Linux Hardware

Hey drop us a line about the show. Feel free to ask questions, provide feedback and criticism, or just ramble on about anything your little heart desires.

Moderators: snarkout, Patrick, dann

User avatar
CptnObvious999
Posts: 798
Joined: Fri Jun 03, 2005 7:54 pm
Location: Maryland
Contact:

Post by CptnObvious999 » Sun Feb 05, 2006 5:49 pm

Jza wrote:
CptnObvious999 wrote:Yes running as root is a huge security risk. If someone exploits firefox your home directory gets destroyed, but if you run it as root your whole system gets destroyed, including the home directories of any other users. Plus if you run as root a rootkit could be installed doing anything it wants. Remember the less the priviledges the better.
And how many people u know that happened to their system? Or rather how many linspire people got their machine explode by a rootkit.

Because thats the important question, not how much probabilty there is but how many casualties have been out there.
That is *NOT* the way you should look at security. Always expect the worst. Most security steps are precautions. How many home users get hacked? Does that mean they don't need a firewall?

User avatar
Jza
Posts: 466
Joined: Sun Oct 30, 2005 7:01 pm
Location: Mexico
Contact:

Post by Jza » Sun Feb 05, 2006 6:20 pm

Well is what you will look if u had to pay for a firewall that was expensive. Your first question will be has anyone been hacked, the second was it related to a lack of firewall, and the last what are the chances of me getting that.

Linspire has a firewall integrated which is the same level as Windows XP SP2. Now the question will be, how many users get hacked using Windows XP SP2. Now this is hacked and is not virus related (or worm).

If you can come up with a figure I will be it will be extremely low. Now if u filter that list because it was OS-centric you end up with an even lower level.

Another way to look at it is going to the Linspire forum and see how many users have complained of their machines being hacked.
Alexandro COLORADO

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Sun Feb 05, 2006 7:56 pm

Jza if you believe in "security by obscurity", like Microsoft does, go ahead and think that way, but that's not the way I look at security.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Post by snarkout » Sun Feb 05, 2006 10:16 pm

The current linux security model doesn't work well for desktop usage though. I'm not advocating making your user root or a member of the root group, but something should be done. Sudo is a step in the right direction I think, but there are still some major problems. One major one is that it's far too easy to create root owned files/directories in a user's home directory. Second is that most users don't give a good goddamn about their OS if their personal data has all been destroyed. Everything most people care about at all lives in their home directory.

I'm currenly helping a friend at work get ubuntu up and running on one of his boxen (I gave him a ship-it disk a while ago, and he installed it eventually). He is an experienced windows user, power user if you will, and he's having a hell of a hard time making the transition to the linux way. It may actually be harder for people who "know WTF a computer should do" to learn a new way, I don't know, but IMO, if my friend is having this much trouble, the current system is broken.
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

User avatar
Jza
Posts: 466
Joined: Sun Oct 30, 2005 7:01 pm
Location: Mexico
Contact:

Post by Jza » Sun Feb 05, 2006 10:31 pm

Tsuroerusu wrote:Jza if you believe in "security by obscurity", like Microsoft does, go ahead and think that way, but that's not the way I look at security.
Security by obscurity is a very different thing, is when you fake security by hidding the holes. Server security root and users make sense because there are foreign systems accesing yours and modifiying information with it. But on a desktop enviroment the access is very restricted, if on top you already have a firewall implemented, the only real harm can come from you and only you.

Firewall is build to block external systems to interact with yours. So running as root makes your system vulnerable to you.

So protecting your system against you, is a very different view versus defending the system vs external systems.
Alexandro COLORADO

User avatar
Jza
Posts: 466
Joined: Sun Oct 30, 2005 7:01 pm
Location: Mexico
Contact:

Post by Jza » Sun Feb 05, 2006 10:36 pm

Snarkout wrote:I'm currenly helping a friend at work get ubuntu up and running on one of his boxen (I gave him a ship-it disk a while ago, and he installed it eventually). He is an experienced windows user, power user if you will, and he's having a hell of a hard time making the transition to the linux way. It may actually be harder for people who "know WTF a computer should do" to learn a new way, I don't know, but IMO, if my friend is having this much trouble, the current system is broken.
That is not surprise, we at OpenOffice.org see simple users be more confortable migrating to OpenOffice.org versus M$ power users.

I think your friend is having a hard time because he is not prepared to learn computers again. He wants to transfer and force his knowledge in winbugs to Linux.

example: simple users, want the computer for 1 thing and 1 thing only, then it discover he can do 2,3,....n things. The more things he find out how to do the more he becomes a 'power user'.

