Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
DARPA-funded Linux security hub withers
Kevin Poulsen, SecurityFocus 2004-01-30

Two years after its hopeful launch, a U.S.-backed research project aimed at drawing skilled eyeballs to the thankless task of open-source security auditing is prepared to throw in the towel.

Comments Mode:
DARPA-funded Linux security hub withers 2004-01-31
Anonymous
I think the real lesson is that there just aren't sufficient security experts with the programming skills needed for such a task. I've been telling folks about this project since its announcment, but personally lack the intense experience with C that is required to be a contributor. I don't think ...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-01
Anonymous (1 replies)
Lets face it, linux users are still in a deluded state of mind where they ignorantly believe linux is already secure....

[ more ]  [ reply ]
Really? 2004-02-04
Anonymous
Then I assume you propose a new name for the Linux systems I am running?...

[ more ]  [ reply ]
Community awareness? 2004-02-02
Anonymous (1 replies)
I didn't even know about this until now, and I do a _lot_ of reading (including much security-related material).

Perhaps before throwing in the towel, they should have a push for new people? Getting front-page on /. about its demise is one thing, but I'm sure you would get more contributors if m...

[ more ]  [ reply ]
Community awareness? 2004-02-04
Anonymous
The same day SecurityFocus ran an article on Sardonix getting DARPA funding, Crispin submitted it to Slashdot. It was put briefly on the frontpage and then yanked for some reason. I had assumed the editors thought it too self-promotional; it looked a little like a press release....

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-02
Anonymous (1 replies)
Let's face it: You're trolling. I think most linux users are far more aware of the state of security on their box than Windows users. They know that their boxes can have security holes.

Let's face it: Most users of proprietary software are in a deluded state of mind when they ignoranyly believe ...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-02
Anonymous (1 replies)
he may have been trolling but he is not far wrong. linux users are no more security savy than windows users. 3 weeks ago I hacked several of my staff's linux systems to show them the dangers of not patches, I expected to be caught quickly as they are good sys admins and were just a little lax over t...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-04
Anonymous
Linux is like marijuana. Its not the dope that's bad, its the people who use it. Most Linux users are shrill, narrow-minded fools who refuse to acknowledge basic economic and marketet concepts. They rant and rave all day about the stupidity of Windows users and the vast superiority of Linux, but whe...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-02
Anonymous
> just aren't sufficient security experts with the

> programming skills needed for such a task

How about this correction:

"Just aren't sufficient security experts with the

programming skills needed for such a task, WILLING TO DO THIS ONEROUS AND THANKLESS TASK FOR FREE"...

...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-02
Anonymous (1 replies)
Five of us have been thinking about starting something like this. I at least would have gladly participated. Minor problem, first we hear of it is notice that it is ending!

Googled for Sardonix, found three articles and a few mailing list posts dated Feb 5th thru 8th of 2002. That's it. I...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-05
Anonymous
I completely agree. I think there are a number of people out there who might volunteer, but didn't

find out about the project through lack of advertising.

It seems like the money was wasted by developing the website but not publicizing it sufficiently.

...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-02
Anonymous
Bad attitude. I tend to keep my eye on all things security, and unfortunately..this is the first time Ive ever heard of this. Maybe thats the issue....

[ more ]  [ reply ]
The primary lesson: ALL developers need to know how to develop secure software 2004-02-02
Anonymous
I think one lesson here is that it's critical to make sure that ALL developers know how to develop secure software. Very, very few people are willing to just do code reviews all day, and Sardonix suggests that it's hard to set up such programs.

There is one counter-example: OpenBSD. It'd be int...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-03
Anonymous
Looks from here like the Sardonix web site developers just took a bunch of government money, kept the whole site a secret, closed the site down and walked off with their ill-gotten gains.

Reminds me of selling elevator tickets to freshmen. :-)

Wish I'd thought of it, first....

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-03
Anonymous
Article doesn't say just what anyone did to let people know this existed. I never heard of it before and I've been following security announcements on LWN and Slashdot for years.

...

[ more ]  [ reply ]
DARPA-funded Linux security hub withers 2004-02-03
Jeff
I read about this when they started the project and thought, "That's a great idea! I am looking forward to their findings." I would have liked to contribute, but am just not a programmer. Then ... nothing.

I believe someone else that posted here was right: They took the money and ran. Why else wo...

[ more ]  [ reply ]
The poor publicity was the real problem 2004-02-03
Roger
Several other contributors have made the same or similar comments, but I'll just throw in my .02 as well:

I regularly read /., Security Focus, and the SANS reading room, not to mention the security specific areas of several coders' websites. I subscribe to two security bulletin mailing lists, plus ...

[ more ]  [ reply ]
Ridiculous Idea 2004-02-04
Anonymous
It is absolutely naive to think that anyone in their right mind would do this. Labour over code and receive a pat on the back. Nonsense. This is not a carrot at the end of a stick rather a pea. With bugtraq depending on how you play the game be it a 0 day you get the thrill of causing a bit of cha...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus