<?xml version="1.0"?>
<rss version="2.0">
<channel>
  <title>Darwin&#039;s Theories - Security category</title>
  <link>http://theories.darwinsys.com:80/categories/security/</link>
  <description>Call it a Blog if you like -- Ian</description>
  <language>en</language>
  <copyright>Ian Darwin</copyright>
  <lastBuildDate>Sun, 19 Oct 2008 19:23:00 GMT</lastBuildDate>
  <generator>Pebble (http://pebble.sourceforge.net)</generator>
  <docs>http://backend.userland.com/rss</docs>
  
  
  <item>
    <title>It&#039;s true what they say about airport security</title>
    <link>http://theories.darwinsys.com:80/2008/10/18/1224362460000.html</link>
    
      
        <description>
          &amp;quot;Airport security in America is a sham&amp;mdash;&amp;ldquo;security theater&amp;rdquo; designed to make travelers feel better and catch stupid terrorists. Smart ones can get through security with fake boarding passes and all manner of prohibited items&amp;mdash;as our correspondent did with ease...&amp;quot;&lt;br /&gt;
&lt;br /&gt;
There&#039;s nothing I can add to &lt;a href=&#034;http://www.theatlantic.com/doc/200811/airport-security&#034;&gt;this&lt;/a&gt;. While you&#039;re there, check the other security-related articles on the site.
        </description>
      
      
    
    
    
    <category>Politics</category>
    
    <category>Security</category>
    
    <comments>http://theories.darwinsys.com:80/2008/10/18/1224362460000.html#comments</comments>
    <guid isPermaLink="true">http://theories.darwinsys.com:80/2008/10/18/1224362460000.html</guid>
    <pubDate>Sat, 18 Oct 2008 20:41:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Linus Just Doesn&#039;t Get It</title>
    <link>http://theories.darwinsys.com:80/2008/07/16/1216230840000.html</link>
    
      
        <description>
          Linux founder Linus Torvalds makes an amazing claim about Linux security (or not) on gmane.kernel.org (I&#039;m not even gonna help &lt;a href=&#034;http://en.wikipedia.org/wiki/Pagerank&#034;&gt;pagerank&lt;/a&gt; that article by linking to it; search the newsgroup name and the date 2008-07-08). Speaking about security fixes, he says:&lt;br /&gt;
&lt;blockquote&gt;... It makes &amp;quot;heroes&amp;quot; out of security people, as if the people who [just]&lt;br /&gt;
fix normal bugs aren&#039;t as important.&lt;br /&gt;
&lt;/blockquote&gt; &lt;blockquote&gt;In fact, all the boring normal bugs are _&lt;u&gt;way&lt;/u&gt;_ more important, just &lt;br /&gt;
because there&#039;s a lot more of them. I don&#039;t think some spectacular &lt;br /&gt;
security hole should be glorified or cared about as being any &lt;br /&gt;
more &amp;quot;special&amp;quot; than a random spectacular crash due to bad locking.&lt;br /&gt;
&lt;/blockquote&gt; &lt;blockquote&gt;Security people are often the black-and-white kind of people that I &lt;br /&gt;
can&#039;t stand. I think the OpenBSD crowd is a bunch of masturbating &lt;br /&gt;
monkeys, in that they make such a big deal about concentrating &lt;br /&gt;
on security to the point where they pretty much admit that nothing &lt;br /&gt;
else matters to them.&lt;/blockquote&gt; Normal bugs are &amp;quot;way more important&amp;quot; than security to Linus, the guy in charge of Linux? I&#039;m sure gonna think twice before running Linux on anything connected to the Internet. If he&#039;d actually read the &lt;a href=&#034;http://www.openbsd.org/security.html&#034;&gt;OpenBSD security policy&lt;/a&gt; document, or any of our &lt;a href=&#034;http://www.openbsd.org/papers/&#034;&gt;presentations at conferences over the years&lt;/a&gt;, rather than just calling silly names, he&#039;d know that OpenBSD works on ordinary bugs as a way of preventing security bugs. But I guess it&#039;s easier to sit at home pulling on your tool chain and calling people names, than to actually acquaint yourself with the facts. Well done, Linus. Next time I won&#039;t even bother recommending Linux as a second choice after OpenBSD.&lt;br /&gt;
&lt;br /&gt;
P.S. As if to prove the point, the next day, security mailing lists were full of this:&lt;br /&gt;
&lt;blockquote&gt;Wei Wang discovered that the ASN.1 decoding routines in CIFS and &lt;br /&gt;
SNMP NAT did not correctly handle certain length values. Remote &lt;br /&gt;
attackers could exploit this to execute arbitrary code or crash&lt;br /&gt;
the system. (CVE-2008-1673) &lt;br /&gt;
&lt;/blockquote&gt;So they have CIFS and SNMP in the Linux kernel, and they haven&#039;t checked for overflows? &#039;Nuff said!&lt;br /&gt;
&lt;br /&gt;
P.P.S: Apparently not enough said! It seems that the esteemed &lt;a href=&#034;http://seclists.org/fulldisclosure/2008/Jul/0276.html&#034;&gt;Mr. Torvalds is also implicated in a massive coverup of security bugs (aka attempted &amp;quot;security through obscurity&amp;quot;)&lt;/a&gt;.
        </description>
      
      
    
    
    
    <category>Open Source Software</category>
    
    <category>OpenBSD</category>
    
    <category>Security</category>
    
    <comments>http://theories.darwinsys.com:80/2008/07/16/1216230840000.html#comments</comments>
    <guid isPermaLink="true">http://theories.darwinsys.com:80/2008/07/16/1216230840000.html</guid>
    <pubDate>Wed, 16 Jul 2008 17:54:00 GMT</pubDate>
  </item>
  
  </channel>
</rss>
