Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Memo to Microsoft: Stay Secretive, Please
Jon Lasser, 2002-05-15

Unix and Linux security owes much to openness and public disclosure, but Microsoft is too far gone for sunshine to do any good.

Comments Mode:
...Until Microsoft redesigns from the ground up 2002-05-16
Matthew Kauffman (2 replies)
...Until Microsoft redesigns from the ground up 2002-05-16
Anonymous (2 replies)
...Until Microsoft redesigns from the ground up 2002-05-20
manually adding html tags to be safe (1 replies)
Memo to Microsoft: Stay Secretive, Please 2002-05-16
Not Really Anonymous (1 replies)
Memo to Microsoft: Stay Secretive, Please 2002-05-17
blane (1 replies)
RE: Memo to Microsoft: Stay Secretive, Please 2002-05-17
Not Really Anonymous (1 replies)
Another Linux/Unix Apologist Overlooks the Obvious 2002-05-16
Anonymous (7 replies)
Another Victim Overlooks the Obvious 2002-05-16
Anon (1 replies)
Another Linux/Unix Apologist Overlooks the Obvious 2002-05-17
Anonymous (1 replies)
Another Linux/Unix Apologist Overlooks the Obvious 2002-05-17
Anonymous Unix Gal (1 replies)
Let's Be Real 2002-05-21
Anonymous
Let's talk about security. With any OS, you tie down security for the system before putting it on the net. Everyone can agree that most compromised systems are due to some lapse in security. Unneeded services or daemons, not locking down the system, default passwords, etc. I have set Windows servers on the internet that have not been broken into in five different independent assessments by external auditors. It took me less time to lock down and monitor those system than it took the Unix admins to do theirs. It can be done. With best practices in place, I have been able to sleep at night through Code Red, Nimda and other events.

Many "Unix/Linux apologists" do what comes natural and lock down their systems when they are built, and maintain patches religiously. They overlook their own practice and berate the MS OS for the need to do the same thing. That is not necessarily solid engineering professionalism in my book.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/82/12697#12697
Memo to Microsoft: Stay Secretive, Please 2002-05-21
blacklight (1 replies)
Another attempt at trying to get fired 2002-05-24
Someone fire this guy :\







 

Privacy Statement
Copyright 2009, SecurityFocus