*BSD News Article 62633


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.anu.edu.au!newshost.telstra.net!act.news.telstra.net!psgrain!news.sprintlink.net!news.ecrc.de!news.space.net!news.touch.net!news.b-1.de.contrib.net!ns.neckar-alb.de!news.belwue.de!news.uni-ulm.de!rz.uni-karlsruhe.de!not-for-mail
From: ig25@fg70.rz.uni-karlsruhe.de (Thomas Koenig)
Newsgroups: comp.os.linux.misc,comp.os.linux.development.system,comp.os.linux.networking,comp.unix.bsd.bsdi.misc,comp.unix.bsd.netbsd.misc,comp.unix.bsd.freebsd.misc,comp.security.misc
Subject: Re: need secure OS to entrust millions to
Followup-To: comp.security.misc
Date: 27 Feb 1996 19:34:52 +0100
Organization: =?ISO-8859-1?Q?Universit=E4t_Karlsruhe_(TH),_Germany_?=
Lines: 14
Message-ID: <4gvisc$a55@fg70.rz.uni-karlsruhe.de>
References: <4gi6t6$3h9@lace.colorado.edu> <y5ad974s4v4.fsf@graphics.cs.nyu.edu> <4gqf17$1lr@cynic.portal.ca> <1996Feb25.152559.8977@jarvis.cs.toronto.edu>
Reply-To: Thomas.Koenig@ciw.uni-karlsruhe.de
NNTP-Posting-Host: fg70.rz.uni-karlsruhe.de
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
NNTP-Posting-User: ig25
Keywords: security linux freebsd operating system
Xref: euryale.cc.adfa.oz.au comp.os.linux.misc:89629 comp.os.linux.development.system:18514 comp.os.linux.networking:30398 comp.unix.bsd.bsdi.misc:2530 comp.unix.bsd.netbsd.misc:2371 comp.unix.bsd.freebsd.misc:14764 comp.security.misc:22847

In comp.os.linux.networking, colohan@eecg.toronto.edu (Chris Colohan) wrote:

>What do you lose by using a free OS in a mission critical application?
>
>1.  Security through obscurity.  More people have access to the source
>code for your OS, so there is a greater chance of someone finding a
>security flaw and exploiting it before you can fix it.

ARGH.

The fewer people have scurtinized the code, the more likely accidental
bugs or deliberate trojan horses are.

Security Maxim #1: The bad guys DO have the info.