MESSAGE
DATE | 2004-09-03 |
FROM | Ron Guerin
|
SUBJECT | Re: [hangout] Re: Advocacy vs. Zealotry vs. Who Cares?!?
|
Billy wrote:
> I apologize.. That was a TERRIBLE link... It only included > >vulns in the OSVDB containing the word "Red Hat", which isn't >really a good way to identify vulns in Linux kernels or apps. >Most of the really BIG vulnerabilities didn't appear on the list, >and I didn't really review it before sending it off... > >Look, last week I got an advisory that anyone running Qt-3.3 >could wind up run arbitrary code by viewing a malicious JPG. > >CVS is full of holes. SSH holes happen all the time. > >This stuff happens all the time, and it's usually fixed quickly. >But people just DON'T UPDATE what they believe to be their >'totally impenetrable' Linux machines, because they believe the >machines are bulletproof. They aren't. > Thank you sir, for yet again speaking the unpopular truth. One of these days real soon now, all this asinine talk on the 'net about how GNU/Linux boxes are inpenetrable and there's "nothing to worry about" is going to bite us on the ass and these people that say these things won't be the ones stuck cleaning up the mess.
Once people find out they've been mislead and lied to, getting their trust back (think the boss who has the final say on new systems) will be twice as hard as getting it the first time was.
- Ron ____________________________ NYLXS: New Yorker Free Software Users Scene Fair Use - because it's either fair use or useless.... NYLXS is a trademark of NYLXS, Inc
|
|