Identi.ca Identi.ca
  • Login
  • Public

    • Public
    • Groups
    • Featured
    • Popular

Conversation

Notices

  1. Aaron Toponce Aaron Toponce

    for those who think unix and linux are immune to malware, time to leave your fictional utopia: http://tinyurl.com/fah2v

    Wednesday, 01-Apr-09 04:48:47 UTC from xmpp
    • Robin Sheat Robin Sheat

      @atoponce Security is a journey. Non-windows has travelled further. Compare: http://en.wikipedia.org/wiki/List_of_computer_viruses

      Wednesday, 01-Apr-09 04:54:21 UTC
    • Mackenzie Mackenzie

      @atoponce: well we're certainly immune to *Windows* malware...and most (all?) of those were patched out years ago

      Wednesday, 01-Apr-09 04:56:01 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian windows has been down the road longer and is a larger target, but thinking 'anything non-windws is secure' just isn't true

      Wednesday, 01-Apr-09 04:56:14 UTC
    • Aaron Toponce Aaron Toponce Mackenzie

      @maco not entirely. cross-platform malware does exist

      Wednesday, 01-Apr-09 04:56:46 UTC
    • Tim Goh Tim Goh

      @atoponce very true, didn't the Morris worm propagate through BSD systems? *NIX has had more time to evolve I suppose.

      Wednesday, 01-Apr-09 04:57:16 UTC
    • Mackenzie Mackenzie

      @atoponce: Unless...are you running an unpatched copy of Debian Potato?

      Wednesday, 01-Apr-09 04:57:17 UTC
    • Mackenzie Mackenzie

      @atoponce: python with embedded assembly?

      Wednesday, 01-Apr-09 04:58:22 UTC
    • Robin Sheat Robin Sheat

      @atoponce with the inclusion of confidence intervals, you can say you won't get a Linux virus. Different from secure though anyway.

      Wednesday, 01-Apr-09 04:58:56 UTC
    • Aaron Toponce Aaron Toponce Mackenzie

      @maco http://en.wikipedia.org/wiki/List_of_Linux_computer_viruses#Cross-platform_viruses

      Wednesday, 01-Apr-09 04:59:57 UTC
    • Aaron Toponce Aaron Toponce Linux , The Unix Operating Systems , Tim Goh

      @keyist the biggest scare is privelege escalation, imo. too many ways on a !unix or !linux system to get access to root

      Wednesday, 01-Apr-09 05:02:31 UTC
    • Mackenzie Mackenzie LaTeX – A document preparation system

      @atoponce: oh yeah...I forgot about that OOo virus...meh, learn to use !LaTeX ya weenies!

      Wednesday, 01-Apr-09 05:03:10 UTC
    • Robin Sheat Robin Sheat

      @atoponce really? If you know of them, I hope you've filed them as security bugs.

      Wednesday, 01-Apr-09 05:03:32 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian 'sudo vim foo.txt> :shell' » root, copy a setuid root executable to an nfs server or usb thumb drive » root.

      Wednesday, 01-Apr-09 05:04:59 UTC
    • Robin Sheat Robin Sheat

      @atoponce no. If you have sudo, then you don't need a vuln. If you can insert a USB drive, you're not an external attacker.

      Wednesday, 01-Apr-09 05:06:46 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian if i can break a non-priv'd account that has sudo, i have root, even if they don't have 'ALL=(ALL) ALL'

      Wednesday, 01-Apr-09 05:07:48 UTC
    • Robin Sheat Robin Sheat

      @atoponce wrt NFS: ... /usr/local type nfs (rw,_nosuid_,nodev,nfsvers=2,tcp,soft,intr,...

