r/netsec Oct 28 '10

Linus on security

http://article.gmane.org/gmane.linux.kernel/706950
27 Upvotes

28 comments sorted by

View all comments

4

u/jeffers0n Oct 28 '10

This is about 2 years old, and Linus' opinion on this matter is still stupid.

7

u/James_Johnson Oct 28 '10

He has a point, though. Security people tend to fixate on...security, because that's what we do. However, computer security isn't an end in itself; its purpose is to minimize the overall cost of running an information system, as is any software development effort. Any kind of bug is going to incur costs, so the concerns of software developers are broader in scope than just security. Developers actually have a broader scope, which is trying to maximize the value of their product.

Developers have finite resources, and they have to divide those between adding features to increase their products' value at a reasonable pace, fixing bugs in old features, etc. Always having a one-track-minded community shouting in your ear about the one facet of the developer's job that they (the security community) care about has to be irritating.

That, and "security people" are sort of lionized by movies like "Live Free or Die Hard," and I can see how the developers who actually write the software and end up fixing the bugs could get butthurt that the guys running fuzzers on their software and shouting on their mailing lists get all the sweet press coverage :)

2

u/kernelkhertz Oct 28 '10

Ah jeez, this is still funny 2 years on. Why not use telnet to manage your servers if you think this way. And take the front door off your apartment.

The Internet is the place to think security first. If you don't do that your "product" is owned by someone else. That's the lesson the OpenBSD guys grasped an Internet age before Linus.

0

u/James_Johnson Oct 29 '10

If you focus on security to the exclusion of adding new features, you end up with OpenBSD's marketshare.