On Microsoft's "EAL4 Certification"

Martin Maney <[email protected]> Fri, 15 Nov 2002 20:20:33 -0600
Newsgroups gmane.org.user-groups.luni.general
Message-ID <[email protected]>
The good news is, Shapiro tells it like it is:

    Security experts have been saying for years that the the security
    of the Windows family of products is hopelessly inadequate. Now
    there is a rigorous government certification confirming this.

The bad news is, Shapiro tells it like it is:

    This may be the best that Microsoft can do, but it is very
    important for you as a user to understand that These requirements
    are not good enough to make the system secure. It also needs to be
    acknowledged that commercial UNIX-based systems like Linux aren't
    any better (though they are more resistant to penetration).

More gory details here:

    http://eros.cs.jhu.edu/~shap/NT-EAL4.html

(thanks to Bruce's pointer in the latest issue of the Crypto-Gram
Newsletter - http://www.counterpane.com/crypto-gram-0211.html)

-- 
One lesson I've learned from my years as Linux's hood ornament is that
there's something worse: some folks can't be content to just take things
too seriously on their own.  They're not happy unless they can convince
others to go along with their obsession.  -- Linus