      Wednesday, 01-Apr-09 05:07:58 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian the usb drive is external, you're right. but about nfs? 'nosuid' must be set, or you're a sitting duck

      Wednesday, 01-Apr-09 05:08:39 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian in other words, there are far too many ways to get to root, which was my point. each must be 100% locked down

      Wednesday, 01-Apr-09 05:09:25 UTC
    • Robin Sheat Robin Sheat

      @atoponce I could give you an ssh key for my machine, which I have sudo on, and you still couldn't get root without an unpatched vuln

      Wednesday, 01-Apr-09 05:10:39 UTC
    • Robin Sheat Robin Sheat

      @atoponce my point is ppl have been doing this for a while now. It's very secure. The holes mentioned aren't there unless you put them there

      Wednesday, 01-Apr-09 05:12:51 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian agreed. my point is, there's more than 'su -' to get to root, which is a subpoint of linux not being immune

      Wednesday, 01-Apr-09 05:13:56 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian nm the fact that malware can exist just fine without root. backup your /home dir recently?

      Wednesday, 01-Apr-09 05:14:40 UTC
    • Robin Sheat Robin Sheat

      @atoponce sure. and if my root password is 'root' that doesn't make linux less secure, it makes me a doofus.

      Wednesday, 01-Apr-09 05:15:22 UTC
      Andy Kruger likes this.
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian the only way linux could be immune, is if there were no bugs. but we see security patches all the time. they're fast, but exist

      Wednesday, 01-Apr-09 05:16:22 UTC
    • Robin Sheat Robin Sheat

      @atoponce it's more secure on that front too with less (hopefully no) avenues to allow it to execute in the first place.

      Wednesday, 01-Apr-09 05:16:42 UTC
    • Robin Sheat Robin Sheat

      @atoponce security is not a binary state. Never think that it is. There is no such thing as 'secure'. Only 'more' or 'less'.

      Wednesday, 01-Apr-09 05:17:49 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian bingo

      Wednesday, 01-Apr-09 05:18:15 UTC
    • Robin Sheat Robin Sheat

      @atoponce however, to allow #140 conv it's fair to say 'linux is secure'. This doesn't mean it's perfect, just that it's in a conf. interval

      Wednesday, 01-Apr-09 05:20:38 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian i'll accept 'linux is more secure than windows' or 'linux isn't a major target'. if the tables were switched...

      Wednesday, 01-Apr-09 05:22:31 UTC
    • Robin Sheat Robin Sheat

      @atoponce it's also acceptable to say 'you won't get a virus on linux'. I'll also say 'you won't get hit by a comet'.

      Wednesday, 01-Apr-09 05:24:10 UTC
    • Aaron Toponce Aaron Toponce Robin Sheat

      @eythian so this should make you nervous then: http://tinyurl.com/75ul9. bit too close for me

      Wednesday, 01-Apr-09 05:25:56 UTC
    • Robin Sheat Robin Sheat

      @atoponce not at all. A) it's not a comet B) it won't hit, C) if it does, nothing I can do about it anyway ;)

      Wednesday, 01-Apr-09 05:28:25 UTC
    • Morten Juhl-Johansen Zölde-Fejér Morten Juhl-Johansen Zölde-Fejér LaTeX – A document preparation system

      I like the concept of !LaTeX, but I sometimes find the markup distracting for the overview of the text. How do you do it?

      Wednesday, 01-Apr-09 07:12:34 UTC
    • Ian Witham Ian Witham Morten Juhl-Johansen Zölde-Fejér

      @mjjzf I use #Kile for writing LaTeX code; the syntax highlighting helps me grok the document.

      Wednesday, 01-Apr-09 07:15:54 UTC
    • unhammer unhammer LaTeX – A document preparation system , Morten Juhl-Johansen Zölde-Fejér

      @mjjzf I mainly use !org-mode and export to !latex . Then there's outline modes, overlays...

      Wednesday, 01-Apr-09 07:26:22 UTC

Site notice

  • API
  • Status

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Identi.ca is a microblogging service brought to you by Status.net. It runs the StatusNet microblogging software, version 1.1.0-alpha1, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Identi.ca content and data are available under the Creative Commons Attribution 3.0 license.

Switch to mobile site layout.

Built in Montreal