That is *NOT* the way you should look at security. Always expect the worst. Most security steps are precautions. How many home users get hacked? Does that mean they don't need a firewall?Jza wrote:And how many people u know that happened to their system? Or rather how many linspire people got their machine explode by a rootkit.CptnObvious999 wrote:Yes running as root is a huge security risk. If someone exploits firefox your home directory gets destroyed, but if you run it as root your whole system gets destroyed, including the home directories of any other users. Plus if you run as root a rootkit could be installed doing anything it wants. Remember the less the priviledges the better.
Because thats the important question, not how much probabilty there is but how many casualties have been out there.
Linux Hardware
Moderators: snarkout, Patrick, dann
- CptnObvious999
- Posts: 798
- Joined: Fri Jun 03, 2005 7:54 pm
- Location: Maryland
- Contact:
Well is what you will look if u had to pay for a firewall that was expensive. Your first question will be has anyone been hacked, the second was it related to a lack of firewall, and the last what are the chances of me getting that.
Linspire has a firewall integrated which is the same level as Windows XP SP2. Now the question will be, how many users get hacked using Windows XP SP2. Now this is hacked and is not virus related (or worm).
If you can come up with a figure I will be it will be extremely low. Now if u filter that list because it was OS-centric you end up with an even lower level.
Another way to look at it is going to the Linspire forum and see how many users have complained of their machines being hacked.
Linspire has a firewall integrated which is the same level as Windows XP SP2. Now the question will be, how many users get hacked using Windows XP SP2. Now this is hacked and is not virus related (or worm).
If you can come up with a figure I will be it will be extremely low. Now if u filter that list because it was OS-centric you end up with an even lower level.
Another way to look at it is going to the Linspire forum and see how many users have complained of their machines being hacked.
Alexandro COLORADO
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
The current linux security model doesn't work well for desktop usage though. I'm not advocating making your user root or a member of the root group, but something should be done. Sudo is a step in the right direction I think, but there are still some major problems. One major one is that it's far too easy to create root owned files/directories in a user's home directory. Second is that most users don't give a good goddamn about their OS if their personal data has all been destroyed. Everything most people care about at all lives in their home directory.
I'm currenly helping a friend at work get ubuntu up and running on one of his boxen (I gave him a ship-it disk a while ago, and he installed it eventually). He is an experienced windows user, power user if you will, and he's having a hell of a hard time making the transition to the linux way. It may actually be harder for people who "know WTF a computer should do" to learn a new way, I don't know, but IMO, if my friend is having this much trouble, the current system is broken.
I'm currenly helping a friend at work get ubuntu up and running on one of his boxen (I gave him a ship-it disk a while ago, and he installed it eventually). He is an experienced windows user, power user if you will, and he's having a hell of a hard time making the transition to the linux way. It may actually be harder for people who "know WTF a computer should do" to learn a new way, I don't know, but IMO, if my friend is having this much trouble, the current system is broken.
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson
--Spider Robinson
Security by obscurity is a very different thing, is when you fake security by hidding the holes. Server security root and users make sense because there are foreign systems accesing yours and modifiying information with it. But on a desktop enviroment the access is very restricted, if on top you already have a firewall implemented, the only real harm can come from you and only you.Tsuroerusu wrote:Jza if you believe in "security by obscurity", like Microsoft does, go ahead and think that way, but that's not the way I look at security.
Firewall is build to block external systems to interact with yours. So running as root makes your system vulnerable to you.
So protecting your system against you, is a very different view versus defending the system vs external systems.
Alexandro COLORADO
That is not surprise, we at OpenOffice.org see simple users be more confortable migrating to OpenOffice.org versus M$ power users.Snarkout wrote:I'm currenly helping a friend at work get ubuntu up and running on one of his boxen (I gave him a ship-it disk a while ago, and he installed it eventually). He is an experienced windows user, power user if you will, and he's having a hell of a hard time making the transition to the linux way. It may actually be harder for people who "know WTF a computer should do" to learn a new way, I don't know, but IMO, if my friend is having this much trouble, the current system is broken.
