Some stories that may be of interest

Miscellaneous Forums/General Discussion/Some stories that may be of interest

Torvalds attacks IT industry 'security circus'
http://news.zdnet.co.uk/software/0,1000000121,39448527,00.htm

Privacy watchdog may get powers to raid (And I hope this has an effect on the topic below)
http://news.zdnet.co.uk/security/0,1000000189,39448955,00.htm

Peer protests BT's Phorm trials
http://news.zdnet.co.uk/security/0,1000000189,39448963,00.htm

Defra to scrap its desktops and handhelds (this would be worrying if other government agency's followed this path topic see below)
http://news.zdnet.co.uk/hardware/0,1000000091,39448520,00.htm

MoD loses 87 USB devices holding classified data
http://news.zdnet.co.uk/security/0,1000000189,39448533,00.htm

And something I must have a look at
Computer blunders of the technologically inept
http://resources.zdnet.co.uk/articles/imagegallery/0,1000002003,39447470,00.htm (look in the Latest New section under A Life in the Service Industry if you go to Rod's lair)

Wow, I am really disappointed by the name calling by Torvalds. He normally seems like a level headed and reasonable person. Calling OpenBSD people "masturbating monkeys" because they are extremely focused on security is a bit childish.

And it is stupid giving the government privacy watchdog group the power to raid businesses... Now, all you have to do is print up a fake government ID and paperwork, and carry out raids on people. Lets see how well privacy is protected when any dimwit with a laminated badge can conduct "privacy audits" on your company. "In order to encourage you to protect your data, we want you to give up your data to anyone who comes busting into your facility asking for it!". Yeah, GREAT IDEA!!! Geez, when will people learn that a police state is actually *LESS* secure than a free society? So are they really interested in protecting privacy and they are just incompetent fools, or are they going to be collecting data for some government anti-terror database and the "privacy" thing is just a cover story?

LOL, I think "masturbating monkeys" is a bit rough, if bsd want to label up even the most trivial of things as "critical" as the real critical stuff then thats up to them isn't it.
However, I think he may have been taken out of context. Most 'security flaws' being ranted about -are- ridiculously trivial and could lead to a complacency (in the sense of crying wolf) on the part of those who fix the bugs and the ones who would start rolling their eyes at the constant flow of largely over-trumpeted updates.
Torvalds wrote that disclosing the bug itself was enough, without having to label each individual security flaw. He added that taking the bugs to the "security circus" level only glorified the wrong kind of behaviour. "It makes heroes out of security people, as if the people who [...] fix normal bugs aren't as important," wrote Torvalds.
A recent ms-backed report into the security of linux and windows concluded that linux had more security flaws. However what it didnt account for was the exact nature of them as they were simply going by "number of security flaws" which was not only misleading but totally inaccurate. (as most of the linux ones were either really mundane or difficult to exploit)

Either way as long as stuff gets fixed then thats ok.


I thought some of the support photos of the inept were funny. If i was alowed to take photos in our support lab i could post a few classics too (like coffee stains in the dvd rom/"cup holder", A GF9800 versus a still smoking 300 watt PSU.. that kind of thing) :D

I do like the "How to get better service" section in Rod's lair. This bit is quite amusing.
12 Even though you're not a technical person, ask for a complete technical breakdown, preferably to molecular level, of EXACTLY what went wrong with their lousy machine, and what was done to repair it. Make the technician guarantee that the machine will never break down again. When the technician does explain the problem, interrupt frequently, emphasizing that you did nothing wrong. Make sure the technician knows he's not dealing with a dummy. You probably know more than he does.

Something to remember the next time you have to take a PC for repair ;)

He normally seems like a level headed and reasonable person.

