Linux is fast, flexible and free. Experts say that comes with a security cost
washingtonpost.com
washingtonpost.com
A pragmatic solution to this is a configurable policy that is determined at boot time (and immutable ever after). There is no need to discuss with the aim to reach an agreement - requirements differ and for a lot of use-cases "I don't care" is just as OK as "no fscking way" is for others.
[1] http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man7/...
It also reeks of he said/she said journalism, but the kind where you're supposed to figure out whether "he" or "she" said the truth, while the reporter mains a kind of false objectivity.
All in all, not a service to anyone.
Ultimately, I think the message of this article, that Linux out of the box isn't inherently secure, and the culture around Linux needs more focus on security, is true. But it's also being said in a vacuum, with no comparison to other platforms. Certainly the experts in question were right to have concerns about Linux security, but I'd put bet money on the assertion that they have even greater concerns about, say, Windows.
And finally, some of the problems being blamed on Linux are actually problems with the tooling around Linux and the platforms Linux is being run on. Android is inherently always going to be insecure as long as it's running with GSM, which is fundamentally broken. Heartbleed was an OpenSSL bug. And Linus is absolutely right that if you are running Linux in a nuclear power plant, you absolutely shouldn't connect it to the internet.
> I'm not sure the author of the article is even saying
that
The author, at least, certainly is: > But while Linux is fast, flexible and free, a growing
chorus of critics warn that it has security weaknesses
that could be fixed but haven’t been.There are security weaknesses in Linux that could be fixed but haven't been. The same is true of Windows, MacOS, iOS, etc.
That's different from saying, that if you choose Linux, you have to pay the cost of lowered security.
I suspect you think this makes you seem more intelligent, but in reality, it makes you seem socially inept. Don't be that guy.
> I suspect you think this makes you seem more intelligent
Nope, I'm just a Mac developer. I use OS X every day. MacOS was non-Unix operating system that ran on a PowerPC architecture. You were very far off
> it makes you seem socially inept
If you called Windows 10, Windows XP it would not be socially inept to correct you unless you were not in the tech industry. However, since this is HN, I assumed you could handle it. Sorry!
So because of the mostly theoretical threat of baseband vulnerabilites, we shouldn't bother securing the software running on the application processor? What if I told you that x86 suffers from similar "there's an omnipotent co-processor with access to your memory" issues?
There's nothing theoretical about the attacks on GSM: there are many attacks which have been demonstrated in the wild. [1][2] [3] And while there is a hypothetical vulnerability in the fact that closed-source processors may be backdoored, at least the AES instructions included in x86 haven't been broken yet. A comparable attack to the GSM attacks would be something like viewing a plaintext transmitted over 802.11i, which, as far as I know, hasn't happened yet.
[1] http://www.gsm-security.net/faq/gsm-a5-broken-security.shtml [2] http://www.techrepublic.com/blog/it-security/gsm-encryption-... [3] http://yro.slashdot.org/story/13/12/14/0148251/nsa-able-to-c...
I believe him, but now I'm not so sure anymore with this article. This is a very disconcerting about the linux kernel, I'm totally freaked out by this article. I didn't realize that the state of security with linux has come to this.
My first linux distro was redhat 2.0. And now after almost 20 some years of using linux, I'm now going to have to switch back to Microsaft Windows!
I understand your point, but why is Windows a thing?
There are also areas that Linus needs to be more forthcoming about. There needs to be some notification on security holes, so firewall vendors, etc, can develop rulesets to detect and block exploitation attempts before they happen. Additionally, not notifying of security holes makes it harder to analyze whether or not one should expend the resources in testing/deploying a new kernel, or even where to start work on backporting. His desire for security by obscurity is a huge problem here, and really does need to be fixed.
The malware problem did not affect Windows' popularity either.
The only result of this article is that I have a lower opinion of The Washington Post than I used to.