On Microsoft's "EAL4 Certification"
Martin Maney <[email protected]> Fri, 15 Nov 2002 20:20:33 -0600
| Newsgroups | gmane.org.user-groups.luni.general |
|---|---|
| Message-ID | <[email protected]> |
The good news is, Shapiro tells it like it is:
Security experts have been saying for years that the the security
of the Windows family of products is hopelessly inadequate. Now
there is a rigorous government certification confirming this.
The bad news is, Shapiro tells it like it is:
This may be the best that Microsoft can do, but it is very
important for you as a user to understand that These requirements
are not good enough to make the system secure. It also needs to be
acknowledged that commercial UNIX-based systems like Linux aren't
any better (though they are more resistant to penetration).
More gory details here:
http://eros.cs.jhu.edu/~shap/NT-EAL4.html
(thanks to Bruce's pointer in the latest issue of the Crypto-Gram
Newsletter - http://www.counterpane.com/crypto-gram-0211.html)
--
One lesson I've learned from my years as Linux's hood ornament is that
there's something worse: some folks can't be content to just take things
too seriously on their own. They're not happy unless they can convince
others to go along with their obsession. -- Linus