Since when, exactly? he flamed respected and competent people back when personal computers were still a novelty. A great deal of his persona is based on such comments, actually, and usually gets in the spotlight because of it (last time he offended the whole Gnome project out of the blue in defense of KDE, and the whole japanese open source community because they don't flame people to defend their ideas (?!) ). He could have stopped at the point where it said that bug solver analysts don't get the attention they deserve, but actually had to go over with ridiculous claims (it's really so difficult to explain why unless you are a nerd in a sealed bunker security holes are more important than others?). It's simply malicious to attack part of your own community in order to gain attention where you could just defend another part of it. Basically he is doing the very same thing he accuses security analysts of doing.

The nature of an open-source OS should imply that everyone could do a distribution which fits his needs, or fills a niche where there isn't offer in a business environment. If OpenBSD had success, they clearly hit a soft spot there. If you don't like it, you still win since they attracted more people to your offering. It's talent you've got (more or less) on your side, while he basically states they have not expertise since any bug solver could do their job (which is NOT true: experience you get on the field is valuable, and with their clients it's experience not many analysts can get their hands on).

It's true that security became a business and as such end up using scare tactics in order to drive money, but it is also true that every pc today is a connected terminal and most of the anti Microsoft campaign is based on the "on linux you don't get any virus" claim, while by telling that security holes are as important as any other bug he is actually confirming the fact that there aren't many viruses on Linux just because it isn't widely used as a desktop environment.

"But it's no less important than everything else that is also important!"

Hands off, that one seems taken from a George W. Bush speech. :)

MoD loses 87 USB devices holding classified data

That's the old topic of computer security against people's awareness and competence. That's why social engineering is still so critical. To think that critical information regarding Blair and foreign policies in Iraq was retrieved just by looking at the history of a word document on a floppy, or that a journalist in Afghanistan bought from a street market an undecrypted laptop used by Al Qaeda executives (later handed to the CIA) make most convoluted spy stories unrealistic. :)

Anyway, it has to be kept in mind that in espionage most documents are important in the short term, since in the long run most governments have ways to retrieve confidential information (expecially with today's hardware, where crypted data can be unlocked in a matter of days or at the most months with the right equipment).

According to the Register Torvalds is now having a go at Dig users http://www.theregister.co.uk/2008/07/18/linus_torvalds_digg/

And some thing new on Intel http://www.channelregister.co.uk/2008/07/18/intel_ec_response/

SCO ordered to pay Novell $2.5m Unix royalties
http://www.theregister.co.uk/2008/07/17/sco_ordered_to_pay_novell/

UK.gov tells throttling petition: Choke on it
http://www.theregister.co.uk/2008/07/18/epetition_broadband/

I agree with D4, Linus has been taken outa context. I'm on torvalds side.

If Torvalds were working in the medical sector, where people can actually die because of software failures, he'd know that those 'masturbating monkeys' have their priorities set right. He should spend some time in an FDA-regulated environment for a while just to get a reality flash.

If Torvalds were working in the medical sector, where people can actually die because of software failures

Well, software failures in the medical field are unlikely to be caused by security holes... that's his point actually, even though it is a field which isn't suited for Linux. However Linux is mostly used in environments where the machine is handling almost only network related tasks and in this cases security is the top priority, so his point doesn't make much sense but on a pc without any kind of connection. Even for desktop use, in this day and age you can't prioritize down security when almost everyone shares financial informations through his IPV4 connection for bills and purchases.

I prefer Torvalds being a bit crazy in writing. He isn't in charge of an operating system. He is key to the development of a major component of it, and could be considered one of the guys who got the ball rolling, but he really is quite modest about it - and rightfully so. Linus makes a point of his presence being minimal; Linux will never see a 'hit by a bus' problem, because every developer has his own publishable kernel tree and the entire development process is open. His bizarre manners are just another hint at that modesty; he does not see himself, or want to be seen as, some all-holy 'master of all'.
GTK, FreeDesktop, GNOME, Bazaar, etc. have no need for the Linux kernel in particular; his work is just another chunk of the free software ecosystem.

And yes, I too prefer the preference of normal bugs rather than an obsession with security. Linus' kernel is really quite focused on desktop use. I am sure if someone wants a kernel [Edit: I mean Linux kernel] whose developers care mainly about security fixes, there is someone with such a tree out there...

