsoft, Red Hat, Debian, HP-UX, AIX, Tru-64. I get as > many security e-mails from each OS as I do from Microsoft. But the point > was as far as writing a policy, and distributing it to all the workstations > and managing that policy, Novell and Microsoft do a lot better job then > Linux at this point. (IMHO) In some ways they're better, in some they're worse. M$ is not wonderful (or at least wasn't) concerning _admitting_ the problem once it's been discovered. They need a slightly larger clue-beating than Linux developers. Also, many of the patches that do come from M$ require reboots - and downtime. Linux and Unix, on the other hand, also have many legacy parts that have large security problems. NFS, file permissions and groups, etc. Like M$ OS's there are old parts that are not very secure, or are confusing enough that they become insecure. So Linux has it's vulnerabilities, too, and yes - if it were far more mainstream that would likely be apparent and there would be more published vulnerabilities for Linux. But it's open, it's free, and it doesn't have the BSA coming after it's users. [I'd like to say that it doesn't have a corporation coming after it's users, but, um, that situation has changed - those jerks...] However.. There is a reason that Universities and research sites don't have Windows machines for their front-end machines directly on the internet. If you compare Linux and M$ OS's there, that's a side-by-side comparison. Of the friends that do tests to see the _time of breakin_ (note: not _IF_, but _WHEN_), the M$ OS's get broken into far more quickly and frequently than the Linux or BSD machines do. That may change as Linux and BSD get more popular, but that's what I understand is happening right now. > It is easy to take a swipe at the suggestion of MS, I > notice is was hard for you to contradict my example with RELEASED AND > AVAILABLE software. It's far easier to take a swipe at M$ due to their political decisions, their denial, they're squashing of companies, or their war on OSS. Those are not laudible things. That they've got vulnerabilities that require fixes is just a fact of life. If your point is that everything requires patches and fixes, I agree - they do. It's impossible to add features that do not increase the liability of the same software as it grows to be more complex and impossible to predict every singly possibility of vulnerability. Anyway - 'nuff a that. There's a bunch of problems I have to try to go solve. - Chris -- Chris Knadle Chris.Knadle-15hjz6xD4c1Wk0Htik3J/[email protected]