I think your friend is having a hard time because he is not prepared to learn computers again. He wants to transfer and force his knowledge in winbugs to Linux.
example: simple users, want the computer for 1 thing and 1 thing only, then it discover he can do 2,3,....n things. The more things he find out how to do the more he becomes a 'power user'.
So power users that want to move to linux find that they have a LEGACY knowledge that want to trasfer to a new OS and that is way harder than just 1.
Alexandro COLORADO
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
You and I clearly have a very different sense of security, I think you fail to realize that if Linux became more popular the spyware guys would start to attack us, and that could be done with exploits in Firefox, and if people ran as root, one zap and you're dead, because a lot of spyware is starting to use rootkits, and rootkits are like "at home" on UNIX or UNIX-like platforms, I'm not talking about someone cracking into your system, nor a worm or a virus, but if a website can exploit a buffer overflow vulnerability in Firefox, it doesn't matter if or if not you have a firewall in place, you can go out and buy enterprise-class security equipment, but it won't help you since it was you who went out on the internet and downloaded the spyware.Jza wrote:Security by obscurity is a very different thing, is when you fake security by hidding the holes. Server security root and users make sense because there are foreign systems accesing yours and modifiying information with it. But on a desktop enviroment the access is very restricted, if on top you already have a firewall implemented, the only real harm can come from you and only you.
Firewall is build to block external systems to interact with yours. So running as root makes your system vulnerable to you.
So protecting your system against you, is a very different view versus defending the system vs external systems.
I think the security model of the current UNIXes are fine for a desktop operating system, you just label the root account the administrator account and then a "user" account, make the user write these two down on a piece of paper and then he's fine whenever he needs root access, it's not a big deal, my aunt can deal with it, so can anyone else. I personally hate the sudo thing, but that's just my opinion.
How many user friendly distributions have you looked at recently? If not that many because you hate GUIs like all the old-school Slackware users, no offense to those of you that do believe dumb users need a GUI, I think you need a major "update", because there are distributions out there that do just as good a job, and in pretty much all cases, a better job, of helping users deal with the two accounts thing than Linspire does.


"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.
currently, running as root on linux is dangerous more because there's no protection against stupid user error.Jza wrote:And how many people u know that happened to their system? Or rather how many linspire people got their machine explode by a rootkit.
Because thats the important question, not how much probabilty there is but how many casualties have been out there.
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
Oh really? Go look at Windows and you'll see!!Jza wrote:there is no proof for which there is not really a ground base that a root account will cause a masive explotion of the system.
Yes, Windows has more holes than FreeBSD and GNU/Linux, but if you don't run as root, most of the exploits don't effect the operating system.


"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.
I've tested it. I've run Windows for years and I've never had a virus or any kind of malware. I've always run my Windows system on an account with no password and full administrator access.Jza wrote:How many times have you test that?
I really need to see more than a theory as probable as your theory sounds, there is no proof for which there is not really a ground base that a root account will cause a masive explotion of the system.
Why hasn't my system been cracked? Vigilant security on my part, luck, and an understanding of where the bad stuff comes from.
There is NO universal security model that works for everybody. Security is about understanding the odds and taking acceptable risks. For a Linspire user, running as root may be the difference between using a computer and not using a computer. It's not what I'd consider secure, but it's a much better risk than running Windows.
I couldn't have said it better myself. Bravo!Gomer_X wrote:I've tested it. I've run Windows for years and I've never had a virus or any kind of malware. I've always run my Windows system on an account with no password and full administrator access.Jza wrote:How many times have you test that?
I really need to see more than a theory as probable as your theory sounds, there is no proof for which there is not really a ground base that a root account will cause a masive explotion of the system.
Why hasn't my system been cracked? Vigilant security on my part, luck, and an understanding of where the bad stuff comes from.
There is NO universal security model that works for everybody. Security is about understanding the odds and taking acceptable risks. For a Linspire user, running as root may be the difference between using a computer and not using a computer. It's not what I'd consider secure, but it's a much better risk than running Windows.
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson
--Spider Robinson