So power users that want to move to linux find that they have a LEGACY knowledge that want to trasfer to a new OS and that is way harder than just 1.
Alexandro COLORADO

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Mon Feb 06, 2006 1:56 am

Jza wrote:Security by obscurity is a very different thing, is when you fake security by hidding the holes. Server security root and users make sense because there are foreign systems accesing yours and modifiying information with it. But on a desktop enviroment the access is very restricted, if on top you already have a firewall implemented, the only real harm can come from you and only you.

Firewall is build to block external systems to interact with yours. So running as root makes your system vulnerable to you.

So protecting your system against you, is a very different view versus defending the system vs external systems.
You and I clearly have a very different sense of security, I think you fail to realize that if Linux became more popular the spyware guys would start to attack us, and that could be done with exploits in Firefox, and if people ran as root, one zap and you're dead, because a lot of spyware is starting to use rootkits, and rootkits are like "at home" on UNIX or UNIX-like platforms, I'm not talking about someone cracking into your system, nor a worm or a virus, but if a website can exploit a buffer overflow vulnerability in Firefox, it doesn't matter if or if not you have a firewall in place, you can go out and buy enterprise-class security equipment, but it won't help you since it was you who went out on the internet and downloaded the spyware.
I think the security model of the current UNIXes are fine for a desktop operating system, you just label the root account the administrator account and then a "user" account, make the user write these two down on a piece of paper and then he's fine whenever he needs root access, it's not a big deal, my aunt can deal with it, so can anyone else. I personally hate the sudo thing, but that's just my opinion.

How many user friendly distributions have you looked at recently? If not that many because you hate GUIs like all the old-school Slackware users, no offense to those of you that do believe dumb users need a GUI, I think you need a major "update", because there are distributions out there that do just as good a job, and in pretty much all cases, a better job, of helping users deal with the two accounts thing than Linspire does.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

thetza
Posts: 146
Joined: Tue Jan 10, 2006 7:25 pm

Post by thetza » Mon Feb 06, 2006 11:35 pm

Jza wrote:And how many people u know that happened to their system? Or rather how many linspire people got their machine explode by a rootkit.

Because thats the important question, not how much probabilty there is but how many casualties have been out there.
currently, running as root on linux is dangerous more because there's no protection against stupid user error.

User avatar
Jza
Posts: 466
Joined: Sun Oct 30, 2005 7:01 pm
Location: Mexico
Contact:

Post by Jza » Tue Feb 07, 2006 12:50 am

How many times have you test that?

I really need to see more than a theory as probable as your theory sounds, there is no proof for which there is not really a ground base that a root account will cause a masive explotion of the system.
Alexandro COLORADO

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Tue Feb 07, 2006 8:46 am

Jza wrote:there is no proof for which there is not really a ground base that a root account will cause a masive explotion of the system.
Oh really? Go look at Windows and you'll see!!

Yes, Windows has more holes than FreeBSD and GNU/Linux, but if you don't run as root, most of the exploits don't effect the operating system.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
Gomer_X
Posts: 901
Joined: Fri Jun 03, 2005 1:31 pm
Location: Cincinnati, Ohio, USA
Contact:

Post by Gomer_X » Tue Feb 07, 2006 12:23 pm

Jza wrote:How many times have you test that?

I really need to see more than a theory as probable as your theory sounds, there is no proof for which there is not really a ground base that a root account will cause a masive explotion of the system.
I've tested it. I've run Windows for years and I've never had a virus or any kind of malware. I've always run my Windows system on an account with no password and full administrator access.

Why hasn't my system been cracked? Vigilant security on my part, luck, and an understanding of where the bad stuff comes from.

There is NO universal security model that works for everybody. Security is about understanding the odds and taking acceptable risks. For a Linspire user, running as root may be the difference between using a computer and not using a computer. It's not what I'd consider secure, but it's a much better risk than running Windows.

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Post by snarkout » Tue Feb 07, 2006 12:35 pm

Gomer_X wrote:
Jza wrote:How many times have you test that?

I really need to see more than a theory as probable as your theory sounds, there is no proof for which there is not really a ground base that a root account will cause a masive explotion of the system.
I've tested it. I've run Windows for years and I've never had a virus or any kind of malware. I've always run my Windows system on an account with no password and full administrator access.

Why hasn't my system been cracked? Vigilant security on my part, luck, and an understanding of where the bad stuff comes from.

There is NO universal security model that works for everybody. Security is about understanding the odds and taking acceptable risks. For a Linspire user, running as root may be the difference between using a computer and not using a computer. It's not what I'd consider secure, but it's a much better risk than running Windows.
I couldn't have said it better myself. Bravo!
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

Post Reply