00000004.htm
来自「一份很好的linux入门资料」· HTM 代码 · 共 212 行 · 第 1/2 页
HTM
212 行
No known tool for security updates <BR> <BR>These are all mainstream Linux distributions, tending towards a <BR>general audience; at the least, they're not aiming at the router <BR>market or the embedded devices market. These are all products intended <BR>to be used by normal people and thrown up on a corporate network or even <BR> the Internet. Some may be aimed at relatively expert users, but I'm a <BR>fairly advanced user myself, and I still expect that my software <BR>distributor is watching out for security at least minimally. That's <BR>one of the reasons I don't roll my own distribution. <BR> <BR>Of the eight common distributions I could think of, three have nothing <BR>whatsoever to do with security, and at least one of the others didn't <BR>seem to be doing anything useful. No wonder Linux has a security <BR>problem: while those four distributions have probably less than a <BR>quarter of the Linux market, they tend to be high-profile <BR>distributions which garner more than their share of media coverage. <BR> <BR>These distributions aren't just putting their users at risk; they're <BR>damaging Linux's credibility and its image in the marketplace. Every <BR>time I'm asked by a reporter why Linux is so insecure, I have to <BR>consider Caldera, Corel, Turbo Linux, and Slackware before I can answer. <BR> These distributions' total lack of concern with security is an <BR>embarrassment to the entire Linux and Open-Source communities. <BR> <BR>Because of these distributions, I'm forced to admit to reporters that <BR>many Linux installations are insecure, and there's little the average <BR>user can do about it without dedicating an inordinate amount of time <BR>to security work. Most users aren't paid to worry about security, as I <BR>am. For many, computing may be only a small part of their work. These <BR>people can't rightly be asked to read Bugtraq; they've got work to do. <BR> <BR>If only systems were kept up to patch, huge numbers of systems <BR>wouldn't be cracked. On the university campus where I work, systems have <BR> been exploited using the automount daemon bug which is more than a year <BR> old, and which has been patched nearly that long. Being a professional, <BR> I know that they shouldn't even be running it, because I know that <BR>they're not using it. But I can't expect them to know, and I can't <BR>even fix it myself: I didn't know that some of these machines existed <BR>until I found out that they'd been hacked. Asking these users to read <BR>a single, low-volume, vendor-specific mailing list is a pretty good <BR>solution -- when those lists exist. <BR> <BR>Experienced users should abandon Linux distributions which don't provide <BR> security fixes in a timely manner and post that information to a Web <BR>site, a mailing list, or both. They should abandon these distributions <BR>not because they necessarily need the security notices for themselves, <BR>but because these distributions are ruining Linux's image not only <BR>with novice users, but with the reporters and editors who shape <BR>managers' opinions on whether Linux is a viable solution. <BR> <BR>You may claim that you're a hobbyist, and you couldn't care less if <BR>businesses use Linux; that's your right, certainly. However, you lose <BR>nothing when businesses use Linux, you lose nothing when security <BR>updates are made available and publicized, and you gain nothing when <BR>businesses reject Linux because some vendor couldn't be bothered to <BR>package up an already publicly-available solution to a security hole. <BR> <BR>The rest of us do lose. It hurts our professional reputations when we <BR>stand behind a piece of software with frequent and highly-publicized <BR>security lapses. It wastes our time, tracking down hacked user <BR>machines for which we're not responsible and rebuilding them from the <BR>ground up. It wastes our money, when businesses and government <BR>agencies buy more expensive hardware and software for the illusion of <BR>security. <BR> <BR>Solving this problem isn't difficult or time consuming; simply pick <BR>distributions which express a basic level of concern for security <BR>issues, and let vendors know -- at trade shows, in e-mail, in letters to <BR> the editor of your favorite publication -- that security isn't just <BR>about security. It's about preserving our reputation for quality, and <BR>it's about saving time and money. <BR> <BR> <BR> <BR>------------------------------------------------------------------------ <BR>-------- <BR> <BR>Jon Lasser is a Unix Systems Administrator, Lead Coordinator for the <BR>Bastille Linux Project, and author of a forthcoming Unix book from <BR>Macmillan tentatively titled Think Unix. He's never bothered to take a <BR>computer course, except a single Pascal class in high school. He lives <BR>in Baltimore with his wife Kathleen, and their three cats: Mallet, <BR>Dashigara, and Spike. If for some reason you want to know more, check <BR>out his home page. <BR> <BR> <BR> <BR>-- <BR> 每个人都会经过这个阶段,见到一座山,就想知道山后面是什么。我很想 <BR>告诉他,可能翻过山后面,你会发现没什么特别。回望之下,可能会觉得这一 <BR>边更好。但我知道他不会听,以他的性格,自己不走过又怎会甘心? <BR> <BR>Welcome to DNA Studio: <A HREF="http://dnastudio.dhs.org">http://dnastudio.dhs.org</A> <BR>new software, navupdate, wallpapers, mp3z, linux, forums...... <BR> <BR>※ 来源:·BBS 水木清华站 smth.org·[FROM: 202.112.85.250] <BR><CENTER><H1>BBS水木清华站∶精华区</H1></CENTER></BODY></HTML>
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?