No edit summary |
m (→Security Circus: s/Linux/Linus) |
||
Line 7: | Line 7: | ||
=== Security Circus === | === Security Circus === | ||
By far the most entertaining story from last week was | By far the most entertaining story from last week was Linus giving a few choice quotes[1]. | ||
He does get some things right, but there's still the very real fact that security flaws let people do things they shouldn't be able to do. This adds a certain amount of danger and does require more attention than some other flaws. A nice comparison is automotive recalls. If there are two problems, one is a broken cup holder, the second makes the car explode, which do you think they'll do a recall for? | He does get some things right, but there's still the very real fact that security flaws let people do things they shouldn't be able to do. This adds a certain amount of danger and does require more attention than some other flaws. A nice comparison is automotive recalls. If there are two problems, one is a broken cup holder, the second makes the car explode, which do you think they'll do a recall for? | ||
[1] http://news.cnet.com/Torvalds-attacks-IT-industry-security-circus/2100-1007_3-6243900.html | [1] http://news.cnet.com/Torvalds-attacks-IT-industry-security-circus/2100-1007_3-6243900.html | ||
=== principle of least privilege === | === principle of least privilege === |
Revision as of 02:40, 20 July 2008
Security Week
In this section, we highlight the security stories from the week in Fedora.
Contributing Writer: JoshBressers
Security Circus
By far the most entertaining story from last week was Linus giving a few choice quotes[1].
He does get some things right, but there's still the very real fact that security flaws let people do things they shouldn't be able to do. This adds a certain amount of danger and does require more attention than some other flaws. A nice comparison is automotive recalls. If there are two problems, one is a broken cup holder, the second makes the car explode, which do you think they'll do a recall for?
[1] http://news.cnet.com/Torvalds-attacks-IT-industry-security-circus/2100-1007_3-6243900.html
principle of least privilege
Steve Grubb has a nice interview up on SearchEnterpriseLinux.com[1].
It offers some hints into some of the intresting things that have happened and can be expected in the SELinux space.
[1] http://searchenterpriselinux.techtarget.com/news/article/0,289142,sid39_gci1321374,00.html">SearchEnterpriseLinux.com