Paul Flint <[email protected]> writes:
> Also, unlike Microsoft, which has deadlines to meet, GNU/Linux only releases
> new versions when there are enough new features, there is much less rush, and
> less chance of cutting corners in terms of security.

I'd really like to see some research that proves this out, cause I don't
believe it.  With some notable exceptions — OpenBSD and some other
distros and projects (e.g. SELinux) focused specifically on security – I
don't think commercial software "cuts corners" in terms of security any
more than open-source software takes due diligence with respect to
security.

Security is hard.  Either the developer is specifically addressing it or
not.  But once they are, it's usually not an issue of time pressure.


> Finally, the overall design of Linux, and also the more recent Apple
> Macintosh Operating System which is based on Linux's cousin, BSD Unix, are
> designed to limit exposure in case of an exploit, because of this and many
> other security design innovations, there are almost no viruses for Linux.

Not to undercut this point too much, because non-admin-by-default and
user-based access control is really valuable … but I'd content the lack
of viruses, &c. is mostly due to market share, not technical inability.
If the installed footprint of linux and OS X were large enough to
justify it, all sorts of local privilege-escalation exploits would be
found pretty quick.  Though they're not even needed; malware that
injects even a user-level process can be part of a botnet and
spam/ddos/scan/proxy just as well as something running as root,
especially if undetected.

-- 
...jsled
http://asynchronous.org/ - a=jsled; b=asynchronous.org; echo $...@${b}

Attachment: pgpda8hSaFIyq.pgp
Description: PGP signature

Reply via email to