Re: linux box compromised: advice needed

From: Tim Haynes (usenet@stirfried.vegetable.org.uk)
Date: 03/27/02

  • Next message: Tim Tassonis: "Re: ssh 1.2.1 Root compromise"

    From: Tim Haynes <usenet@stirfried.vegetable.org.uk>
    Date: Wed, 27 Mar 2002 09:30:47 +0000
    
    

    Marcus Lauer <reply@via.newsgroup.com> writes:

    > Tim Haynes wrote:
    >
    >> Saying `qmail is more secure', in the absence of demonstrable recovery-
    >> from-compromise time stats, is FUD. Saying that people should run from
    >> something they've chosen to use to qmail, even because of a compromise,
    >> is mis-applying said FUD.
    >
    > "Recovery-from-compromise" stats? That sounds pretty useless.
    > What you want is for exploits to be found rarely (preferrably never) so
    > that compromises never occur. Data on number of root exploits, or average
    > time between discovery of root exploits, would be more useful.

    No it's not. FFS, past performance is no indicator of future. Simple
    "number of root exploits" is what anti-sendmail pillocks use, and a big
    stinkin' 0 from qmail does NOT prove it's any more secure.

    Ultimately I don't care if my MTA has up to ~5 or so separate security
    incidents in a year as long as they're all fixed in a reasonable -quick-
    turnaround time, because I'd *far* rather have a fixed bug, know about it,
    and be done, than be told "it's more secure" with NO REAL DATA.

    ~Tim

    -- 
    Sometimes you're the pigeon,                |piglet@stirfried.vegetable.org.uk
    Sometimes you're the statue.                |http://spodzone.org.uk/
    



    Relevant Pages

    • Re: linux box compromised: advice needed
      ... > I didn't say that sendmail was the problem but it has had several known ... Saying `qmail is more secure', in the absence of demonstrable recovery- ... from-compromise time stats, is FUD. ...
      (comp.os.linux.security)
    • Re: qmail starttls patch does not seed the random number generator
      ... qmail starttls patch does not seed the random number generator ... > The way you fixed the problem is not secure. ... If you're depending on the fact that your mail server is TLS encrypting ...
      (Bugtraq)
    • Re: A router question from a newbie
      ... Roger Mills wrote: ... this is essentially the same as saying that you have every right to ... anyone who does not secure their wireless connection deserves to be ...
      (uk.telecom.broadband)
    • Re: locals comment on stolen guns at Joes Gun Shop
      ... you saying it was some kind of insurance scam? ... Are you saying it wasn't? ... I know one thing about his financial situation: He can't afford to secure ... laws that punish victims rather than criminals. ...
      (talk.politics.guns)
    • Re: Thou shalt have no other gods before the ANSI C standard
      ... >by some famous targeted attack? ... qmail was architected in a thoughtful ... code that is critical to ensuring the security properties hold). ... That's far short of a proof that it is secure, ...
      (sci.crypt)