*BSD News Article 62253


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!olive.mil.adfa.oz.au!navmat.navy.gov.au!posgate.acis.com.au!warrane.connect.com.au!news.syd.connect.com.au!news.mel.connect.com.au!munnari.OZ.AU!metro!metro!inferno.mpx.com.au!news.mel.aone.net.au!imci4!newsfeed.internetmci.com!in2.uu.net!news.dialnet.net!news.dialnet.net!not-for-mail
From: dledford@dialnet.net (Doug Ledford)
Newsgroups: comp.os.linux.development.system,comp.os.linux.misc,comp.os.linux.networking,comp.unix.bsd.freebsd.misc,comp.unix.bsd.netbsd.misc,comp.unix.bsd.bsdi.misc
Subject: Re: need secure OS to entrust millions to
Followup-To: comp.os.linux.development.system,comp.os.linux.misc,comp.os.linux.networking,comp.unix.bsd.freebsd.misc,comp.unix.bsd.netbsd.misc,comp.unix.bsd.bsdi.misc
Date: 26 Feb 1996 08:01:09 GMT
Organization: Digital Internet Access Link, Inc. Springfield, MO 873-DIAL
Lines: 60
Message-ID: <4grpc5$5o@news.dialnet.net>
References: <4gi6t6$3h9@lace.colorado.edu> <312D2029.FF6D5DF@freebsd.org> <4gmf5l$mel@news.bu.edu>
NNTP-Posting-Host: news.dialnet.net
X-Newsreader: TIN [UNIX 1.3 BETA-950824-color PL0]
Xref: euryale.cc.adfa.oz.au comp.os.linux.development.system:18085 comp.os.linux.misc:88774 comp.os.linux.networking:29807 comp.unix.bsd.freebsd.misc:14417 comp.unix.bsd.netbsd.misc:2338 comp.unix.bsd.bsdi.misc:2480

Mikhail Teterin (mi@aldan.bu.edu) wrote:
: Honorable Jordan K. Hubbard
:       wrote on Feb 22, 1996 (in article <312D2029.FF6D5DF@freebsd.org>):
: 
: =Don't get me wrong, I think that free operating systems are great
: =(obviously) and perfectly wonderful for many things, but secure cash
: =transactions and running life support systems are not the kinds of
: =things I'd entrust to them, if only for pure legal liability reasons.

Neither would the makers of the "commercial" OSes in question.  Most of 
them include disclaimers in their documentation and warranty statements 
specifically disallowing any liability for the use of their os in such 
aplications as mentioned above.

: 
: There must be something wrong with the country, if decisions
: are made "for pure legal liability reasons"...
: 

I agree.  Grow some guts, take a little responsibility for your actions, 
and fix your mistakes.  That's the way things outght to be handled.  I 
have no problem with someone screwing up, if and only if they will 
acknowledge their mistake when brought to their attention and correct it 
in a timely fasion.  Do this and I won't sue.

: Do not forget, BTW, about recent break-in to Citibank computers by
: a guy from Russia. I do not think Citibank was using Linux (or
: FreeBSD).

When the security hole in Linux was found that allowed someone to log in
with the username "-froot" and get root access without needing a password,
it was fixed within days.  The same problem was found under AIX at the
same time.  IBM's official patch was MUCH slower coming around.  Think
about that when you wonder how fast security holes will get fixed under
which OSes. 

: 
: =Buy a commercial OS and the best support contract money can buy.
: 
: With all due respect, Mr. President, support contract does not imply
: the OS itself has to be commercial.

Nor does it imply any kind of legal liability for failure of the OS on 
the part of the manufacturer.  It just means someone on the other end of 
the phone will hold your hand through setting things up, and console you 
as they tell you "I'm not sure when the fix for that problem will be out"

Most of my disgruntlement with the above comments has nothing to do with 
an advocacy of free unices, but rather an avid distaste for the 
commercial OS vendors I have worked with.

-- 
*****************************************************************************
* Doug Ledford                      *   Unix, Novell, Dos, Windows 3.x,     *
* dledford@dialnet.net    873-DIAL  *     WfW, Windows 95 & NT Technician   *
*   PPP access $14.95/month         *****************************************
*   Springfield, MO and surrounding * Usenet news, e-mail and shell account.*
*   communities.  Sign-up online at * Web page creation and hosting, other  *
*   873-9000 V.34                   * services available, call for info.    *
*****************************************************************************