Linked by Jordan Spencer Cunningham on Mon 14th Jun 2010 23:58 UTC
Bugs & Viruses Recently, the Linux version of UnrealIRCd was discovered to have had a Trojan worm its way into the source code. Even more embarrassing for the developers of Unreal is that the Trojan's been holding open the backdoor in the source code since November of 2009-- not very recently. And, of course, bloggers and press in general are taking the opportunity of another breach in Linux security to point out doomsday devices that don't really exist.
Thread beginning with comment 430104
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[5]: Comment by flanque
by lemur2 on Tue 15th Jun 2010 12:05 UTC in reply to "RE[4]: Comment by flanque"
Member since:

It is evident you don't know much about the matter. I wonder why you feel compelled to post so much in this thread.

The problem at hand could have indeed been solved using trusted and trustworthy repositories.

However if the software has bugs, like using gets(), but really many kinds of bugs can do. You rely on exploit prevention and mitigation which is on par with Windows and still not at modern levels.

Then there is another whole class of exploits helped by people keeping all doors open in their servers, most of which use Linux, but could use anything.

This is not GPL code vs everyone else, it is distributors(GPLd and Proprietary) not fixing fixable things for whatever dark reason they have.

Your beloved Linux has "free" code(often just changing a number here and there) to prevent many exploits currently affecting faithful users like you. However, if they are not enabled by default it's as if they never were there when the system is used by a normal user. Ship with all doors closed and write down why it is dangerous to open them and the user will get the chance to think twice.

Let's just say that "insecure by default" doesn't make a good slogan.

Meanwhile, in the real world, we actually get this situation:

When they say "malware infected PCs", they actually mean an estimated level of "malware infected Windows machines".

This is the status-quo level at which the proverbial "bar has been set". Linux machines must be able to better this standard to come off well in comparison with machines that are commonly marketed today.


Wait though ... it gets better. Here is an expert opinion on the value for money of the status quo machines being mass-marketed today:

Here is the situation with the worlds highest-performing, most expensive, highest-value machines:

Edited 2010-06-15 12:23 UTC

Reply Parent Score: -1