Re: Security followup

Subject: Re: Security followup
From: Bruce Byfield <bbyfield -at- axionet -dot- com>
To: "TECHWR-L" <techwr-l -at- lists -dot- raycomm -dot- com>
Date: Fri, 17 Jan 2003 18:57:14 -0800


Andrew Plato wrote:

This is why saying things like "use Linux, you'll be more secure" are totally
misleading.
Yes and no. Much of what you say is true. You can't, for example, compare the CIS tests for Windows and for Linux to say which one is more secure, because the tests aren't complementary.

However, that doesn't mean that you can't talk about underlying capability - for example, about whether passwords are stored encrypted or not, and what encryption methods are used.

In other words, you can't say that this Linux machine is more secure than that Windows machine simply because of its operating system. The individual configuration of each machine needs to be taken into account. However, you can say - along with the majority of veteran system administrators - that, overall, Linux has the POTENTIAL for greater security. Its features and the approach to security taken by its development community help to ensure that.

I mention this in the interests of accuracy, but it's starting to sound uncomfortably like a holy war.

One thing we can all agree on: if you want to be secure, you have to learn about security measures, and implement them. You can't just choose a piece of software and be secure. Choosing to run Linux won't automatically make you safer. Nor will simply installing Norton AntiVirus.

--
Bruce Byfield bbyfield -at- axionet -dot- com 604.421.7177
http://members.axion.net/~bbyfield

"Fairy tales are more than true: not because they tell us that dragons exist, but because they tell us that dragons can be beaten."
-G. K. Chesterton.



^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
A new book on Single Sourcing has been released by William Andrew
Publishing: _Single Sourcing: Building Modular Documentation_
is now available at: http://www.williamandrew.com/titles/1491.html.

Help Authoring Seminar 2003, coming soon to a city near you! Attend this
educational and affordable one-day seminar covering existing and emerging
trends in Help authoring technology. See http://www.ehelp.com/techwr-l2.

---
You are currently subscribed to techwr-l as:
archive -at- raycomm -dot- com
To unsubscribe send a blank email to leave-techwr-l-obscured -at- lists -dot- raycomm -dot- com
Send administrative questions to ejray -at- raycomm -dot- com -dot- Visit
http://www.raycomm.com/techwhirl/ for more resources and info.



Follow-Ups:

References:
RE: Security followup: From: Andrew Plato

Previous by Author: Re: Security followup
Next by Author: Re: Speaking of resumes....
Previous by Thread: RE: Security followup
Next by Thread: Re: Security followup


What this post helpful? Share it with friends and colleagues:


Sponsored Ads