On CHOW: His burger will EAT your burger
BNET Business Network:
BNET
TechRepublic
ZDNet

February 2nd, 2006

Thinking about Linux security

Posted by Paul Murphy @ 5:00 am

Categories: General, Linux, Security

Tags:

Last week, I read an interesting techtarget article (registration required) Windows-to-Linux desktop migration tips: Why to switch, how to plan by editor Jan Stafford. Here’s her lead and a couple of other paragraphs that give you gist of the argument:

 

Businesses should switch from Windows to Linux desktops because Linux’s technology is superior, according to Jon Walker, CTO of Versora .

It’s great that Linux is an open source platform, but that’s not the main reason why businesses should switch their desktops to it, Walker said. He quoted Paul Graham — programmer, author and inventor of the first Web application — who said: "Users don’t switch from Explorer to Firefox because they want to hack the source. They switch because it’s a better browser."

Walker thinks that Linux’s stronger security tips the scales in its favor as an enterprise desktop operating system (OS).

Linux developers have taken almost the opposite approach to security to what Microsoft has, said Walker. Linux code is open to everyone, so vulnerabilities are spotted quickly and breaches are attacked and fixed rapidly by thousands of developers. The code itself is streamlined, simple, up-to-date and designed for use in enterprise settings, making it easier to secure.

It’s a pretty good article, but I don’t agree with her interviewee’s interpretation of the security issue.

Basically Walker says that the Linux community works in the open, on a clean code base, and responds very quickly while Microsoft works in secret, on a muddled code base, and responds slowly. He’s right, but that’s not the essence of the issue.

In my opinion the most important difference is conceptual, not a matter of response or openness, but one of fundamental design. The Microsoft community’s response to virus and other attacks is fundamentally to defeat exploits after the fact, the Unix approach is to eliminate the exploit opportunity.

Thus the Microsoft community loads anti-virus scanners on its PCs, scans files, and "fixes" or deletes affected files to eliminate the danger these pose. In effect, they let fully armed bad guys into the house hoping to recognize and massacre them before they can commit harm.

The general Unix community, in contrast, fixes the underlying OS or application code to make it difficult or impossible for an exploit to work –rendering any bad guys in the house fundamentally harmless.

The downside of the Microsoft approach, of course, is that new attacks can’t be recognized, defences become increasingly burdensome -virus scanners now search for more than 40,000 attack signatures- and every new idea gets at least one free run -a classic case of closing the barn door each time someone notices that the horse has been stolen.

Unix, including Linux, simply doesn’t do that -by making the system proof against every new attack that comes along we create a situation where Unix becomes stronger each time it’s attacked, and the whole virus scanning idea remains fundamentally inapplicable

Paul MurphyPaul Murphy (a pseudonym) is an IT consultant specializing in Unix and related technologies. See his full profile and disclosure of his industry affiliations.


Email Paul Murphy

Subscribe to Managing L'unix via Email alerts or RSS.

