On 10/25/07, Bernd Petrovitsch <bernd@firmix.at> wrote:Do you lock your bike up when you leave it lying around? My point is that real security comes in layers, not one perfect solution that will always work everywhere for everyone. The latter is a pipe-dream. The fallacy here is to believe that just because they have no security, that it will *in*any*way* change their behavior. I deal with real users daily, and *they*don't*care*. Further, there's no level of education that we can instill into the community to make them aware of the issues and change their habits accordingly, because real users don't have the background to understand those lessons. While you can teach them that running an executable from someone they haven't heard of is obviously bad, they don't know why downloading an image is potentially dangerous, "it's an image, right?" "Well, there's these things called buffer overflows..." <eyes glaze over> Security is not an all or nothing game, it's layers. And we have to make sure that the layers are usable without taking a course from the NSA. I'd love to see a poll of the kernel development community to find out how many use SELinux on their machines, for example. So your argument is that if there weren't a personal firewall on Windows, that a significant number of people would then not run as Administrator? I beg to differ. Ray -
| Michał Kudła | [2.6.26-rc5] iwlwifi 4965 not working - last on 2.6.23 |
| monstr | [PATCH 52/60] microblaze_v4: fcntl.h sockios.h ucontext.h |
| James Bottomley | Re: Integration of SCST in the mainstream Linux kernel |
| Nick Piggin | [rfc] no ZERO_PAGE? |
git: | |
| Patrick Altman | Git Library? |
| Jakub Narebski | Re: [RFC] origin link for cherry-pick and revert |
| Avery Pennarun | [bug] Segfault in git rev-list --first-parent --bisect |
| skimo | [PATCH 16/22] unpack-trees.c: optionally clone submodules for later checkout |
| Richard Stallman | Real men don't attack straw men |
| Marco Peereboom | Re: Real men don't attack straw men |
| James Hartley | scp batch mode? |
| Brandon Lee | DELL PERC 5iR slow performance |
| Julius Volz | [PATCH RFC 13/24] IPVS: Add IPv6 support to ip_vs_conn_hashkey() |
| Christopher Snook | RFC: Nagle latency tuning |
| David Miller | Re: [PATCH 10/11] [IPSEC]: Disallow combinations of RO and AH/ESP/IPCOMP |
| Jeff Kirsher | [RESEND][NET-NEXT PATCH 04/29] ixgbe: Update watchdog thread to accomodate longerl... |
