RE: Security (was Third-Party Vendors)

"Ridgeway, Alan" <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
>If your point is that everything requires patches and fixes, I agree - they 
do.

Actually my original point was Linux was not superior in everything.

I pointed out that when it comes to making a policy across a large network
with 1000 of users and the tools from Novell and Microsoft are better then was
is available in Linux. 

Patches are not relevant to my point. I agree that MS patches can suck
since some force a reboot and other patches need to be reissued (MS SQL last week)

But compare setting permissions for printers/network resources(shares)/proxy/etc.
and you will find that the Linux roll-your-own hack this and script the other becomes
diffciult to maintain. CFengine and scripts can get you so far. Then compare that with
what you can do with NetWare and Win2K, Linux is harder to maintain UNDER THIS SITUATION.

As pasted int he past, if I have to build any of the following:

Web Server
Light/Medium router/firewall
Network monitor (RRD Tool)/ sniffer 
Security tools (Pen testing/vuln testing/IDS/port scanning)
DNS/Mail/FTP

I would use Linux because it is the best tools for the job/price.

Hence I have to restate my annoyance of anyone who thinks that if
someone suggests Linux is not the best in everything, then that person is
a MS hack. ;)

>If your point is that everything requires patches and fixes, I agree - they 
do.
It was not my point, but I agree. If you saw my mailbox, you could not help but agree. ;)

Alan





-----Original Message-----
From: Chris Knadle [mailto:Chris.Knadle-15hjz6xD4c1Wk0Htik3J/[email protected]]
Sent: Monday, August 25, 2003 1:30 PM
To: [email protected]
Subject: Re: [Annoyances] Security (was Third-Party Vendors)


On security issues...

> >But I find it odd, you would talk about Win2k (or any windows platform) in
> > the same post in which you address security.
>
> Then you missed my point.
> The original point said Linux was far superior to any OS.
> Ya, Window 2000 has security issues in the base OS. Here here is a suprise
> SO DOES LINUX. Guess what, SO DO Major UNIX vendors.

   So does Cisco.  Do do handhelds.  So do LinkSys routers running Linux.  So 
does every device that is accessible by a human being and not behind a vault 
door that cannot stop a human from pulling the plug and creating a DoS 
problem.

> I am on the security
> mailing lists of Microsoft, Red Hat, Debian, HP-UX, AIX, Tru-64. I get as
> many security e-mails from each OS as I do from Microsoft. But the point
> was as far as writing a policy, and distributing it to all the workstations
> and managing that policy, Novell and Microsoft do a lot better job then
> Linux at this point.

   (IMHO) In some ways they're better, in some they're worse.  M$ is not 
wonderful (or at least wasn't) concerning _admitting_ the problem once it's 
been discovered.  They need a slightly larger clue-beating than Linux 
developers.  Also, many of the patches that do come from M$ require reboots - 
and downtime.
   Linux and Unix, on the other hand, also have many legacy parts that have 
large security problems.  NFS, file permissions and groups, etc.  Like M$ 
OS's there are old parts that are not very secure, or are confusing enough 
that they become insecure.

   So Linux has it's vulnerabilities, too, and yes - if it were far more 
mainstream that would likely be apparent and there would be more published 
vulnerabilities for Linux.  But it's open, it's free, and it doesn't have the 
BSA coming after it's users.  [I'd like to say that it doesn't have a 
corporation coming after it's users, but, um, that situation has changed - 
those jerks...]

   However..  There is a reason that Universities and research sites don't 
have Windows machines for their front-end machines directly on the internet.  
If you compare Linux and M$ OS's there, that's a side-by-side comparison.
   Of the friends that do tests to see the _time of breakin_ (note: not _IF_, 
but _WHEN_), the M$ OS's get broken into far more quickly and frequently than 
the Linux or BSD machines do.
   That may change as Linux and BSD get more popular, but that's what I 
understand is happening right now.

> It is easy to take a swipe at the suggestion of MS, I
> notice is was hard for you to contradict my example with RELEASED AND
> AVAILABLE software.

   It's far easier to take a swipe at M$ due to their political decisions, 
their denial, they're squashing of companies, or their war on OSS.  Those are 
not laudible things.  That they've got vulnerabilities that require fixes is 
just a fact of life.

   If your point is that everything requires patches and fixes, I agree - they 
do.  It's impossible to add features that do not increase the liability of 
the same software as it grows to be more complex and impossible to predict 
every singly possibility of vulnerability.

   Anyway - 'nuff a that.  There's a bunch of problems I have to try to go 
solve.
	- Chris

-- 
Chris Knadle
Chris.Knadle-15hjz6xD4c1Wk0Htik3J/[email protected]


_______________________________________________
annoyances mailing list
[email protected]
http://michelangelo.renaissoft.com/mailman/listinfo/annoyances
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.