  • Talkback
  • Most Recent of 119 Talkback(s)
kn
hjblj (Read the rest)
Posted by: yulia666_damned Posted on: 07/02/06 You are currently: a Guest | | Terms of Use
BINGO! / We have a Winner!  D. T. Schmitz | 02/02/06
So then why is LAMP the most hacked  No_Ax_to_Grind | 02/02/06
The most hacked boxes are home users Windows  mosborne | 02/02/06
Duh, there are no Linux home users.  No_Ax_to_Grind | 02/02/06
Please try again  Linux User 147560 | 02/02/06
ZOk your right, there are 12 in North America...  No_Ax_to_Grind | 02/02/06
ZOk your an idiot!  Linux User 147560 | 02/02/06
Not quite  balsover | 02/02/06
The best insults always come form Linux zealots...  No_Ax_to_Grind | 02/02/06
Balsover...  Linux User 147560 | 02/02/06
Guesstimates depend on the person  voska | 02/02/06
ZOk your an idiot!  Linux User 147560 | 02/02/06
ZOk your an idiot!  Linux User 147560 | 02/02/06
there are 12 in North America...  axe's worst nightmare | 02/02/06
You may be right, nost won't admit it.  No_Ax_to_Grind | 02/02/06
Bill's Lackeys  bigpicture | 02/03/06
There is more than that now ,  I'm Ye, the MS SHILL . | 02/07/06
That's one of the most  Cardinal_Bill | 02/02/06
Hey, I corrected it...  No_Ax_to_Grind | 02/02/06
Home Users  nisquallypauli@... | 02/02/06
Duh, ...Apache!  thelemite | 02/03/06
A few things  Robert Crocker | 02/02/06
All open source components.  No_Ax_to_Grind | 02/02/06
Your point is?  balsover | 02/02/06
So, Apache should be...  thelemite | 02/03/06
No_Ax paid MSFT shill  Chad_z | 02/02/06
Is that your very best personal attack?  No_Ax_to_Grind | 02/02/06
Trying Hard  Harry Bardal | 02/02/06
Respond = insult in your book?  No_Ax_to_Grind | 02/02/06
No you need to buy the clue  Linux User 147560 | 02/02/06
Oh, and the ZDNet authors don't  John Zern | 02/02/06
I wish you could too.  No_Ax_to_Grind | 02/02/06
No Axe  Linux Guy 1000 | 02/03/06
Thanks Linux Guy!  brble | 02/06/06
Not from what I see  voska | 02/02/06
what you say makes sense, its quite funny though  BrutalTruth | 02/02/06
ok, you asked for that  the_fiddler_on_the_roof | 02/02/06
If you want a 100% safe system....  rock06r | 02/02/06
no you can't  corticus | 02/07/06
any links to that?  crocd | 02/02/06
I think yoiu just did.  No_Ax_to_Grind | 02/02/06
Are you the same No_Ax?  Anti_Zealot | 02/02/06
Yeah, it's this set of rented fingers.  No_Ax_to_Grind | 02/02/06
Message has been deleted.  Linux User 147560 | 02/02/06
CYA (nt)  No_Ax_to_Grind | 02/02/06
Where did you get this false idea?  zkiwi | 02/02/06
Why you ask?  IAHawkeye | 02/02/06
You are really out there bitty  AmusedAtItAll | 02/08/06
Thinking about linux security  leguirerj | 02/02/06
This myth again  Real World | 02/02/06
YaRight Lamp is most hacked  axe's worst nightmare | 02/02/06
Ah, another wanna be fan!!! I love it!!!  No_Ax_to_Grind | 02/02/06
See  axe's worst nightmare | 02/02/06
Hey, I ALWAYS try to give my fans props first..  No_Ax_to_Grind | 02/02/06
what I expected from you  axe's worst nightmare | 02/02/06
Yes I know you as a fan expect a great deal..  No_Ax_to_Grind | 02/02/06
kn  yulia666_damned | 07/02/06
YaRight LAMP is most hacked  axe's worst nightmare | 02/02/06
Not exactly a myth  mosborne | 02/02/06
I couldn't disagree more  Real World | 02/03/06
Maybe this is clearer  mosborne | 02/03/06
2 definitions for the term  NonZealot | 02/03/06
This myth again  AmusedAtItAll | 02/08/06
No Ax still spreading the myth  Roger Ramjet | 02/02/06
Re: No Ax still spreading the myth  axe's worst nightmare | 02/02/06
Dear Fan Club member...  No_Ax_to_Grind | 02/02/06
here ya go axey  axe's worst nightmare | 02/02/06
No Ax  axe's worst nightmare | 02/02/06
Children and new fans often have to wait.  No_Ax_to_Grind | 02/02/06
COWARD  axe's worst nightmare | 02/02/06
coward??? Is that the best you can do?  No_Ax_to_Grind | 02/02/06
Better, but no there yet...  No_Ax_to_Grind | 02/02/06
You mean .. Not there yet...  axe's worst nightmare | 02/02/06
Ah, you caught my typo, good on ya!  No_Ax_to_Grind | 02/02/06
The sad part is, we will never know.  No_Ax_to_Grind | 02/02/06
we will never know.  axe's worst nightmare | 02/02/06
I have eyes...  No_Ax_to_Grind | 02/02/06
As the song says  axe's worst nightmare | 02/02/06
As i say...  No_Ax_to_Grind | 02/02/06
And then we look at desktops  Sabz5150 | 03/01/06
You don't understand, let me explain  NonZealot | 02/02/06
Spot On.  No_Ax_to_Grind | 02/02/06
Are You sure that you understand???  axe's worst nightmare | 02/02/06
Ah, so you set it up for them...  No_Ax_to_Grind | 02/02/06
And how is  axe's worst nightmare | 02/02/06
Because they don't set them up  No_Ax_to_Grind | 02/02/06
Linux is left up to the user as well  Sabz5150 | 03/01/06
Point by point crushing of your post  NonZealot | 02/02/06
Preventing users running attachments  RJCorfield | 02/27/06
Not a true proof  Roger Ramjet | 02/03/06
Kama sutra  nisquallypauli@... | 02/03/06
Your arguments are old and tired  NonZealot | 02/03/06
False argument  Anti_Zealot | 02/18/06
And you supported the fact that Linux is secure  Sabz5150 | 03/01/06
compare IIs 5.x with Apache 1.3.x  thelemite | 02/03/06
Why compare web servers?  NonZealot | 02/03/06
Home OSs?  thelemite | 02/03/06
Good response  NonZealot | 02/03/06
re: good response  thelemite | 02/03/06
Re re: good response  NonZealot | 02/03/06
IE is tied to the OS - absolutely  thelemite | 02/04/06
PS.  thelemite | 02/04/06
thelemite, I'm done with you  NonZealot | 02/04/06
PS re: hacks  NonZealot | 02/04/06
Slashdot? - No these are facts!  thelemite | 02/05/06
RE: thelemite, I'm done with you  AmusedAtItAll | 02/08/06
RE: PS re: hacks  AmusedAtItAll | 02/08/06
You are Blind  balsover | 02/02/06
You ignore other factors  mosborne | 02/02/06
And let's not forget...  Tony Agudo | 02/08/06
interesting opinion piece....  rock06r | 02/02/06
A matter of degree  Roger Ramjet | 02/02/06
I agree with you Paul  jonfromwestmont | 02/02/06
Wow. Now here's a thought  John Zern | 02/02/06
Murph - the man with no shame  zzz1234567890 | 02/02/06
I feel the desperation on Murphs mind  BrutalTruth | 02/02/06
Windows, Linux, Unix, VMS or other OS and vs hackers... hummm  dbaelegance | 02/02/06
Lets talk unix security  zzz1234567890 | 02/14/06
SUID and trusted components  RJCorfield | 02/27/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here