Home Blog Page 10366

EFF defends nameless Netizens

Author: JT Smith

On Oct. 13, the Electronic Frontier Foundation and
Public Citizen filed a brief on behalf of an individual,
known as “Jane Doe,” who posted comments to a
Yahoo! Inc. message board that an AK Steel Corp.
(formerly Armco Steel) executive said were disparaging,
threatening, and defamatory, reports ZDNet News.

TurboLinux ships new workstation

Author: JT Smith

TurboLinux, Inc., the high-performance Linux company, today announced the release of its new TurboLinux
Workstation Pro 6.1 that includes the first commercial version of Linux for Intel’s forthcoming Itanium processor
systems (IA-64), from NewsAlert.

Panel: Open Source security needs to be priority

Author: JT Smith

By Grant Gross
Managing Editor

Open Source systems aren’t inherently more secure than propriety systems — unless the designers make security a priority, according to several security experts speaking at a conference Monday.

Panel moderator Peter G. Neumann, from SRI International, argued that Open Source development, which he called “open box,” presents both opportunities of “many eyes” finding software bugs that compromise security, and a challenge when some of those eyes aren’t friendly.

“By itself, the open box paradigm is not a solution, but my contention is it affords us enormously more opportunity that the closed-source model,” said Neumann, speaking at a panel during the 23rd National Information Systems Security Conference in Baltimore, Md. “The problem with [the many eyeballs concept] is if your system is lousy to begin with, the bad guys have a lot of eyeballs.”

Open Source advocate Eric S. Raymond, a scheduled panelist, wasn’t able to attend the session and defend the many eyeballs concept. But the message from the panel, including three people working on making Open Source systems more secure, was that Open Source developers shouldn’t trick themselves into thinking that their systems are more secure just because they don’t come from the company noted for its blue screen of death.

“I don’t think that the many eyes will do the right thing, so I want to apply some tools to make sure the system is secure,” said Crispin Cowan, CTO for WireX Communications and chief research scientist for Immunix Technologies, which is working security solutions for Open Source operating systems.

Many developers sacrifice security for functionality when they’re building a program, the panelists said, and Cowan contended that if security is your top priority, you need to design for security first. It’s a tradeoff depending on a developer’s priorities.

“Does Open Source make a difference? No. If you’re going to build an unsecure system, you’re going to build an unsecure system,” added Rick Smith, senior principal engineer for Secure Computing Corp. “You have to make money, and you take risks to make money, and sometimes the risks are in information security.”

Jay Beale, lead developer for the Bastille Linux security project, said education of system administrators and users is part of the solution to the problem of system security. One audience member, a system administrator in a university setting, said, “All the secure operating systems in the world aren’t going to stop these idiots who give away their passwords.”

Beale suggested system administrators take active roles by warning users who do unsecure things such as use the outdated FTP to exchange files on the Internet. Back in the early, low-user days of the Internet, FTP worked fine, he said, but “the Internet’s become a lot bigger neighborhood, and it’s a lot more rough.”

One advantage for users of Open Source products, Beale said, is they don’t have to pierce a corporate bureaucracy to find someone to respond to bug-fix requests. “If you are the end user who’s depending on your distribution to give you a fix you can easily install, then you’ve got to push them to do it,” he said. “We’ve got to get the end users to start demanding it, and if we don’t, then it’s not going to be a priority for someone trying to get more features in.”

One audience member questioned the commitment many Open Source vendors have to security. “I look at the Open Source environment, and there are people who are very concerned about security, and they’re very vocal, but they don’t seem to be the majority,” he said. “Unfortunately, there doesn’t seem to be a correlation between how security conscience the distribution makers are with how successful their products are.”

Cowen and Beale argued that because users can see the source with Open Source products, they can fix the bugs instead of just relying on the documentation from proprietary vendors. “Documentation lies — read the source,” Beale said.

Open Source projects also have a community of programmers eager to provide solutions. Beale quoted a study saying the average time it took Red Hat Linux 11 days to fix a security problem, while it took Microsoft an average of over three months.

Added Brian Witten, program manager for information assurance at the U.S. Defense Advanced Research Projects Agency: “All Open Source does is it levels the playing field without the good guys having to haggle for the source code.”

Witten announced at the discussion that DARPA was ready to make a substantial investment in Open Source development. No additional information was immediately available.

Category:

  • Linux

Interviews from the Annual Linux Showcase in Atlanta

Author: JT Smith

There’s always something new going on in Linux, reports Maximim Linux, while here at the Annual Linux Showcase in Atlanta, Maximum Linux decided to find out
how some of the visitors feel about a few of the
newest news breaks in the Linux industry.

Category:

  • Linux

Dr. Dobb’s Python-URL for October 17

Author: JT Smith

Linux Weekly News offers Dr. Dobb’s Python-URL! – weekly Python news and links.

Connex offers free trial of SANavigator

Author: JT Smith

Connex, a developer of Storage Area Network (SAN) and
Network Attached Storage (NAS) solutions, today announced
a free trial of its SANavigator(TM) software,
reports PRNewswire, specific instructions for Windows, UNIX or Linux installations
are available on the web site and in the SANavigator ZIP file.

Sphera delivers open software platform for hosting provider industry

Author: JT Smith

BusinessWire: Sphera Corporation, a pioneer in service automation for the Web hosting industry, today
announced the availability of Sphera HostingDirector 3.0, the first open and extensible software
platform to address the mission-critical IT needs of the hosting provider industry.

HP’s Fiorina backs open source

Author: JT Smith

In her keynote speech at researcher Gartner’s
Symposium/ITxpo in Florida, Fiorina said: “The open source
movement is natural, inevitable and creates huge benefits.
It’s part of the next wave of computing, and that will involve
participants and users within the industry in open source.”, from vnunet News.

Category:

  • Open Source

3Com debuts Audrey, Internet appliance

Author: JT Smith

Reuters reports, 3Com Corp.
on Tuesday unveiled a home Internet appliance
named Audrey that provides electronic mail, Web
access, a calendar, address book and synchronization
capability for personal digital assistants.

Category:

  • Unix

Handspring should back Linux to beat Palm

Author: JT Smith

Handspring, the developer of Palm OS-based Visor devices, would present
an even greater threat to Palm Pilots if it decided to create Linux-based, Palm-compatible appliances, suggests this article from All Linux Devices.