[Discuss] Gentoo?
Patrick
Nixnik-sneaking at sneakEmail.com
Mon Jan 27 11:07:32 PST 2014
On Sun, 26 Jan 2014 16:36:16 -0800
Bernie C. Till wrote:
> Well, Drew, it seems that you and I are singing from the same page of the
> same hymn book.
>
> The three most important issues to me are security, security, security,
> stability, and functionality.
One thing to consider here -- the elegance and relative security
of open source software over closed-source is that a *lot* of
people see it, review it, patch it and update it on an ongoing
basis. It gets scrubbed and polished to the point where it not
only shines, but actually has all its corners rounded-off and
won't chip, even if you drop it on concrete.
Meanwhile, the boys at Microsoft can use as many goto's as they
like, because no one will ever notice. Their turnaround time in
acknowledging security issues and patching them has improved a
lot, however. Still, no closed-source project can afford the
sort of auditing and peer review that an open one gets for free.
*Nobody* has that kind of money, not even Microsoft.
Meanwhile, you're just one guy, and can't expect much of a peer
review at all. Disabling features you don't need makes perfect
sense [not in a configuration file, but in the way the software's
compiled], but beyond that, I'm not sure if there's much benefit
over picking a `hardened' distro and having a little trust in the
millions[!] of dedicated developers who had a hand in making it.
BTW, this was a major stumbling-block in Netscape's efforts to
release its web browser into the world of FOSS. They kept
stripping out dead code, straightening out piles of spaghetti
code, trying to make their indentation a little more consistent
and such... and the hippie anarchist programmers they were
handing it to just laughed, and/or sent them nasty emails about
the horrible state of their project.
Closed source. They'd never expected anyone outside the company
to see it, let alone make fun of it.
>
> The stakes are a lot higher when your server is connected to the internet
> 24/7 by a big fat pipe, as compared to a desktop client, which I physically
> disconnect from the internet when I'm not actively using it.
I'm thinking maybe a month or two of *without* any sort of
antivirus / antimalware might ease your mind a bit. ;-)
For example...
After a deeply paranoid online discussion with, and dire warnings
from a Windows user about network security, I tried going `naked'
to GRC's `Shields Up!' port-scanner to see what would happen. No
firewall, not even a router, just an ethernet line directly from
the computer to my DSL modem.
About six ports were visible, but closed. Most were completely
invisible, as if my IP address pointed to thin air. One port
*was* open... 80, on purpose. I'd been running a server from
home, from the same laptop I use for day-to-day computing, for
over a year without any trouble. Nothing special, just stuff
like;
http://wgbeeper.dns1.us/
hosted remotely now, because internet's included in the rent
here. Since I'm behind the landlord's router instead of my own,
I can't adjust things like port-forwarding.
I also got to prefer reading manual pages in a web browser, where
I've got a [Ctrl-F] shortcut to look for specific phrases, all
the headings indexed and linked, references to other manual pages
which appear as links, etc, and the best way to do that is to
visit;
http://localhost/cgi-bin/man/man2html
[Note: won't work unless you've got a web-server and man2html
installed. A featherweight browser like Dillo also recommended.]
If/when I skimmed Apache's logs, I would notice occasional
requests for things like /squirrelmail/webmail.php?guest ,
another one associated with Sendmail I think -- stuff like that.
Probably spammers, looking to hitch a free ride on my open relay,
except there wasn't one. These requests were all met with 404
errors, because I had no webmail interface to access. Google
indexed me periodically [including the manual [web]pages], but
not obtrusively, so I never bothered to write a `robots.txt'.
But I was pretty diligent about keeping the FTP turned off when
I wasn't using it, even though port 21 was *not* open to the
public. I just use that around the house, because it's easier
than finding a thumb-drive, finding a USB port, copying stuff
onto the pen-drive, unmounting and disconnecting it from one
computer, going over and plugging it into the other computer,
copying stuff off it, going back and repeating the whole process
in a few minutes if I'd forgotten something...
[...]
> --
> Drew
>
> "Nothing in life is to be feared. It is only to be understood."
> --Marie Curie
Uh... Wasn't she trying to understand radium? And didn't she
come down with a bad case of leukemia, later on?
>
> "This started out as a hobby and spun horribly out of control."
> -Unknown
Oh, absolutely. ;-)
Cheers,
Patrick.
--
BOFH excuse #309:
firewall needs cooling
More information about the Discuss
mailing list