Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] For all you vi heathen ;-)
- Date: Mon, 20 Jul 2020 00:28:36 +0900
- From: Benjamin Kowarsch <trijezdci@example.com>
- Subject: Re: [tlug] For all you vi heathen ;-)
- References: <20200716231225.GD62955@nuskie.local> <CADR0rneFcGb+RFSsPTpr78iK+R-b70mGzMY8ZhKMHc78zov_Hw@mail.gmail.com> <20200717145503.jm5h5bdbed2luxmu@iambic.cynic.net> <CADR0rncwO=vtnN+YTuM9r1yLkDQoa7JZ7UBqk7PqdASQM2NzeA@mail.gmail.com> <20200719130515.mozmc5cbb3aiwgmq@iambic.cynic.net>
On Sun, 19 Jul 2020 at 22:12, Curt J. Sampson <cjs@example.com> wrote:On 2020-07-18 00:39 +0900 (Sat), Benjamin Kowarsch wrote:
> Running VMS is about the smartest approach to security on this planet.
These kinds of statements are exactly why so many people set up such
terribly insecure systems. A product does not give you good security. Ever.Absolutely not. Besides, other than outfits like the NSA, large bankingand insurance corporations for their most sensitive stuff, who isstill running VMS systems? And those who do, they do so becausethey know that VMS is the best there is when it comes to security,not because they read somebody on the internet say something.> Well, on VMS a "restricted shell" is called a captive account
> and it actually performs to specification, not best effort.
Hard as it is to get things to perform to specification, it's even harder
to ensure that the specification itself is correct.
> ...being handed out to anybody who would email in and ask for one. Nobody
> has ever managed to break out.
Oh dear. "I don't know of of any failures" == "There have been no failures."I didn't say that. The point is this, unlike the vast and overwhelming majority ofNix and Nix like systems out there, VMS has been designed with securityin mind from the start and this focus has been maintained ever since.DEC used to bring their boxes to these hacker contests where you could winprice money for breaking into some system since the manufacturersthen got the info how their system was hacked and were able to fixvulnerabilities.IIRC there was one single incident where someone managed to break intoa VMS system. DEC had to constantly raise the price money wellabove what any other vendor was offering to even find any takers, thehackers preferred to invest their efforts into hacking some other systembecause they knew that way they had a good chance to go home withsome actual cash in their pockets.That doesn't mean there are no vulnerabilities, but it illustrates the point,that a system designed from the start with security in mind will run ringsaround all those where security was a mere afterthought, bolted on later.> There is a difference between system design with security designed in
> from the start, and system "design" with "security" bolted on afterwards.
Certainly! If you know this, I find it surprising you recommend OpenBSD to
people wanting to be more secure.I mentioned OpenBSD for two simple reasons:* courtesy, this is a form of open source people after all* I got the impression that the OpenBSD project prioritises security.Now, I will grant you that prioritising security is not anywhere near as goodas designed with security in mind from the start, but priority on securityis still better than not prioritising security.There seem to be too many script kiddies out there in the world of systemsoftware implementation and packaging who want stuff simply because it is"cool" without much concern what the implications are. That certainly doesnot count as priority on security. I'd rather trust a regime by which certainstuff is excluded until it has been shown to meet the regime's securitypolicy. That appears to be the regime under which OpenBSD is operating.It most certainly is not the regime under which Linux, Windows, andMacOS are being developed/maintained. In their realms features trumpsecurity and reliability ***more often than not***.
- Follow-Ups:
- Re: [tlug] For all you vi heathen ;-)
- From: Curt J. Sampson
- Re: [tlug] For all you vi heathen ;-)
- From: Chris
- Re: [tlug] For all you vi heathen ;-)
- From: Stephen J. Turnbull
- References:
- Re: [tlug] For all you vi heathen ;-)
- From: Chris
- Re: [tlug] For all you vi heathen ;-)
- From: Benjamin Kowarsch
- Re: [tlug] For all you vi heathen ;-)
- From: Curt J. Sampson
- Re: [tlug] For all you vi heathen ;-)
- From: Benjamin Kowarsch
- Re: [tlug] For all you vi heathen ;-)
- From: Curt J. Sampson
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] For all you vi heathen ;-)
- Next by Date: Re: [tlug] For all you vi heathen ;-)
- Previous by thread: Re: [tlug] For all you vi heathen ;-)
- Next by thread: Re: [tlug] For all you vi heathen ;-)
- Index(es):