Re: Security (was Third-Party Vendors)

Chris Knadle <Chris.Knadle-15hjz6xD4c1Wk0Htik3J/[email protected]>
Newsgroups gmane.linux.usability.annoyances
Organization Aeroflex
Message-ID <[email protected]>
On security issues...

> >But I find it odd, you would talk about Win2k (or any windows platform) in
> > the same post in which you address security.
>
> Then you missed my point.
> The original point said Linux was far superior to any OS.
> Ya, Window 2000 has security issues in the base OS. Here here is a suprise
> SO DOES LINUX. Guess what, SO DO Major UNIX vendors.

   So does Cisco.  Do do handhelds.  So do LinkSys routers running Linux.  So 
does every device that is accessible by a human being and not behind a vault 
door that cannot stop a human from pulling the plug and creating a DoS 
problem.

> I am on the security
> mailing lists of Microsoft, Red Hat, Debian, HP-UX, AIX, Tru-64. I get as
> many security e-mails from each OS as I do from Microsoft. But the point
> was as far as writing a policy, and distributing it to all the workstations
> and managing that policy, Novell and Microsoft do a lot better job then
> Linux at this point.

   (IMHO) In some ways they're better, in some they're worse.  M$ is not 
wonderful (or at least wasn't) concerning _admitting_ the problem once it's 
been discovered.  They need a slightly larger clue-beating than Linux 
developers.  Also, many of the patches that do come from M$ require reboots - 
and downtime.
   Linux and Unix, on the other hand, also have many legacy parts that have 
large security problems.  NFS, file permissions and groups, etc.  Like M$ 
OS's there are old parts that are not very secure, or are confusing enough 
that they become insecure.

   So Linux has it's vulnerabilities, too, and yes - if it were far more 
mainstream that would likely be apparent and there would be more published 
vulnerabilities for Linux.  But it's open, it's free, and it doesn't have the 
BSA coming after it's users.  [I'd like to say that it doesn't have a 
corporation coming after it's users, but, um, that situation has changed - 
those jerks...]

   However..  There is a reason that Universities and research sites don't 
have Windows machines for their front-end machines directly on the internet.  
If you compare Linux and M$ OS's there, that's a side-by-side comparison.
   Of the friends that do tests to see the _time of breakin_ (note: not _IF_, 
but _WHEN_), the M$ OS's get broken into far more quickly and frequently than 
the Linux or BSD machines do.
   That may change as Linux and BSD get more popular, but that's what I 
understand is happening right now.

> It is easy to take a swipe at the suggestion of MS, I
> notice is was hard for you to contradict my example with RELEASED AND
> AVAILABLE software.

   It's far easier to take a swipe at M$ due to their political decisions, 
their denial, they're squashing of companies, or their war on OSS.  Those are 
not laudible things.  That they've got vulnerabilities that require fixes is 
just a fact of life.

   If your point is that everything requires patches and fixes, I agree - they 
do.  It's impossible to add features that do not increase the liability of 
the same software as it grows to be more complex and impossible to predict 
every singly possibility of vulnerability.

   Anyway - 'nuff a that.  There's a bunch of problems I have to try to go 
solve.
	- Chris

-- 
Chris Knadle
Chris.Knadle-15hjz6xD4c1Wk0Htik3J/[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.