Re: Linux vs Windows Firewalls
David Vehrs <[email protected]>
| Newsgroups | gmane.linux.usability.annoyances |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Sep 19, 2003 at 11:09:49PM -0800, John Andersen wrote: > On Wednesday 10 September 2003 15:24, PK Carlisle wrote: > > It -is- nice that a virus or data miner can only access my login > > account, but I guess it seems little comfort considering what > > programs want to store and send. Linux appears to be wide open > > to this exploitation. Is it possible that the only reason this exploit > > has not yet taken off is that Linux does not have enough market > > share to be *worth* attacking in bulk, but that someday it possibly > > might (if you took out 1% of the world's computers, would anyone > > even notice)? > > Yes, you would. Linux, and various flavors of Unix RUN the > Infrastructure of the internet. To OWN someone else's linux box > would give an attacker a tremendous advantage. > > There is a reason MS boxes are not trusted at ISPs for > anything but office work, and often not even for that. There > is a reason that Microsoft's Hotmail does not run on > Windows boxes. There is a reason that the Microsoft Update > site crawled behind a linux firewall when the last worm storm > hit. And there is a reason that all the worms and viruses > target Microsoft products. > > If you choose to believe the market share argument that's > your business, and your folly. Microsoft FUD mongers > are smileing gleefully on you. > > If you trust your firewall's protection, why don't you publish its IP address > and Administrator password? That's exactly what Russel > Coker did for his Linux Journal article titled > "Root for All on the SE Linux Play Machine". He published > root's password. See it In Aug 2003 edition. First, you should point out that this is Linux box is running all of the NSA Security Enhanced patches. That it is NOT A STANDARD linux box. That many of the patches used have yet to be auditted for other security issues. Its a good idea but its not quite ready for a production environment. Dave V. -- David E Vehrs, System Engineer Aspen Systems [email protected] 3900 Youngfield Street Tel: +01 303 431 4606 Wheat Ridge CO 80033, USA Fax: +01 303 431 7196 http://www.aspsys.com