On the contrary I think he makes such statements because he realizes the opposite and grins (or masturbate as a monkey?) at the reactions. :)

I am sure if someone wants a kernel whose developers care mainly about security fixes, there is someone with such a tree out there...

Uhm... they are the subject of this discussion, the very same OpenBSD guys he flamed during his own circus. :)

Well, software failures in the medical field are unlikely to be caused by security holes... that's his point actually, even though it is a field which isn't suited for Linux.
Actually it is, i do some contract work for a huge biotech company who use a suse-based linux system for monitor & control of machinery, which has something to do with manufacture for protein separation for the hospital nearby. Its highly specialized stuff which is probably why they use it (they have re-written it and customized it to do the job) its highly stable and dedicated to the task. A system crash in there would be either very dangerous or very expensive which is why they need a rock solid system.
Some of the main servers are also suse, aix or solaris.

Needless to say us 'windows techs' are not allowed near it. :)

while by telling that security holes are as important as any other bug he is actually confirming the fact that there aren't many viruses on Linux just because it isn't widely used as a desktop environment.
While thats probably partly true, and there are viruses for every OS, it is much more difficult to write actual exploits and spyware on a linux system simply from the way it is built and operates. Most of the few linux/unix viruses work badly or not at all because of this.
Still there is no defence against admin/root-user stupidity though (on any system!)

Doiron, I beg to differ. A couple of years ago, I've worked in the EDC field (for clinical trials sponsored by various large pharmaceutical corporations), where live and production server farms where used by thousands of users. Security -is- an issue, and in many cases, EDC software actually calculates the dosage of the patient's next medication. Security is important not only to prevent people from stealing or accessing sensitive data, but also to prevent (malicious) manipulation or software failures because of security holes. The amount of QA in that field is a real nightmare and no fun at all. For example, you cannot install a patch without running and documenting full QA loops for the --entire-- system. But, as my senior management used to tell us: "Look at Contergan if you have forgotten why we are doing this."

A system crash in there would be either very dangerous or very expensive which is why they need a rock solid system.

You misunderstood what I was saying. Since it is dedicated machinery it is unlikely to receive external input which could compromise its security and therefore its stability. The kind of bug that could more likely affect its stability are all the other ones, and anyway, in this context EVERY bug is as important, so it's one of those rare cases where Torvalds point is valid.

a suse-based linux system for monitor & control of machinery

Theoretically though it isn't a good choice for robotics and machinery: if you use a monolithic OS and the system crashes, all the machinery crashes, which is unacceptable in the medical field among others (unless you have a good and stable fail safe server system up and running).

I know theres 3 embedded workstations, all the same, one in the control room and 2 on different 'levels' of the machine that can be used to control/monitor it. Perhaps they use some kind of '3 vote' failsafe or something.

Ill ask when i go back to work :/

Actually, when I was visiting a hospital lately, I was paying attention to the OS the machines (ultrasound, baby heart and contraction monitor, etc)seemed to use, and all seemed to be running Windows NT.

Yep, ive seen it in a few odd and unlikely places too (like cashpoints! -you can tell from the occasional bluescreen or error message box).
Either way, if i was building something where stability/reliability was critical i would have more faith in Unix or Linux than i would in windows, simply because it is more robust.

I've seen Windows NT in ATM's too while they restart the system.

I've had trouble finding my luggage in one of the large international airports a few years back when all the luggage retrieval mills in the arrival hall were showing Blue Screen's of Death instead of the respective flight numbers...

This is my favorite: //www.techosphere.net/wp-content/uploads/2007/05/bluescreenofdeath.jpg

I think windows 7 should introduce the "green screen" for a refreshing change.

Although before everyone accuses me of... whatever the word is, you will be pleased to know that after 3 years i had my first "kernel panic" the other day.
(although i blame me, ati and a hacked kernel)

I actually liked the custom case mod myself.