Re: Qns on linux security frm windows users :::Help !!!



Arvin wrote:
I've been using linux for a long time and have been trying to *popularize*
it. But can anyone help me with some qns which windows users asked me...???

1. Since the source is open, cant people introduce trojans and spywares in
the main source code itself, taking away our personal info ? (i'm not saying
windows doesnt have such codes)

The source is open in the sense that anybody can read it. But any specific
distribution package of the code has to be made by somebody, and that
person or group serves as gatekeeper, deciding what changes will be
incorporated and what will not. For the kernel, Linus Torvalds had that
function by himself for a number of years; now it is essentially done by
a small group. But if a distribution--the actual packages people install--
acquires a reputation for instability, it will disappear quickly.

So the short answer is that "open source" doesn't mean anybody gets to
change the software that everybody else uses. It means lots of people
are able to review and discuss openly what does change.

2. Is ther any other feature which protects itself frm viruses other than
the denial of the execution permission ? (not talking about 3rd party
antiviruses)

I don't think Linux has special antivirus capabilities, but the
general UNIX model of not running with more privileges than necessary,
which are very slowly becoming the norm in Windows systems, have
helped Linux a lot. Still, if you run a Linux desktop system as root,
you're asking for trouble. But most Linux users simply don't.

Much of the early vulnerabilities of both UNIX and Windows came from
applications trusting each others' data too much. Both systems have
changed a lot since the early 1990s, and the biggest changes have been
in checking carefully the data that are exchanged.

3. Since the *making* of the linux apps involves the open source community
as a whole, how can they follow a good well defined process to generate a
*good* code ? which can lead to security holes and other problems ?

<opinion>
Widespread code review and actual use is better than any methodological system.
Cheaper, too. Moreover, there's nothing to prevent Linux developers from
using a systematic process to develop code.
</opinion>

Peter
--
Peter N. Schweitzer (MS 954, U.S. Geological Survey, Reston, VA 20192)
(703) 648-6533 FAX: (703) 648-6252 email: pschweitzer@xxxxxxxx
<http://geology.usgs.gov/peter/>
.



Relevant Pages

  • Re: Future of IT in Lebanon
    ... working knowledge of Indian programmers DNA, nor of their intuitive Java ... > So Longhorn is not an experiment and Linux is an experiment? ... another chapter in the Windows story, and the Microsoft marketing machine is ... > application opens, Check the about, it says Microsoft Visual Basic 6.3. ...
    (soc.culture.lebanon)
  • FTP DOWNLOAD! More than 6500 CRACKED SOFTWARE(CAD,CAE,CAM,ED
    ... Autodesk Architectural Desktop 2005 ... DASSAULT SYSTEMES CAA ENOVIA LCA V5R13 ... ALTAIR.OPTISTRUCT V5.1 for LINUX ... ANSYS V8.0 FOR WINDOWS ...
    (microsoft.public.dotnet.framework.adonet)
  • Linux for Senior Citizens
    ... Linux for Senior Citizens ... For such people, I believe, Windows really is a better option: ... The kernel manages all the hardware and also looks after all running ...
    (uk.people.silversurfers)
  • Re: Future of IT in Lebanon
    ... It's the same Linux code base. ... Microsoft Office on a Windows server, it will install and run fine, the main ...
    (soc.culture.lebanon)
  • Re: ethernet
    ... This is all flotsam and jetsam from the Windows world. ... majority of Windows users I work with ... that they will never look at Linux as long as it has that restriction. ... security or how to maintain an OS ...
    (alt.os.linux.suse)

Quantcast