Linked by Thom Holwerda on Fri 28th Mar 2008 20:39 UTC, submitted by irbis
Thread beginning with comment 307101
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
I've got to be honest, I'm surprised and *very* impressed that both Vista lasted this long, and that the eventual downfall of the Vista machine was caused by non-MS code.
Why are you surprised? I do not use Vista and am not particularly impressed with what I have seen of it but it has had a decent security record. Not outstanding, but quite decent, especially for Microsoft.
I'm even more impressed that Ubuntu (which doesn't run a firewall by default, and doesn't use SELinux) is still going.
Again why?
1) Ubuntu has no services listening on an external address by default. This somewhat limits the utility or need for a firewall.
2) SELinux is not a miracle cure acting as the only line of defense on a Linux system. Properly configured SELinux makes a system more secure, no argument there. But if all applications running on the system are patched and do not have known buffer overrun or privilege escalation vulnerabilities then a system without SELinux can still be quite secure. The dire security need for SELinux is predicated on there being exploitable vulnerabilities on a system and an attempt to be made to use the exploit.
The trend I have been seeing on SELinux going from being seen as a tool to increase security to people arguing that a system is not secure without it is bothersome. The absence of SElinux does not make a system inherently vulnerable to attack. SELinux makes a system which has an exploit in need of being patched less likely to be compromised. The key here is the application with the exploit should be patched in any case.
The trend I have been seeing on SELinux going from being seen as a tool to increase security to people arguing that a system is not secure without it is bothersome.
Hear! Hear!
I would have further described it as "damned irritating", as well. But you really hit the nail on the head, there.




Member since:
2006-02-01
According to
http://dvlabs.tippingpoint.com/blog/2008/03/28/pwn-to-own-final-day...
the Vista laptop was eventually hacked after the Adobe Flash plugin was installed.
I've got to be honest, I'm surprised and *very* impressed that both Vista lasted this long, and that the eventual downfall of the Vista machine was caused by non-MS code. I'm even more impressed that Ubuntu (which doesn't run a firewall by default, and doesn't use SELinux) is still going.
Combine taht with the embarrassing result for Apple and the whole thing is really eye-opening.