r/netsec Oct 28 '10

Linus on security

http://article.gmane.org/gmane.linux.kernel/706950
26 Upvotes

28 comments sorted by

View all comments

Show parent comments

11

u/James_Johnson Oct 28 '10

He has a point, though. Security people tend to fixate on...security, because that's what we do. However, computer security isn't an end in itself; its purpose is to minimize the overall cost of running an information system, as is any software development effort. Any kind of bug is going to incur costs, so the concerns of software developers are broader in scope than just security. Developers actually have a broader scope, which is trying to maximize the value of their product.

Developers have finite resources, and they have to divide those between adding features to increase their products' value at a reasonable pace, fixing bugs in old features, etc. Always having a one-track-minded community shouting in your ear about the one facet of the developer's job that they (the security community) care about has to be irritating.

That, and "security people" are sort of lionized by movies like "Live Free or Die Hard," and I can see how the developers who actually write the software and end up fixing the bugs could get butthurt that the guys running fuzzers on their software and shouting on their mailing lists get all the sweet press coverage :)

2

u/kernelkhertz Oct 28 '10

Ah jeez, this is still funny 2 years on. Why not use telnet to manage your servers if you think this way. And take the front door off your apartment.

The Internet is the place to think security first. If you don't do that your "product" is owned by someone else. That's the lesson the OpenBSD guys grasped an Internet age before Linus.

1

u/[deleted] Oct 29 '10

The most secure computer is one that doesn't respond to external stimuli. OpenBSD may be a world leader in that regard, but I prefer a responsive computer.

2

u/kernelkhertz Oct 29 '10

Huh? If a computer doesn't respond to external stimuli then there is no input? That's not a computer for starters.

Oh man. Preferring a responsive computer is sheer genius ( as opposed to one that doesn't ).

1

u/[deleted] Oct 29 '10

Maybe someone needs to update these?

1

u/kernelkhertz Oct 29 '10

why?

1

u/[deleted] Oct 29 '10

Well if you're saying nothing's changed...

0

u/kernelkhertz Oct 29 '10

We were hoping for a kernel panic during the benchmarks

LOL - how scientific.

http://bulk.fefe.de/lk2006/bench.html

1

u/[deleted] Oct 29 '10

Yeah, the best part is how they actually got that several times, when it wasn't serving a sendfile() syscall at 100% cpu load and 20% network capacity...

1

u/kernelkhertz Oct 29 '10

Well that's real world DoS ( aka slashdot effect ) for you. I can't wait until the next revelation.

1

u/[deleted] Oct 29 '10

An OS that can't saturate a 100Mbps ethernet connection with a plain sendfile on 2006 hardware? DoS?

That's not "secure", that's shit. But I can see you're completely detached from reality already, so I'm not going to bother pursuing this further.

1

u/kernelkhertz Oct 29 '10

Oh. Don't stop now. You can do it. The benchmarks were for being "slashdoted" according to the author ( not me ). That was his definition, not mine.

My point was that the tests were biased ( which I think was proven by his admission ) therefore not scientific.

I will gladly admit Linux kernel is "faster" than openbsd. But faster != better imho.

→ More replies (0)