Firewall Wizards mailing list archives

Re: Worms, Air Gaps and Responsibility


From: Gwendolynn ferch Elydyr <gwen () reptiles org>
Date: Mon, 10 May 2004 11:32:25 -0400 (EDT)

On Sat, 8 May 2004, Mark Gumennik wrote:
LINUX on a desktop? - I am going back to desktop administration right
away. Hooray! - we will get paid more money than security gurus! And
instead of getting 5 people per 1000 users (whatever the standard is
right now) we will have to hire 25. Go employment for IS, I mean us !
AND how the heck do you propose to manage AAA? Any replacement for
domain infrastructure? - the only one I know today that is better then
MS is Novell NDS (and btw it's 10 years more mature, and btw it works on
LINUX ) Shall we use NDS? - Go back to that monster? Was it better
under their dictatorship?

Uhhhh. Too much coffee? Sugar?

I suspect that any desktop platform will inherently require more support
than a server platform - but that difference is related to the need to
help users to get their work done, as well as managing machines.

That you've left out NIS/NIS+, LDAP, Radius and Kerberos suggests to
me that you're not very familiar with what's availible for AAA under
Linux.

There's a reasonable arguement to be made for Linux being easier to
manage than Windows - there's a broad selection of tools designed to
handle user and application updates, not to mention the relative
simplicity of writing scripts and scheduling various tasks.

AND: where do you get the info about LINUX being more secure than the
Big Bad ? Read any serious info , like from bagtrack, LINUX had more
vulnerabilities for the past 3 years than any given MS OS

It's not about the -number- of vulnerabilities. It's about the degree
to which vulnerabilities create risk.  Frankly, I don't care if a
program that I don't run, but is available for Linux has a bug. I do
care if an email program or a web browser that's hooked into the kernel
of my operating system has a bug.

AND: I don't like the fact that LINUX security is mostly sponsored by
German and some other governments, just don't like it. Do you seriously
check all the code before installing the OS? Every distro?

That's ... one of the more peculiar assertions that I've heard in a
long time.  I'm starting to wonder if this message is a troll.  I suspect
that when you say "some other governments" you don't actually mean
"the US government too".  I also suspect that you've forgotten that this
is an international list.

Something else to mull on:

        http://www.xent.com/FoRK-archive/jan98/0090.html

        "The company has confidence that the American authorities
        responsible for this have full control over the keys
        and can ensure that they will not be misused."

Not exactly what I'd describe as ... reassuring.

That aside, if you're trying to suggest that government and corporate
sponsorship is somehow putting malicious code in Linux, you should also
suggest the same of Microsoft and Novell - and any number of other
entities.  While you're at it - do audit the windows source code...

Oh. I forgot. You can't.

cheers!
==========================================================================
"A cat spends her life conflicted between a deep, passionate and profound
desire for fish and an equally deep, passionate and profound desire to
avoid getting wet.  This is the defining metaphor of my life right now."

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: