<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://www.osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/23463/Linux_Security_-_a_Few_Useful_Tactical_Tips</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2013, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Tue, 18 Jun 2013 06:32:28 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>Good practical advice</title>
			<link>http://www.osnews.com/thread?430873</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430873</guid>
			<description>It is nice to see some practical advice regarding security. Now I am off to investigate gufw!</description>
			<pubDate>Mon, 21 Jun 2010 09:56:00 GMT</pubDate>
			<author>donotreply@osnews.com (Nitrodist)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>gufw</title>
			<link>http://www.osnews.com/thread?430877</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430877</guid>
			<description>Ok, someone has spent countless hours coding and debugging his new masterpiece app and yet couldn't spend five minutes thinking about a real, at least pronounceable name? I mean, gufw?</description>
			<pubDate>Mon, 21 Jun 2010 10:33:00 GMT</pubDate>
			<author>donotreply@osnews.com (Bending Unit)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: gufw</title>
			<link>http://www.osnews.com/thread?430878</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430878</guid>
			<description>Indeed, the name is just horrible. And besides, it looks pretty but has almost no features whatsoever. Firestarter ( <a href="http://www.fs-security.com/" rel="nofollow">http://www.fs-security.com/</a> ) may not be as pretty but it's a lot more functional and serves much better as a GUI for the Linux firewall system.</description>
			<pubDate>Mon, 21 Jun 2010 10:51:00 GMT</pubDate>
			<author>donotreply@osnews.com (WereCatf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: gufw</title>
			<link>http://www.osnews.com/thread?430879</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430879</guid>
			<description>GUi Uncomplicated FireWall. Seems pretty logical, though not as sexy as iGUFW.Edited 2010-06-21 11:13 UTC</description>
			<pubDate>Mon, 21 Jun 2010 11:10:00 GMT</pubDate>
			<author>donotreply@osnews.com (flanque)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: gufw</title>
			<link>http://www.osnews.com/thread?430880</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430880</guid>
			<description>Unfortunately Firestarter isn't particularly maintained anylonger, except occasional patches from the community. Otherwise a (very bestest) great GUI-tool for managing firewalls.</description>
			<pubDate>Mon, 21 Jun 2010 11:10:00 GMT</pubDate>
			<author>donotreply@osnews.com (dylansmrjones)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: gufw</title>
			<link>http://www.osnews.com/thread?430882</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430882</guid>
			<description>Unfortunately Firestarter isn't particularly maintained anylonger, except occasional patches from the community. Otherwise a (very bestest) great GUI-tool for managing firewalls.<br />
<br />
What little I have used it I haven't found any bugs or missing features, the only thing that needs improvement is the looks and flow of action. And that should be rather easy to improve on, I might even try it myself when I get bored <img src="/images/emo/smile.gif" alt=";)" /></description>
			<pubDate>Mon, 21 Jun 2010 11:29:00 GMT</pubDate>
			<author>donotreply@osnews.com (WereCatf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: gufw</title>
			<link>http://www.osnews.com/thread?430885</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430885</guid>
			<description><div class="cquote">GUi Uncomplicated FireWall. </div><br />
And that's not even good English. <img src="/images/emo/smile.gif" alt=";)" />  A more correct name would have been: Uncomplicated GUI Firewall (UGF). But then again programmers like to program, not think up fancy names or write documentation. ;-)</description>
			<pubDate>Mon, 21 Jun 2010 12:16:00 GMT</pubDate>
			<author>donotreply@osnews.com (ggeldenhuys)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Security</title>
			<link>http://www.osnews.com/thread?430886</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430886</guid>
			<description>Back in college, the course on Operating Systems had this to say on Linux security:<br />
<br />
&quot;Linux is both the least and most secure OS there is. It all depends on how much time and effort the admin puts in to properly configuring it.&quot;</description>
			<pubDate>Mon, 21 Jun 2010 12:20:00 GMT</pubDate>
			<author>donotreply@osnews.com (Terg)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Security</title>
			<link>http://www.osnews.com/thread?430887</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430887</guid>
			<description><div class="cquote">Back in college, the course on Operating Systems had this to say on Linux security: <br />
<br />
&quot;Linux is both the least and most secure OS there is. It all depends on how much time and effort the admin puts in to properly configuring it.&quot; </div><br />
<br />
Well that's not really true as, generally speaking, Linux distros ship with more secure defaults than Windows does.<br />
<br />
However, it is fair to say that no OS is secure if you stick an experienced idiot in front of it. i.e. the kind of users who are experienced enough to know how to do stuff but not smart enough to know they shouldn't do it.  (unfortunately I think we've all met at least one of these guys and I'm sure a few of you guys has made a living out of fixing their computers)</description>
			<pubDate>Mon, 21 Jun 2010 12:37:00 GMT</pubDate>
			<author>donotreply@osnews.com (Laurence)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Link error</title>
			<link>http://www.osnews.com/thread?430889</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430889</guid>
			<description>The link to the article about white-listing vs black-listing is a file:// URL. (And it includes a Windows drive letter!)Edited 2010-06-21 13:09 UTC</description>
			<pubDate>Mon, 21 Jun 2010 13:08:00 GMT</pubDate>
			<author>donotreply@osnews.com (Zifre)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?430890</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430890</guid>
			<description>While I agree that anti-virus is pretty pointless on Linux, and even detrimental on Windows I think your reasons are nearly all flawed.<br />
<br />
<b>1. User account stops viruses getting root</b><br />
<br />
This is largely moot. Viruses aren't really interested in gaining root access. They can do nearly anything as the user anyway - key-logging, sending spam, DDoS, and so on. Besides once you have access to a user's account it is trivial to gain root - just change their path to point to a fake 'sudo' program which logs their password.<br />
<br />
<b>2. System updates provide security fixes for all software.</b><br />
<br />
Ok this is a fair point.<br />
<br />
<b>3. Software is obtained from trusted repository</b><br />
<br />
This is true up to a point. I'd bet most linux users install stuff from outside the repositories, and besides we've already seen examples of mirrors, and even source code being maliciously modified.<br />
<br />
<b>4. By default files aren't executable</b><br />
<br />
This is just silly. Most viruses work either by buffer overflow type exploits, or by tricking the user into running a program. File permissions aren't going to help in either case. By the way, you can easily execute non-'executable' binaries like this:<br />
<br />
/lib/ld-linux-x86-64.so.2 ./a_file<br />
<br />
<b>5. Diversity</b><br />
<br />
This is true. Although I'd wager Ubuntu is becoming popular enough to count as a single target.<br />
<br />
<b>6. People will see vulnerabilities in open-source code.</b><br />
<br />
Well evidently not, otherwise there wouldn't be any need for security updates. See also the Underhanded C Contest: <a href="http://underhanded.xcott.com/" rel="nofollow">http://underhanded.xcott.com/</a><br />
<br />
<b>7. Linux users are more skillfull.</b><br />
<br />
True, I suppose.<br />
<br />
The real reason you don't need anti-virus on linux is because there are a very very small number of linux viruses. And that is almost certainly due to the fact that it has a 1% market share (and probably the diversity and skill factors to some extent).</description>
			<pubDate>Mon, 21 Jun 2010 13:46:00 GMT</pubDate>
			<author>donotreply@osnews.com (Timmmm)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>insecurity</title>
			<link>http://www.osnews.com/thread?430891</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430891</guid>
			<description>&quot;Well, firewall seems like the best single solution overall.&quot;<br />
 <br />
 Firewall won't save you from anything by itself and the only meaningful reason of using fws is when certain hosts need access to certain service. On a workstation you can pretty much disable/remove every network daemon like ssh, apache, mysql etc. or if you need them to develop stuff then just bind them to localhost. <br />
 <br />
 &quot;It's useful and sometimes rather necessary. Anti-virus and malware scanners are definitely not needed.&quot;<br />
 <br />
 Then why do you even mention them? Most of the linux AVs were made for mail gws or to scan fileservers and their detection rate is far worst than what their windows version can offer. Except clamav because thats crap on both. If you would have to write a list which av is the worst clamav would be somewhere on top.<br />
 <br />
 You should've rather write about rootkit detectors like: <a href="http://www.chkrootkit.org/" rel="nofollow">http://www.chkrootkit.org/</a><br />
 <br />
 <br />
 One of the best nix sec guide I read in the past (good for workstations too) was this one, unfinished unfortunately:<br />
 <br />
 <a href="http://slackware.asmonet.net/index.php?dzial=artykuly&amp;p=5" rel="nofollow">http://slackware.asmonet.net/index.php?dzial=artykuly&amp;p=5</a> Edited 2010-06-21 13:54 UTC</description>
			<pubDate>Mon, 21 Jun 2010 13:50:00 GMT</pubDate>
			<author>donotreply@osnews.com (xaeropower)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Small typographic error</title>
			<link>http://www.osnews.com/thread?430892</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430892</guid>
			<description>&quot;I've bored the readers of my personal websiteto death...&quot;<br />
<br />
Not the &quot;websiteto&quot; bit. I think that should be reader (singular)?<br />
<br />
:-)<br />
<br />
This seems to be an article about how great your own piece of software is... if OS news is going to let people advertise they could at least tell people about it first like: Advertisment follows...</description>
			<pubDate>Mon, 21 Jun 2010 13:58:00 GMT</pubDate>
			<author>donotreply@osnews.com (Coxy)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Small typographic error</title>
			<link>http://www.osnews.com/thread?430893</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430893</guid>
			<description>Two questions for you: What are you smoking, and can I get some of it?</description>
			<pubDate>Mon, 21 Jun 2010 14:03:00 GMT</pubDate>
			<author>donotreply@osnews.com (dylansmrjones)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Security</title>
			<link>http://www.osnews.com/thread?430894</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430894</guid>
			<description>Linux also ships with more outdated and insecure packages, than the latest version of Windows.</description>
			<pubDate>Mon, 21 Jun 2010 14:04:00 GMT</pubDate>
			<author>donotreply@osnews.com (fanboi_fanboi)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: gufw</title>
			<link>http://www.osnews.com/thread?430898</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430898</guid>
			<description>GUFW is a GUI for UFW, where UFW means &quot;Uncomplicated FireWall&quot; (formerly &quot;Ubuntu FireWall&quot;), so the programmer only added the G part.<br />
<br />
The programmer is spanish, and his english isn't very good, so instead of bullying him, you should be thanking the extra work to translate into english so you can use it, or make your own program and try to do a better work.Edited 2010-06-21 14:32 UTC</description>
			<pubDate>Mon, 21 Jun 2010 14:28:00 GMT</pubDate>
			<author>donotreply@osnews.com (GatoLoko)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>The biggest threat is you</title>
			<link>http://www.osnews.com/thread?430899</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430899</guid>
			<description>One of the biggest security concern for home users is to protect their data from themselves. Baking up your data and running with unprivileged account helps a lot.</description>
			<pubDate>Mon, 21 Jun 2010 14:28:00 GMT</pubDate>
			<author>donotreply@osnews.com (spiderman)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Security</title>
			<link>http://www.osnews.com/thread?430900</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430900</guid>
			<description><div class="cquote">Linux also ships with more outdated and insecure packages, than the latest version of Windows. </div><br />
<br />
Because Windows retail boxes update themselves while sitting on the shelves at the store, right?</description>
			<pubDate>Mon, 21 Jun 2010 14:33:00 GMT</pubDate>
			<author>donotreply@osnews.com (ichi)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Inaccurate and misleading statement</title>
			<link>http://www.osnews.com/thread?430901</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430901</guid>
			<description>&quot;You can run a comfortable desktop life in Linux without so much as lifting a finger, with most distributions configured properly, including firewall enabled and running and hardening profiles preconfigured for you.&quot;<br />
<br />
This is completely untrue.  You explain how to minimize risk, however you still have to be careful about what you install or run, or you can still be exploited just like anyone else.<br />
<br />
You do NOT need root to be exploited.  Implying that users are safe by nature of running Linux is a very dangerous thing to tell to people that don't know better.<br />
<br />
Please update your article.</description>
			<pubDate>Mon, 21 Jun 2010 14:37:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?430902</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430902</guid>
			<description><div class="cquote"><br />
<b>7. Linux users are more skillfull.</b><br />
<br />
True, I suppose.<br />
 </div><br />
<br />
This is no longer true.  The stated goal of Ubuntu is to build a consumer distribution, and it is being sold by Linux zealots that non-skilled users are safe using it.<br />
<br />
This has opened a wide vector for attack.</description>
			<pubDate>Mon, 21 Jun 2010 14:40:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: The biggest threat is you</title>
			<link>http://www.osnews.com/thread?430903</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430903</guid>
			<description><div class="cquote">One of the biggest security concern for home users is to protect their data from themselves. Baking up your data and running with unprivileged account helps a lot. </div><br />
<br />
You can delete, or ship user data without root escalation so I fail to see how running with a non-privileged account helps here.<br />
<br />
Keeping backups is a good practice.</description>
			<pubDate>Mon, 21 Jun 2010 14:42:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Security</title>
			<link>http://www.osnews.com/thread?430907</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430907</guid>
			<description>Welcome to every OS ever created.</description>
			<pubDate>Mon, 21 Jun 2010 14:59:00 GMT</pubDate>
			<author>donotreply@osnews.com (Soulbender)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: insecurity</title>
			<link>http://www.osnews.com/thread?430908</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430908</guid>
			<description><div class="cquote">Firewall won't save you from anything by itself </div><br />
<br />
Yes, I agree. I really don't see much point in packet filters on workstations. Either you want to run a certain daemon and then it needs open ports or you don't and you just don't run it. If daemons are running with listening ports that shouldn't either you screwed up or your distro is fundamentally broken.<br />
<br />
<div class="cquote">Except clamav because thats crap on both. </div><br />
<br />
I'd have to disagree, in my experience it's quite capable at mail scanning. Sure beats most the Windows junk AV's.</description>
			<pubDate>Mon, 21 Jun 2010 15:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (Soulbender)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: gufw</title>
			<link>http://www.osnews.com/thread?430909</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430909</guid>
			<description>I thought Gnome UFW.</description>
			<pubDate>Mon, 21 Jun 2010 15:12:00 GMT</pubDate>
			<author>donotreply@osnews.com (Soulbender)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: insecurity</title>
			<link>http://www.osnews.com/thread?430913</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430913</guid>
			<description><div class="cquote">Firewall won't save you from anything by itself and the only meaningful reason of using fws is when certain hosts need access to certain service. On a workstation you can pretty much disable/remove every network daemon like ssh, apache, mysql etc. or if you need them to develop stuff then just bind them to localhost. </div><br />
<br />
A local firewall is very useful, even on a Linux computer when it's directly connected to the internet (home, free public WIFI, etc).<br />
<br />
There are a lot of network based attacks that computers without firewalls are vulnerable to.<br />
<br />
man in the middle attacks, spoofing, etc.  It also keeps ports that shouldn't be exposed to the internet away from the internet.</description>
			<pubDate>Mon, 21 Jun 2010 15:20:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: gufw</title>
			<link>http://www.osnews.com/thread?430914</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430914</guid>
			<description>But... it is far easier to complain than contribute... <img src="/images/emo/wink.gif" alt=";)" /></description>
			<pubDate>Mon, 21 Jun 2010 15:24:00 GMT</pubDate>
			<author>donotreply@osnews.com (jgagnon)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Security - ah.. that's wat it is</title>
			<link>http://www.osnews.com/thread?430917</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430917</guid>
			<description>Ah, thanks for that heads up. That Windows shipping with more up to date programs and patches would explain the 80 fed into my shiny new Windows machine last Friday.</description>
			<pubDate>Mon, 21 Jun 2010 15:41:00 GMT</pubDate>
			<author>donotreply@osnews.com (jabbotts)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Security</title>
			<link>http://www.osnews.com/thread?430918</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430918</guid>
			<description><div class="cquote">Well that's not really true as, generally speaking, Linux distros ship with more secure defaults than Windows does.  </div><br />
<br />
And may I remind people that Linux security features are not even turned up to full blast on default installations. It's this good out of the box but it's not even trying. There's room for increasing Linux security two-fold or more. Consider:<br />
<br />
* mandatory AppArmor-based software whitelisting;<br />
* mandatory separate /home and /tmp partitions with noexec,nodev,nosuid;<br />
* restricting software installation to official repositories and their mirrors and denying direct install of debs/rpms/install kits by default;<br />
* integrating and shipping default kernels that feature better ASLR and NX bit support.</description>
			<pubDate>Mon, 21 Jun 2010 15:42:00 GMT</pubDate>
			<author>donotreply@osnews.com (wirespot)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?430919</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430919</guid>
			<description><div class="cquote">Viruses aren't really interested in gaining root access. They can do nearly anything as the user anyway - key-logging, sending spam, DDoS, and so on. </div><br />
 <br />
 Note: don't call them viruses, call them worms. Viruses are a different beast (they don't use networking as a vector).<br />
 <br />
 Second, it's not that easy. As an unpriviledged user you can NOT snoop on other users or open ports under 1024 (which is where most legitimate servers like to reside). But yes, you have network access so spam and DoS are valid points.<br />
 <br />
 <div class="cquote">Besides once you have access to a user's account it is trivial to gain root - just change their path to point to a fake 'sudo' program which logs their password. </div><br />
 <br />
 It's NOT trivial to gain root, if it was trivial the whole UNIX security would be worthless. The particular method you described is not really practical.<br />
 <br />
 I think you mean social engineering -- tricking the user with a sudo window. Which can work (if the user doesn't bother to think why there's a sudo window all of a sudden).<br />
 <br />
 But the point is moot. If there's malicious stuff running on your machine you're pretty much screwed. <b>This is the 1st major vector of computer security: remote break-ins without user intervention.</b> This is a very important important thing and THIS is why Linux is more secure than Windows: on Linux, everybody makes every effort so that the break-in doesn't happen. On Windows they let it happen and deal with it afterwards.<br />
 <br />
 <div class="cquote">I'd bet most linux users install stuff from outside the repositories, and besides we've already seen examples of mirrors, and even source code being maliciously modified. </div><br />
 <br />
 Granted, the dependence of the repositories is a weak link. But the repositories are distributed and closely watched by many people. I'd say they do a much better job than, say, Apple does with the AppStore. Not to mention they have the source code too.<br />
 <br />
 As for installing stuff from other sources... <b>this is the 2nd big vector: users bringing malware in themselves</b>. And there's not much anybody can do about it. Unless the user understands not to install stuff from unofficial sources, all bets are off.<br />
 <br />
 BTW, a Linux distro can easily close 99% of this vector by only allowing certain repositories and disallowing direct installation of package files (deb, rpm etc.) But it's not practical.<br />
 <br />
 <div class="cquote">Most viruses work either by buffer overflow type exploits, or by tricking the user into running a program. File permissions aren't going to help in either case. By the way, you can easily execute non-'executable' binaries like this:<br />
 <br />
 /lib/ld-linux-x86-64.so.2 ./a_file </div><br />
 <br />
 For that to happen you need to already be able to run code. If you managed that you don't need that trick. On the rest, you're right.<br />
 <br />
 But let me point out that when you're trying to trick someone into running malware, it's one thing if all it takes is to double-click (a universal action used for everything) or if you need to go into file properties and change some stuff. You have to admit that executable status in metadata is better than executable status as part of the file name.<br />
 <br />
 <div class="cquote">Although I'd wager Ubuntu is becoming popular enough to count as a single target.  </div><br />
 <div class="cquote">The real reason you don't need anti-virus on linux is because there are a very very small number of linux viruses. And that is almost certainly due to the fact that it has a 1% market share (and probably the diversity and skill factors to some extent). </div><br />
 <br />
 That point of view is wrong.<br />
 <br />
 Some people like to say that once a platform is more popular there's more (or more motivated) people attacking it so chances for break-in increase. That's bull. Remember that most of the servers of the world run some form of UNIX or Linux and that has NOT made them more vulnerable. There's no direct link between popularity and security.<br />
 <br />
 There is an indirect one. Some of the installations are old and not updated. If you have lots and lots of installations, statistically the chances increase for running into an old one. It's a numbers' game. No relation to actual security.<br />
 <br />
 The reason there is so much Windows malware is because it's easy for it to exist: lots of vulnerabilities, bad underlying security models (fixed with Windows 7, hopefully), unpatched machines, many propagation vectors. There's next to none for Linux because vulnerabilities get patched fast, almost all installations update by default and propagation vectors are few.<br />
 <br />
 <div class="cquote">Well evidently not, otherwise there wouldn't be any need for security updates. </div><br />
 <br />
 Not sure how you mean that. Since there are security updates, obviously somebody DID see the vulnerability (and fixed it). Ok, they didn't see it the first time, but second time is better than never. Between a platform with 1000 vulnerabilities which has updates for all 1000 and a platform with 2 vulnerabilities which leaves 1 open, I'll take the first.<br />
 <br />
 <div class="cquote">Linux users are more skillfull.<br />
 <br />
 True, I suppose. </div><br />
 <br />
 Don't count on it.  Educating users will not work in the long run. Most users are not skilled enough, and security is a highly skilled game.<br />
 <br />
 The most you can teach them is not to install software from anywhere else but the official distros. The rest of the security job needs to be done by the OS and software with no user intervention.<br />
 <br />
 Which will always leave social engineering as a backdoor. But that's valid anywhere.Edited 2010-06-21 15:53 UTC</description>
			<pubDate>Mon, 21 Jun 2010 15:43:00 GMT</pubDate>
			<author>donotreply@osnews.com (wirespot)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?430920</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430920</guid>
			<description>You guys forget that security features don't exist in a vacuum and I'm not sure you realize how much Linux does to mitigate the user being the weak link.<br />
<br />
<b>4. By default files aren't executable</b><br />
<br />
In combination with things like a lack of embedded program icons, not hiding file extensions and, for Nautilus users, extension-header mismatch warnings, this works to prevent &quot;Cool picture!.jpg.exe&quot;-style exploits.<br />
<br />
I vaguely remember the devs recognizing a hole in this protection relating to .desktop files about a year ago and rushing to close it.<br />
<br />
<b>5. Diversity</b><br />
<br />
Ubuntu may be approaching &quot;single-target&quot; popularity, but I suspect the presence of Kubuntu, Xubuntu, and Lubuntu will prevent it from ever having that problem as badly as Windows or MacOS could.<br />
<br />
<b>6. People will see vulnerabilities in open-source code.</b><br />
<br />
While this is somewhat optimistic, open-source <i>does</i> have a deterrent effect on bundled malware and, more importantly, it means that features like stack-smashing protection, NX-bit buffer overflow security (A.K.A. Hardware DEP), and the like can be easily phased in by adding the userspace changes to the compiler.<br />
<br />
For example, on Windows, last I checked, Hardware DEP was still an opt-in thing in the default configuration to ensure backwards-compatibility with older software. On 64-bit Linux (and 32-bit distros which don't need to ensure no on-boot freezes on Pentium Pro), GCC has been appropriately setting the DEP opt-out flag in ELF headers for years. (nested functions, JIT compilers, and so on require the ability to dynamically build code and then execute it)<br />
<br />
<b>Here are some of the other things I didn't see mentioned:</b><br />
<br />
1. Linux vendors have a better track record than Microsoft for patching vulnerabilities quickly. (Is Microsoft still equating their confirmed exploits to Linux potential vulnerabilities and ignoring the Security/Crash/Bug/Annoyance flags to pad the numbers? I know they used to do that)<br />
<br />
2. Without root access, malicious programs can't remove themselves from the list of running, killable processes, interfere with syslog, etc. Last I checked, Windows was still struggling to virtualize all the admin-level access that older programs expected to have.<br />
<br />
3. On Linux, because privilege separation was around from the start, the number of escalation dialogs users see is significantly smaller than on Windows (partly because of the batching of package installs) so users are less likely to get in the habit of just clicking OK without reading them.<br />
<br />
Also, the presence of user accounts from the beginning means families which give different people different accounts are less likely to run into rough edges or to end up depending on apps which implement their own user profile systems. (Which means that you can have users who don't know any better (eg. kids) but don't have the admin password or access to mommy and daddy's files)<br />
<br />
4. Linux media players aren't vulnerable to the &quot;Use Windows Media Player and get tricked into visiting a malicious DRM auth site&quot; vulnerabilities I see every now and then. Any automatically-offered codecs come from the same signed repository farm as the OS.<br />
<br />
5. Linux provides many APIs for implementing drivers in userspace (libusb, CUPS, FUSE, CUSE, etc.) minimizing the amount of potentially vulnerable code that runs in kernel space. (Especially important since, video aside, the main remaining things which don't use a standard OS-bundled driver seem to be USB doodads and printers)<br />
<br />
5. Linux provides no hooks for programs to steal file associations, which removes the need for 90% of those buggy, tray-resident &quot;agents&quot;. (Especially when combined with the general preference for minimizing wheel-reinvention (outside the world of Linux audio))</description>
			<pubDate>Mon, 21 Jun 2010 15:44:00 GMT</pubDate>
			<author>donotreply@osnews.com (ssokolow)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?430921</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430921</guid>
			<description><div class="cquote">[q]It's NOT trivial to gain root, if it was trivial the whole UNIX security would be worthless. The particular method you described is not really practical.<br />
   <br />
   I think you mean social engineering -- tricking the user with a sudo window. Which can work (if the user doesn't bother to think why there's a sudo window all of a sudden). </div><br />
   <br />
   echo alias sudo='sudo do bad stuff &gt;/dev/null 2&gt;&amp;1;sudo' &gt;&gt;~/.bashrc<br />
  <br />
  I agree with pretty much everything else you said though.  Malicious people that want in don't necessarily need in &quot;right now&quot;, they wait patiently for it.Edited 2010-06-21 15:54 UTC</description>
			<pubDate>Mon, 21 Jun 2010 15:50:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>AV isn't really optional</title>
			<link>http://www.osnews.com/thread?430922</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430922</guid>
			<description>I don't view AV as optional regardless of platform. Even if your using a low risk platform; you probably talk to other platforms. Viruses for my platform may be far and few between but why should that justify my being an immune carrier and passing on something to a platform I'm interacting with. When we all got on the same network, we became responsible for each others platforms. Passing something on through negligence is not unjustifiable.</description>
			<pubDate>Mon, 21 Jun 2010 16:19:00 GMT</pubDate>
			<author>donotreply@osnews.com (jabbotts)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Comment by Dedoimedo</title>
			<link>http://www.osnews.com/thread?430924</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430924</guid>
			<description>Hello guys,<br />
<br />
Dedoimedo here. First, this is the first article posting here, so please excuse the few rough points, like the missing space in paragraph one and such, will be sorted out. Be gentle.<br />
<br />
Now, thanks for the comments.<br />
<br />
Linux security: we can argue about this to death, but the point is: it's all about statistical probability.<br />
<br />
I think the home usage security card is seriously overplayed, regardless of the operating system used and if you get it right, the operating system becomes a non-issue. Real security is agnostic.<br />
<br />
Exploits exist, vulnerabilities exist. On the same note, huge meteors exist and cosmic ray bursts exist. Likelihood of witnessing one before imminent doom? Not very high.<br />
<br />
If you don't go about wildly executing stuff, then you won't see the pixel devils take over your machine.<br />
<br />
Cheers,<br />
Dedoimedo</description>
			<pubDate>Mon, 21 Jun 2010 16:44:00 GMT</pubDate>
			<author>donotreply@osnews.com (Dedoimedo)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Comment by Dedoimedo</title>
			<link>http://www.osnews.com/thread?430925</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430925</guid>
			<description><div class="cquote">Hello guys,<br />
<br />
Dedoimedo here. First, this is the first article posting here, so please excuse the few rough points, like the missing space in paragraph one and such, will be sorted out. Be gentle.<br />
<br />
Now, thanks for the comments.<br />
<br />
Linux security: we can argue about this to death, but the point is: it's all about statistical probability.<br />
<br />
I think the home usage security card is seriously overplayed, regardless of the operating system used and if you get it right, the operating system becomes a non-issue. Real security is agnostic.<br />
<br />
Exploits exist, vulnerabilities exist. On the same note, huge meteors exist and cosmic ray bursts exist. Likelihood of witnessing one before imminent doom? Not very high.<br />
<br />
If you don't go about wildly executing stuff, then you won't see the pixel devils take over your machine.<br />
<br />
Cheers,<br />
Dedoimedo </div><br />
<br />
This is exactly the same security mistake that Microsoft made in the 80s and 90s.</description>
			<pubDate>Mon, 21 Jun 2010 16:53:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: insecurity - SSH is a must for workstations</title>
			<link>http://www.osnews.com/thread?430926</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430926</guid>
			<description>For workstations and even home personal machines; SSH is a must for me. I can manage, and have, my home machines from anywhere in the world with a network connection; safely. If you support client/family/friend machines then SSH can save you a house call.<br />
<br />
Not to mention, copy files between machines safely, provide ad-hoc secure proxy when away from home, provide network shares with real security rather than CIFS/Samba's leaky credential management.<br />
<br />
Even if SSH wasn't so wonderfully useful, I'd still recommend firewall rules if only to detect port scanning and other network oddities. If it has a network connection, it should have a firewall in place.</description>
			<pubDate>Mon, 21 Jun 2010 17:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (jabbotts)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Comment by Dedoimedo</title>
			<link>http://www.osnews.com/thread?430927</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430927</guid>
			<description>And what do you mean by: This is exactly the mistake that Microsoft made in 80s, 90s?<br />
Dedoimedo</description>
			<pubDate>Mon, 21 Jun 2010 17:08:00 GMT</pubDate>
			<author>donotreply@osnews.com (Dedoimedo)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Comment by Dedoimedo</title>
			<link>http://www.osnews.com/thread?430928</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430928</guid>
			<description><div class="cquote">And what do you mean by: This is exactly the mistake that Microsoft made in 80s, 90s?<br />
Dedoimedo </div><br />
<br />
Do you seriously not know?<br />
<br />
<div class="cquote">it's all about statistical probability. </div><br />
<div class="cquote">the home usage security card is seriously overplayed </div><br />
<div class="cquote">Real security is agnostic </div><br />
<div class="cquote">Exploits exist, vulnerabilities exist. On the same note, huge meteors exist and cosmic ray bursts exist. Likelihood of witnessing one before imminent doom? Not very high. </div><br />
<br />
All mistakes Microsoft made until they decided to take security seriously.</description>
			<pubDate>Mon, 21 Jun 2010 17:13:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[4]: Comment by Dedoimedo</title>
			<link>http://www.osnews.com/thread?430930</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430930</guid>
			<description>I disagree.<br />
<br />
I truly believe what I say and it's as simple as that. Security (for home) is no biggie. In fact, it's boring.<br />
<br />
Windows OS is neither the disaster nor the blessing that you might read about here and there. If you pay attention, most boxes were compromised by: no patches and ancient vulnerabilities, deliberate execution of code, user mistakes, not any special inherent flaws in the design.<br />
<br />
Dedoimedo</description>
			<pubDate>Mon, 21 Jun 2010 17:22:00 GMT</pubDate>
			<author>donotreply@osnews.com (Dedoimedo)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: insecurity - SSH is a must for workstations</title>
			<link>http://www.osnews.com/thread?430931</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430931</guid>
			<description><div class="cquote">Even if SSH wasn't so wonderfully useful </div><br />
Yep, SSH is awesome.<br />
<br />
<div class="cquote">I'd still recommend firewall rules if only to detect port scanning and other network oddities. </div><br />
<br />
Why bother? If you're connected to the internet you're going to get port scanned and probed. It's a fact, you don't need a packet filter to tell you that.<br />
Heck, you're probably getting scanned and probed so often that that logs will be too big to be useful.<br />
<br />
<div class="cquote">If it has a network connection, it should have a firewall in place. </div><br />
Firewalls are over-rated, both on workstations and standalone gateways.<br />
<br />
Off-topic but this is especially common in corporate environments where many managers seem to think that firewalls (especially Cisco ones) are magic amulets that will protect you from all evil.</description>
			<pubDate>Mon, 21 Jun 2010 17:22:00 GMT</pubDate>
			<author>donotreply@osnews.com (Soulbender)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[5]: Comment by Dedoimedo</title>
			<link>http://www.osnews.com/thread?430933</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430933</guid>
			<description><div class="cquote">I disagree.<br />
<br />
I truly believe what I say and it's as simple as that. Security (for home) is no biggie. In fact, it's boring.<br />
<br />
Windows OS is neither the disaster nor the blessing that you might read about here and there. If you pay attention, most boxes were compromised by: no patches and ancient vulnerabilities, deliberate execution of code, user mistakes, not any special inherent flaws in the design.<br />
<br />
Dedoimedo </div><br />
<br />
Windows was a disaster until XP service pack 2, as was ME, 98, 95, 3.11, and MS-DOS before that.<br />
<br />
I know that you disagree, but that doesn't make your opinion right.  Microsoft even admitted that their security was crap and their design was flawed themselves 8 years ago.<br />
<br />
<a href="http://www.microsoft.com/presspass/features/2002/feb02/02-20mundieqa.mspx" rel="nofollow">http://www.microsoft.com/presspass/features/2002/feb02/02-20mundieq...</a><br />
<br />
&quot;Boring&quot;? What does that even mean?  Ignoring security at home will just make Linux become the next Windows 95. Stop telling users that don't know better that they don't need to worry about it.</description>
			<pubDate>Mon, 21 Jun 2010 18:10:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: insecurity</title>
			<link>http://www.osnews.com/thread?430935</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430935</guid>
			<description>&quot;Sure beats most the Windows junk AV's&quot;<br />
<br />
I don't think that any antivirus company even consider clamav as a competitor or care to share samples with them this is the reason why their signature db is nowhere compared to the &quot;junk avs&quot; you mentioned. My experience is that clamav not just gets sigs for a certain malware later but it doesn't have a signature from 10/8 files. <br />
<br />
&quot;There are a lot of network based attacks that computers without firewalls are vulnerable to.<br />
man in the middle attacks, spoofing, etc.&quot;<br />
<br />
I don't see how firewall would help you in a MITM attack. There is a publicly available tool called ZXARPS which is able to intercept/change traffic between hosts in the same broadcast domain (eg between yout laptop and default gateway), try to defend your box against that with iptables <img src="/images/emo/smile.gif" alt=";)" /> <br />
<br />
&quot;It also keeps ports that shouldn't be exposed to the internet away from the internet. &quot;<br />
<br />
The thing is that you are almost always behind a NAT device whether you using your laptop in a corporate network or just at home behind a dsl router but don't get me wrong having a firewall in situations where you for example have a samba server running on your laptop what you need to access when you are home is ok. <br />
Using premade firewall rulesets however what the user in many cases don't understand and probably just an &quot;input only&quot; ruleset doesn't help much.</description>
			<pubDate>Mon, 21 Jun 2010 18:32:00 GMT</pubDate>
			<author>donotreply@osnews.com (xaeropower)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Security</title>
			<link>http://www.osnews.com/thread?430936</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430936</guid>
			<description><div class="cquote">"<i>Well that's not really true as, generally speaking, Linux distros ship with more secure defaults than Windows does.  </div><br />
<br />
And may I remind people that Linux security features are not even turned up to full blast on default installations. It's this good out of the box but it's not even trying. There's room for increasing Linux security two-fold or more. Consider:<br />
<br />
* mandatory AppArmor-based software whitelisting;<br />
* mandatory separate /home and /tmp partitions with noexec,nodev,nosuid;<br />
* restricting software installation to official repositories and their mirrors and denying direct install of debs/rpms/install kits by default;<br />
* integrating and shipping default kernels that feature better ASLR and NX bit support. </i>"<br />
<br />
May I remind you that I stated &quot;more secure defaults than Windows&quot; and not that &quot;Linux's defaults are perfect&quot; <img src="/images/emo/smile.gif" alt=";)" /></description>
			<pubDate>Mon, 21 Jun 2010 18:39:00 GMT</pubDate>
			<author>donotreply@osnews.com (Laurence)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[4]: Security</title>
			<link>http://www.osnews.com/thread?430939</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430939</guid>
			<description><div class="cquote">May I remind you that I stated &quot;more secure defaults than Windows&quot; and not that &quot;Linux's defaults are perfect&quot; <img src="/images/emo/smile.gif" alt=";)" />  </div><br />
<br />
They aren't more secure than Windows anymore.  At one time, sure.  Now?  No.</description>
			<pubDate>Mon, 21 Jun 2010 18:48:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: insecurity</title>
			<link>http://www.osnews.com/thread?430940</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430940</guid>
			<description><div class="cquote">There are a lot of network based attacks that computers without firewalls are vulnerable to. <br />
<br />
man in the middle attacks, spoofing, etc. </div><br />
<br />
What?!? How exactly does a firewall mitigate man in the middle attacks or spoofing? That's just silly.</description>
			<pubDate>Mon, 21 Jun 2010 18:50:00 GMT</pubDate>
			<author>donotreply@osnews.com (rexstuff)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: insecurity</title>
			<link>http://www.osnews.com/thread?430941</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430941</guid>
			<description><div class="cquote">"<i>There are a lot of network based attacks that computers without firewalls are vulnerable to. <br />
<br />
man in the middle attacks, spoofing, etc. </div><br />
<br />
What?!? How exactly does a firewall mitigate man in the middle attacks or spoofing? That's just silly. </i>"<br />
<br />
Spoofing IS a man in the middle attack.<br />
<br />
- <a href="http://www.fwbuilder.org/4.0/docs/users_guide/ch15s02s06.html" rel="nofollow">http://www.fwbuilder.org/4.0/docs/users_guide/ch15s02s06.html</a><br />
<br />
- <a href="http://www.cipherdyne.org/LinuxFirewalls/ch01/" rel="nofollow">http://www.cipherdyne.org/LinuxFirewalls/ch01/</a><br />
<br />
- <a href="http://www.aboutdebian.com/firewall.htm" rel="nofollow">http://www.aboutdebian.com/firewall.htm</a></description>
			<pubDate>Mon, 21 Jun 2010 18:58:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: insecurity</title>
			<link>http://www.osnews.com/thread?430942</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430942</guid>
			<description><div class="cquote">&quot;There are a lot of network based attacks that computers without firewalls are vulnerable to.<br />
man in the middle attacks, spoofing, etc.&quot;<br />
<br />
I don't see how firewall would help you in a MITM attack. There is a publicly available tool called ZXARPS which is able to intercept/change traffic between hosts in the same broadcast domain (eg between yout laptop and default gateway), try to defend your box against that with iptables <img src="/images/emo/smile.gif" alt=";)" /> <br />
 </div><br />
<br />
Depends on the attack really, a firewall shouldn't be the only line of defense. <img src="/images/emo/wink.gif" alt=";)" /> <br />
<br />
<div class="cquote">&quot;It also keeps ports that shouldn't be exposed to the internet away from the internet. &quot;<br />
<br />
The thing is that you are almost always behind a NAT device whether you using your laptop in a corporate network or just at home behind a dsl router but don't get me wrong having a firewall in situations where you for example have a samba server running on your laptop what you need to access when you are home is ok. <br />
Using premade firewall rulesets however what the user in many cases don't understand and probably just an &quot;input only&quot; ruleset doesn't help much. </div><br />
<br />
That is a fair point, but it requires that the user remember to turn on and configure a firewall during times that they aren't protected by some other method.</description>
			<pubDate>Mon, 21 Jun 2010 19:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[5]: Security</title>
			<link>http://www.osnews.com/thread?430944</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430944</guid>
			<description>So Windows 7 doesn't give the default user accounts full administration rights?<br />
<br />
Windows has come a long long way, there's no denying that. And I'm not disputing that security is an ongoing battle in which users shouldn't get complacent regardless of the OS they run.<br />
<br />
I just don't see the point in lying by saying all OSs are equally secure by default. The simple fact is some OSs do ship with better defaults. However, and as I've already stated, none of that really makes much difference if you stick an experienced idiot in front of the keyboard.</description>
			<pubDate>Mon, 21 Jun 2010 19:14:00 GMT</pubDate>
			<author>donotreply@osnews.com (Laurence)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>nice article</title>
			<link>http://www.osnews.com/thread?430945</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430945</guid>
			<description>It's nice to see common sense articles like this one, and helpful, too.  Hopefully it will also demonstrate that Windows users are not only affected by viruses, malware, and all of that, but they don't have any useful logging capabilities either.  Linux is amazing when it comes to logs.  Logs are kept for everything, and are a tremendous help when trying to troubleshoot something.  In Windows, logs are an afterthought, and makes troubleshooting more difficult as we find ourselves looking around for solutions with symptoms. On Linux where we can look at a lot and determine where to go next.</description>
			<pubDate>Mon, 21 Jun 2010 19:17:00 GMT</pubDate>
			<author>donotreply@osnews.com (apexwm)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[6]: Security</title>
			<link>http://www.osnews.com/thread?430946</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430946</guid>
			<description><div class="cquote">So Windows 7 doesn't give the default user accounts full administration rights?<br />
<br />
Windows has come a long long way, there's no denying that. And I'm not disputing that security is an ongoing battle in which users shouldn't get complacent regardless of the OS they run.<br />
<br />
I just don't see the point in lying by saying all OSs are equally secure by default. The simple fact is some OSs do ship with better defaults. However, and as I've already stated, none of that really makes much difference if you stick an experienced idiot in front of the keyboard. </div><br />
<br />
It really would be a lie to say that they were all secure by default, because none of them are.</description>
			<pubDate>Mon, 21 Jun 2010 19:17:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: insecurity - SSH is a must for workstations</title>
			<link>http://www.osnews.com/thread?430953</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430953</guid>
			<description>True, on there own packet filtering isn't going to cure all. You will also see a lot of noise if connected directly to the internet. If the user is behind a router, that notice of network noise may be a sign of issues within the local area though. A friend is visiting and suddenly I'm getting port scans and other network oddities; I ask them if they are playing with my network or have an infection that needs to be addressed. My user's network is behind a router but they call asking about popups or see oddities in the logs; I start looking at the other machines inside the network.<br />
<br />
I'm not the average user though as all my machines at home that can, have IDS on and watching each other. Someone may pop one of my machines but you can bet there are going to be &quot;witnesses&quot; that see the mugging and report back to root.<br />
<br />
I figure it's already there in the kernel and the setup isn't hard enough to justify not doing at least a three way handshake and a couple of drop all rules.</description>
			<pubDate>Mon, 21 Jun 2010 19:58:00 GMT</pubDate>
			<author>donotreply@osnews.com (jabbotts)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: insecurity - SSH is a must for workstations</title>
			<link>http://www.osnews.com/thread?430956</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?430956</guid>
			<description><div class="cquote">Firewalls are over-rated, both on workstations and standalone gateways.<br />
<br />
Off-topic but this is especially common in corporate environments where many managers seem to think that firewalls (especially Cisco ones) are magic amulets that will protect you from all evil. </div><br />
<br />
Overrated, maybe.  Over-relied-upon, definitely.  But they have value.  At least a few Windows remote exploits were preventable or otherwise mitigated by using a firewall (maybe Linux ones, too).  And they help in a defense-in-depth strategy.  They might also help some less-skilled Windows users detect network-accessing malware (though the false alarms often generated diminish the advantage  there).</description>
			<pubDate>Mon, 21 Jun 2010 20:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (license_2_blather)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Small typographic error</title>
			<link>http://www.osnews.com/thread?431009</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431009</guid>
			<description><div class="cquote">&quot;I've bored the readers of my personal websiteto death...&quot;<br />
<br />
Not the &quot;websiteto&quot; bit. I think that should be reader (singular)?<br />
<br />
:-)<br />
<br />
This seems to be an article about how great your own piece of software is... if OS news is going to let people advertise they could at least tell people about it first like: Advertisment follows... </div><br />
<br />
Yeah, another useless article by some self-promoting dickhead featured on OSNews.<br />
<br />
You've got to wonder when the so-called editors on this site will wake up to the fact that they are little more than a bunch of saps.....</description>
			<pubDate>Mon, 21 Jun 2010 23:55:00 GMT</pubDate>
			<author>donotreply@osnews.com (chris_l)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Comment by Dedoimedo</title>
			<link>http://www.osnews.com/thread?431010</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431010</guid>
			<description>I said this earlier, but the link to your article on white-listing and black-listing is broken (it is a file:// URL). It looks like you forgot to put that on the Internet. I would be interested in reading it.</description>
			<pubDate>Tue, 22 Jun 2010 00:03:00 GMT</pubDate>
			<author>donotreply@osnews.com (Zifre)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?431027</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431027</guid>
			<description>echo alias sudo='sudo do bad stuff &gt;/dev/null 2&gt;&amp;1;sudo' &gt;&gt;~/.bashrc<br />
<br />
I agree with pretty much everything else you said though. Malicious people that want in don't necessarily need in &quot;right now&quot;, they wait patiently for it.<br />
<br />
In order for that to work the malware app in question would either have to be root in order to put the fake sudo in a location mentioned in $PATH, or it would have to place it somewhere in the user's own home directory and modify $PATH.<br />
<br />
The problem? Well, atleast some distros use the Tomoyo/SELinux framework to disable running applications from the user's own home directory if they have the same name as a common system application, and sudo often belongs in that list.<br />
<br />
Some shell providers even completely disable the ability for one to run executable code from the home directories or /tmp and it might actually be a good idea for home-user oriented distros too; a common home user does not have the need to execute stuff from their home directory, they'll most likely just install what they need system-wide using the package manager. Executing stuff from your own home dir is more likely a power-user feature, including programmers et al, not Joe Sixpack.</description>
			<pubDate>Tue, 22 Jun 2010 02:55:00 GMT</pubDate>
			<author>donotreply@osnews.com (WereCatf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Comment by Dedoimedo</title>
			<link>http://www.osnews.com/thread?431043</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431043</guid>
			<description>Just go to his own site and search for it.<br />
<a href="http://www.dedoimedo.com/life/whitelist-blacklist.html" rel="nofollow">http://www.dedoimedo.com/life/whitelist-blacklist.html</a><br />
<br />
And also, I would say that the whitelist blacklist article on his website is pretty much against what I think about whitelisting and blacklisting.<br />
<br />
Central to his whitelisting and blacklisting article is the idea that whitelisting = innocent-until-proven-guilty and yet he goes on to say that whitelisting is done in old Soviet Union yada yada and that blacklisting is the norm of the society, done in US and guilty-until-proven-innocent.<br />
<br />
I would say that trying to divide it into forms of governance and behavioural patterns is much more complicated. Not to mention the amount of prior work needed to prove that governance and behavioural patterns can be mapped into the analogy in the first place. But I'm digressing. My main problem is that I do not even agree with his use of the words whitelisting and blacklisting.<br />
<br />
Basically, the idea of blacklisting (not coincidentally, blacklist as a word is permitted by the spell check while the much newer whitelist is not) is to select known bad elements of the pool of all elements and apply strict rules on them. Contrast this with whitelisting where you select the known good elements and build a fence around them to protect them.<br />
<br />
Actually, both cases' characteristics are very well known. Blacklisting allows for more rapid development but is much more prone to attacks while whitelisting is much more secure (though not eliminating insiders) but can be so painfully slow. Usually, in real life, they are used in combination -- simply allow for a gray area and you can selectively relax rules for known good elements and apply strict rules to the known bad ones, with whatever policies the administrator wants to apply on the gray.<br />
<br />
I am now going to show how both cases are doomed to failure if not applied together. Blacklisting is currently employed in malware scans. This is where malware appears in the wild first (recall Blaster, mydoom, sasser?) and then the malware scanning companies will do whatever they can to block it, which, for virii (stupid spell check allows for viruses but not virii) is a signature check. This model of work is proven to be easily compromised. Whitelisting, on the other hand, is going to say that you can only use openoffice.org and mozilla firefox. That way, you cannot install stuff that compromises the security of the system. If chrome comes along, it will need to be thoroughly vetted first (no wonder it is so slow moving), but this system is only vulnerable to regulation oversight and insider malevolence. It tends to last longer, and is evolutionarily selected for use in large governmental organisations, most notably in military (i.e. those that try to be funny in war tend to be infiltrated too quickly).<br />
<br />
Hence, it is important to incorporate both. Which is the problem with malware scanning these days -- old systems used to have intrusion prevention rather than detection, and when they compared the newer detection to prevention, they found out, quite unsurprisingly, that detection is a lot lousier in dealing with attacks (and that the number of signatures to scan increases so fast that whatever gains it initially had over prevention is quickly overrun).<br />
<br />
If you want to read more, read ranum at<br />
<a href="http://www.ranum.com/security/computer_security/editorials/dumb/index.html" rel="nofollow">http://www.ranum.com/security/computer_security/editorials/dumb/ind...</a><br />
<br />
PS: In fact, the whole site itself is generally well-written.</description>
			<pubDate>Tue, 22 Jun 2010 07:42:00 GMT</pubDate>
			<author>donotreply@osnews.com (xiaokj)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[5]: Security</title>
			<link>http://www.osnews.com/thread?431054</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431054</guid>
			<description><div class="cquote">They aren't more secure than Windows anymore. At one time, sure. Now? No. </div><br />
<br />
Ah, but what do you mean by &quot;Windows&quot; and &quot;Linux&quot;? If you mean an install with just the OS and an interface, let's assume you're right. Windows 7 has made great strides into closing remote vulnerabilities and has taken protections such as ASLR, sandboxing IE etc. Remote breaking into Windows 7 through IE8 has been called one of the biggest modern challenges in security.<br />
<br />
But a working PC also contains a large number of applications. This is where the cookie crumbles. <br />
<br />
The Windows applications come in huge numbers, they are mostly closed source and they are not updated in a centralized manner. Plus,  Windows users consider it normal to download stuff off any website they run into, not to mention downloading and running dubious cracks and keygens. What's more, they've become complacent about having malware in their machine.<br />
<br />
Contrast this with Linux apps which are fewer, mostly open sourced, come 99% from trusted repositories, the update system is centralized and automated, and there's usually no need to go and install cracks. And a Linux user who finds a single piece of malware on their machine will be absolutely horrified.<br />
<br />
Basically, the Windows userland is a security nightmare.</description>
			<pubDate>Tue, 22 Jun 2010 09:10:00 GMT</pubDate>
			<author>donotreply@osnews.com (wirespot)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?431055</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431055</guid>
			<description><div class="cquote">echo alias sudo='sudo do bad stuff &gt;/dev/null 2&gt;&amp;1;sudo' &gt;&gt;~/.bashrc </div><br />
<br />
That works. It can be countered with some extra safety measures in the shell.<br />
<br />
But it's awkward; it may give false positives and impact legitimate uses; it can still be circumvented; it uses a blacklist, which is usually a bad idea in security; and most importantly, it misses the main point: <b>once malware executes on your machine, you're screwed</b>.<br />
<br />
