Re: Linux vs Windows Firewalls

David Vehrs <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
On Fri, Sep 19, 2003 at 11:09:49PM -0800, John Andersen wrote:
> On Wednesday 10 September 2003 15:24, PK Carlisle wrote:
> > It -is- nice that a virus or data miner can only access my login
> > account, but I guess it seems little comfort considering what
> > programs want to store and send.  Linux appears to be wide open
> > to this exploitation.   Is it possible that the only reason this exploit
> > has not yet taken off is that Linux does not have enough market
> > share to be *worth* attacking in bulk, but that someday it possibly
> > might (if you took out 1% of the world's computers, would anyone
> > even notice)?
> 
> Yes, you would.  Linux, and various flavors of Unix RUN the
> Infrastructure of the internet.  To OWN someone else's linux box
> would give an attacker a tremendous advantage.
> 
> There is a reason MS boxes are not trusted at ISPs for
> anything but office work, and often not even for that.  There
> is a reason that Microsoft's Hotmail does not run on 
> Windows boxes.  There is a reason that the Microsoft Update
> site crawled behind a linux firewall when the last worm storm
> hit.  And there is a reason that all the worms and viruses
> target Microsoft products.
> 
> If you choose to believe the market share argument that's
> your business, and your folly.  Microsoft FUD mongers 
> are smileing gleefully on you.
> 
> If you trust your firewall's protection, why don't you publish its IP address 
> and Administrator password?  That's exactly what Russel
> Coker did for his Linux Journal article titled
> "Root for All on the SE Linux Play Machine".  He published
> root's password.  See it In Aug 2003 edition.

First, you should point out that this is Linux box is running all
of the NSA Security Enhanced patches.  That it is NOT A STANDARD
linux box.  That many of the patches used have yet to be auditted
for other security issues.  Its a good idea but its not quite ready
for a production environment.

Dave V.

-- 
David E Vehrs, System Engineer          Aspen Systems
[email protected]                       3900 Youngfield Street
Tel: +01 303 431 4606                   Wheat Ridge CO 80033, USA
Fax: +01 303 431 7196                   http://www.aspsys.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.