On The Insider: John Mayer Equates Dating with Shame
BNET Business Network:
BNET
TechRepublic
ZDNet

May 18th, 2005

Is the Linux process insecure?

Posted by Dana Blankenhorn @ 10:46 am

Categories: General, Legal, Linux, Security

Tags:

Window of ExposureTime for me to play devil’s advocate again.

The Schneier Wave graph to the right may be the most famous diagram in computer security. It’s named for Bruce Schneier of Counterpane, a leading computer security expert.

As Schneier explained back in 2001, vulnerability to a security bug is highest between the moment the problem is revealed and the moment a patch is made available. After that the risk goes down, but never to zero, because there are always some fools who don’t patch.

A few months after publishing the graph he expounded on this, suggesting that while it’s generally best to disclose a vulnerability as soon as it’s found, it might be better if vendors were notified of them first, and given a fixed time limit on solving each problem, in order to minimize the time between the announcement of a bug and delivery of a fix.

Well, due to the nature of Linux this can’t happen. We’re all responsible for finding exploits and for fixing them. Thus we must have open commuication. Virtually any limit on who can see something, or any delay in letting everyone see something, can mean a delay in implementing a fix.

So yesterday I come across this. It’s a Linux 2.6 security bug, reported on the French Security Information Response Team Web site. I did not get this because I’m clever. It was part of my regular RSS feed. I use this example mainly because it’s a local bug. The announcement notes it can’t be exploited remotely.

It lets users of local systems gain elevated privileges, even institute a local denial of service attack. Pretty nasty. But if I could use this bug to attack a French computer the risk would be much greater, and I wouldn’t be providing the links in the above paragraph, never mind how I got them.

The point is should access to bug information and exploit code be limited at all, and if so, how would you do it? I don’t want the bad guys seeing exploits either, but it’s impossible on the Internet for me to know who the bad guys are.

Microsoft has theoretical control of this situation. Open source does not. Leave your answers at TalkBack.

Dana BlankenhornDana Blankenhorn has been a business journalist for 30 years, a tech freelancer since 1983. You can follow Dana on Twitter. See his full profile and disclosure of his industry affiliations.

Email Dana Blankenhorn

Subscribe to Linux and Open Source via Email alerts or RSS.

  • Talkback
  • Most Recent of 24 Talkback(s)
chmod u+x
Just what he said. Any exe or bat file can be
executed by anyone. However, you really don't
understand Linux permissions, do you, if you
"think" they are just like Windows?

Ev... (Read the rest)
Posted by: GreyGeek Posted on: 05/20/05 You are currently: a Guest | | Terms of Use
well...  bthomasmo@... | 05/18/05
When is a bug "revealed"?  Michael Kelly | 05/18/05
Agreed 100%  __howard__ | 05/18/05
The difference is...  Shadus | 05/18/05
and for better or worse...  bthomasmo@... | 05/18/05
No!- the devil is in the details or rather the Penguin!  whieber | 05/18/05
You Linux noobs...  toadlife | 05/18/05
Here's two answers why Microsoft has no security.  Xunil_Sierutuf | 05/18/05
Fish on!!  toadlife | 05/18/05
FreeBSD not M$ Windows is your desktop of choice?  IT-sys | 05/18/05
Puting words in my mouth  toadlife | 05/19/05
#2 is flawed  rpmyers1 | 05/18/05
chmod u+x foo.txt doesn't equal default insecurity  whieber | 05/18/05
And running as a standard user on windows gives the same immunity  rpmyers1 | 05/18/05
lol  toadlife | 05/18/05
chmod u+x  GreyGeek | 05/20/05
Thats your point?!  whieber | 05/18/05
I take it you've had a windows box owned?  toadlife | 05/18/05
Hassles now thats a selling point!  whieber | 05/18/05
You have just demonstrated the power of the community  Xunil_Sierutuf | 05/18/05
There is a security process, you just don't see it  shemminger | 05/18/05
we deserve full immediate disclosure from all parties involved. the rub  wessonjoe | 05/19/05
Enterprise users have a new option.  praetorpal@... | 05/20/05
Insecure?  xstep | 05/20/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here