Re: controversial paper

From: Ernst Lippe (ernstl-at-planet-dot-nl_at_ignore.this)
Date: 09/27/03


Date: Sat, 27 Sep 2003 01:30:56 +0200

On Fri, 26 Sep 2003 22:41:36 +0000, Tom St Denis wrote:

>
> "Ben Mord" <benmord@earthlink.net> wrote in message
> news:bl2evg$7gkfi$1@ID-101018.news.uni-berlin.de...
>> Interesting.
>>
>> This seems to be a controversial paper:
>> http://www.ccianet.org/papers/cyberinsecurity.pdf
>>
>> Published here:
>> http://www.ccianet.org/index.php3

> The net sum of the paper is "windows bad because it has flaws".

No. The main thesis of the paper is that a monoculture is bad for
security, because the majority of the systems will share the same
vulnerabilities.

Given the fact that all computer systems have some vulnerabilities,
the validity of that thesis does not depend on the security of the
dominant computer system.

greetings,

Ernst Lippe



Relevant Pages

  • Re: [fw-wiz] concerning ~el8 / project mayhem
    ... On Mon, 19 Aug 2002, Paul Robertson wrote: ... This has become a major credibility issue for the security industry. ... the vast majority of these individuals, ... vulnerabilities aren't ever exploited, and those that are are not visible ...
    (Firewall-Wizards)
  • Re: controversial paper
    ... because the majority of the systems will share the same ... Given the fact that all computer systems have some vulnerabilities, ... the validity of that thesis does not depend on the security of the ...
    (sci.crypt)
  • [Full-Disclosure] Disclosure Debate FW: [ISN] When to Shed Light
    ... Information security, in particular, cannot exist. ... full disclosure results in FEWER hands at work in this process, ... Microsoft because of how dependent publishers are on access to beta software ... > I think actively seeking vulnerabilities is just plain destructive. ...
    (Full-Disclosure)
  • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
    ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
    (microsoft.public.security)
  • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
    ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
    (microsoft.public.inetserver.iis.security)