Re: The state of linux security

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Helge Hafting
Date: Sunday, July 20, 2008 - 4:01 am

On Wed, Jul 16, 2008 at 04:05:07PM +0000, Cheradenine Zakalwe wrote:

Bear in mind that top linux development does not happen in a
corporation. So "commercial value" is a complete non-issue.
Corporations like RedHat and SUSE care about this though. If
you want guarantees and documented security - that is where you
want to go. Not to the kernel mailing list. 


Sure. And kernel developers don't want their machines
taken over either. So they do fix security bugs.


Not absurd if you think about it. Most linux developers don't develop
linux for money - they don't have customers - so customers have *no*
hold over them at all. Vendors are the ones who have to care, so they
do that. 

Still, linux security is good for a different reason - there is prestige
in making linux good, and so developers strive for that. Also,
security-concerned vendors are always welcome to bring security
patches...




Each developer has the mindset "what I want from linux". That's
what you get from such a loosely organized effort. But many actually
wants security, so you get that even without a clear policy.


This is much harder to do in linux, than in a closed-source system. If I
bribe a key microsoft developer to put in a backdoor, then nobody notice
until I exploit it - for the source code is a trade secret.

If i bribe a linux developer to put in a backdoor, then this developer's
patch will likely be rejected by the upstream maintainer or Linus, for
containing a griveous scurity flaw. And if it isn't caught immediately,
then it will still be open for all to see.

Also, bribing a key linux developer is probably much harder, since
they work for pride instead of money. Someone getting caught
would likely never be trusted in open-source development again,
a dramatic loss for such a person.



Current attitudes has brought linux where it is today - it works very
well.

Helge Hafting

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
The state of linux security, Cheradenine Zakalwe, (Wed Jul 16, 9:05 am)
Re: The state of linux security, Randy Dunlap, (Wed Jul 16, 9:26 am)
Re: The state of linux security, david, (Wed Jul 16, 9:38 am)
Re: The state of linux security, David Newall, (Wed Jul 16, 9:38 am)
Re: The state of linux security, Alan Cox, (Wed Jul 16, 10:57 am)
Re: The state of linux security, Valdis.Kletnieks, (Wed Jul 16, 1:08 pm)
Re: The state of linux security, Stefan Roas, (Wed Jul 16, 1:29 pm)
Re: The state of linux security, Helge Hafting, (Sun Jul 20, 4:01 am)