Magic Bullets, Free Lunch, and other myths Ben Staab COSC5010 Computer Security
In November 2004, Brittish security firm MI2G released a report entitled: “Deep Study: The world's safest computing environment” The study focused on 235,907 break ins of computers connected permanently to the internet. The Results?
Out of 235,907 break ins: 1.BSD based systems (Including Mac OS X) % 2.Microsoft Windows % 3.Linux %
But wait a minute... ● If there are more linux machines, wouldn't you expect there be more linux break-ins? ● The report only counted targeted, manual attacks. What about automated attacks? (virii, worms, etc) ● £29.38 just to read the report? Could this just be manufactured contoversy to sell copies? ● What about all the other OS's? True UNIX variants, Solaris, etc.. Ok, this study might have been a little flawed. So what's the point?
now as far the security issue goes: Linux is Unix based.... INPENITRABLE!!! you cannot hack into that!!! From
There is no magic bullet: Every OS has vulnerabilities One conclusion MI2G drew from their investigation was that far too many administrators were installing Linux, and then not doing anything else to secure the system. Every OS has security holes. Linux, MS Windows, even my personal favorite, BSD.
There is no free lunch: You have to work at it to get security Security really is a process Keep your systems up to date and patched Don't rely on “out of the box” configurations for security