There's a [url=<a href="http://ubuntuforums.org/showthread.php?t=504740" rel="nofollow">http://ubuntuforums.org/showthread.php?t=504740</a>]lengthy discussion[/url] on this exact topic on the Ubuntu forums, if you care to read it.<br />
<br />
Personally, I'd rather have most effort put into plugging app vulnerabilities than in mitigating the aftermath of a break-in. I find the casual attitude about break-ins on Windows terrible. If a Linux user found a single piece of malware crawling inside their machine, they'd be horrified. A Windows user just assumes it's natural to have piles of that stuff. Terrible.<br />
<br />
Granted, good security means layers upon layers and not relying on a single barricade, lest you find yourself in trouble when that barricade is breached. sudo calls could probably use better guarding and closing some of the more &quot;creative&quot; ways of plugging into it.<br />
<br />
<div class="cquote">I agree with pretty much everything else you said though. Malicious people that want in don't necessarily need in &quot;right now&quot;, they wait patiently for it. </div><br />
<br />
Let's not assume there's an actual person behind every break-in. Most break-ins into personal computers are done by bots, the worms that cruise the net and blindly try every address with every trick they know. They don't rest, they don't stop, they don't think, they don't have personal likes or dislikes or reasons to do something. They just do what they were told to do, forever. Like I said, a numbers' game. That's the main threat we're trying to protect against: dumb repetitive robots.<br />
<br />
I'd wager that if an actual highly skilled hacker wants in your computer, they will manage that. Then again, even an unskilled person can manage that, with a hammer and your fingers. But that's another ball game entirely.</description>
			<pubDate>Tue, 22 Jun 2010 09:11:00 GMT</pubDate>
			<author>donotreply@osnews.com (wirespot)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[7]: Security</title>
			<link>http://www.osnews.com/thread?431059</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431059</guid>
			<description><div class="cquote">It really would be a lie to say that they were all secure by default, because none of them are. </div><br />
<br />
And once again: Hence why I said &quot;more secure by default&quot; and not &quot;Linux's defaults are perfect&quot;</description>
			<pubDate>Tue, 22 Jun 2010 10:20:00 GMT</pubDate>
			<author>donotreply@osnews.com (Laurence)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[6]: Security</title>
			<link>http://www.osnews.com/thread?431068</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431068</guid>
			<description><div class="cquote">Basically, the Windows userland is a security nightmare. </div><br />
<br />
s/Windows/any\ OS/i</description>
			<pubDate>Tue, 22 Jun 2010 12:17:00 GMT</pubDate>
			<author>donotreply@osnews.com (fewt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Ubuntu Firewall</title>
			<link>http://www.osnews.com/thread?431139</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431139</guid>
			<description>I don't quiet agree with the article, the default setup does not use a firewall, but it does expose some things to the outside world: avahi-daemon<br />
<br />
It has a few settings to make it more secure by itself, but saying a default Ubuntu desktop has nothing exposed is not true.<br />
<br />
Possible even dhcpcd is listening on his/her socket.</description>
			<pubDate>Tue, 22 Jun 2010 23:30:00 GMT</pubDate>
			<author>donotreply@osnews.com (Lennie)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?431165</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431165</guid>
			<description><div class="cquote">This is true up to a point. I'd bet most linux users install stuff from outside the repositories, and besides we've already seen examples of mirrors, and even source code being maliciously modified.  </div><br />
<br />
Correction: We have seen a few examples of mirrors where someone hacked into a machine, but no distributed software was altered because of that. Just lately, we saw one example of an obscure source code tarball being replaced on some mirrors by a trojaned version. Fortunately this affected the repositories of only two know distributions, Arch and Gentoo, both of which are minor distributions.<br />
<br />
It is unlikely that as many as a dozen systems were ever infected by any of this activity.<br />
<br />
BTW: I personally install very litlle software from outside the repositories. Why would I? Debian repositories contain over 25,000 packages. There is very little outside that you would actually need.<br />
<br />
If we are going to try to scope the problem, lets try to keep it real. Compare this real-world scope for malware infection of Linux systems to the estimated 50% of Windows machines that are infected (perhaps 200 million machines or more) ... that gives it some perspective.</description>
			<pubDate>Wed, 23 Jun 2010 04:27:00 GMT</pubDate>
			<author>donotreply@osnews.com (lemur2)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[6]: Security</title>
			<link>http://www.osnews.com/thread?431166</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431166</guid>
			<description><div class="cquote">The Windows applications come in huge numbers, they are mostly closed source and they are not updated in a centralized manner. Plus, Windows users consider it normal to download stuff off any website they run into, not to mention downloading and running dubious cracks and keygens. What's more, they've become complacent about having malware in their machine. <br />
 <br />
 Contrast this with Linux apps which are fewer, mostly open sourced, come 99% from trusted repositories, the update system is centralized and automated, and there's usually no need to go and install cracks. And a Linux user who finds a single piece of malware on their machine will be absolutely horrified.  </div><br />
 <br />
 Precisely so.<br />
 <br />
 In fact, there was one case recently of an obscure program called UnRealIRCd where someone had replaced a tarball (which was unsigned) on a mirror with a version that contained a trojan.<br />
 <br />
 There was a huge amount of &quot;horror&quot; and discussion generated over this, but at the end of the day the trojan found its way into only two minor distribution repositories. It is unclear if it actually mamanged to infect any end user's machines at all.<br />
 <br />
 The amount of &quot;horror&quot; generated compared to the actual infection rate was hugely blown out of proportion. In a way, that is a positive ... if an equivalent thing had happened in the Windows ecosystem, probably no-one would ever have even noticed, and certainly there would be no comment raised.Edited 2010-06-23 04:37 UTC</description>
			<pubDate>Wed, 23 Jun 2010 04:36:00 GMT</pubDate>
			<author>donotreply@osnews.com (lemur2)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[5]: Security</title>
			<link>http://www.osnews.com/thread?431167</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431167</guid>
			<description><div class="cquote">"<i>May I remind you that I stated &quot;more secure defaults than Windows&quot; and not that &quot;Linux's defaults are perfect&quot; <img src="/images/emo/smile.gif" alt=";)" />  </div> They aren't more secure than Windows anymore. At one time, sure. Now? No. </i>"<br />
<br />
Depends on how you define it. Windows now is certainly more secure than Windows of the past, but nevertheless the actual infection rate of Windows systems is still vastly more than infection rates of any other system.<br />
<br />
It matters not at all to the end user (whose system gets infected) if this is &quot;unfair&quot; comparison, or if it is due to the fact that there is vastly more security threats against Windows. The practical outcome is still that if you run a Windows system, it is far more likely to get infected.</description>
			<pubDate>Wed, 23 Jun 2010 04:42:00 GMT</pubDate>
			<author>donotreply@osnews.com (lemur2)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Don't need anti-virus?</title>
			<link>http://www.osnews.com/thread?431489</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?431489</guid>
			<description>Personally  I think Linux is much more secure than Windows and it is more reliable than Windows. However all Distro(s) run as server will be set up an anti virus software to increase the protection.<br />
<br />
The following link shows The Most Reliable Hosting in May/2010:<br />
<a href="http://news.netcraft.com/archives/2010/06/08/most-reliable-hosting-company-sites-in-may-2010.html" rel="nofollow">http://news.netcraft.com/archives/2010/06/08/most-reliable-hosting-...</a></description>
			<pubDate>Fri, 25 Jun 2010 14:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (djannie)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
