The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Linux Rated Less Secure than Windows
Time: 00:00 EST/05:00 GMT | News Source: WinInformant | Posted By: Todd Richardson

Thanks RMD. When Microsoft announced that its Windows 2000 operating system had been awarded the highest possible grade in the Common Criteria (CC) security certification last fall, open source advocates downplayed the honor as insignificant and unrelated to real-world security analysis. This week, however, Linux was also awarded with CC security certification, and as one might expect, this announcement greeted with cheers from the open source community. There's just one catch: Linux got a lower security rating than Windows 2000 did last year.

Linux was certified as providing "low to moderate" security, while Windows 2000 received a "moderate to high" security rating last year. According to people close to the certification, Linux was being tested for better security ratings, but only achieved the "low to moderate" rating.

Write Comment
Return to News

  Displaying 1 through 25 of 156
Last | Next
  The time now is 9:50:23 PM ET.
Any comment problems? E-mail us
#1 By 10896 (24.25.182.11) at 8/6/2003 7:08:58 AM
This was even a special version of SUSE Linux on IBM hardware.
It was trying to get the higher rating and failed so only the low to moderate was achieved.
Any company with security in mind should be very careful in deploying other versions of Linux.
If you dont have the high rating like Windows 2000, you cant compete for many contracts that require CC certification.

#2 By 6859 (206.156.242.36) at 8/6/2003 9:04:58 AM
SomeDork has a valid question. I, too, would like to know how 2003 did, if they even tested it yet...

#3 By 20 (67.9.179.51) at 8/6/2003 10:42:53 AM
The process is arduous and I'm sure it takes at least 1-2 years. There are reams of documentation necessary and probably even some code audits for critical security processes.

I don't know how Linux even got low to moderate because it doesn't even have DAC (Discretionary Access Control -- basically full access control lists (with deny capability) to sensitive resources like files and network resources)).

DAC is generally considered a basic requirement for any serious security implementation. Most commercial Unixes have it now and have gone away from the kindergarten User/Group/Everyone model that Unix used to use and Linux still uses.

There are ACL implementations for Linux but they're unstable and don't provide full DAC across the OS, just ACLs for files.

#4 By 20 (67.9.179.51) at 8/6/2003 11:51:35 AM
I don't think it's something you decide to add one day. DAC is a mindset and a design choice and Linux was not designed with that in mind. It's a major effort to overhaul the entire security infrastructure of the OS and it took most Unix vendors several years to get it to the point where they could get certified.

Linux is lost in this regard and it'll take a monumental effort by some large corporate entity to bring it up to the level of HP-UX and longer for Windows 2003

#5 By 16451 (63.227.226.13) at 8/6/2003 2:43:08 PM
PAM

#6 By 20 (67.9.179.51) at 8/6/2003 7:19:39 PM
#12: So far Red Hat has released 46 vulnerabilities for it's Linux 9.0 product this year.

Windows 2003 has had one vulnerability so far (well, ok, 3 if you count the IE vulnerabilities that don't affect Win2K3 by default, you have to TRY to get the vulnerability)

How many times have you tried to connect to a Windows ahred folder and had it forget to ask for a password?

Never. Either passwords are required or not. It never "forgets" to ask you.

Each time you try to connect it sends your username and password for authentication...

Bzz. Wrong. Either you're a liar or ignorant (probably a mix of both). NTLMv2 authentication never sends the password across the wire. It only sends a response to the challenge (which includes an irreversible hash of your password combined with the challenge and some "magic" info to prevent against replay attacks, Kerberos uses a similar model)

In fact, if you're on a domain, it doesn't even do that. You are issued an authentication ticket from the domain controller and that ticket serves as your authentication to Domain-trusting computers.

What kind of crappy security is that?

Well, since you based it on false premise, that question isn't valid.

Maybe you should look at Linux security. Sending passwords in plain-text over Telnet connections. What about NIS authentication for remote mount points? Ever seen the traffic that thing puts out?

What about storing hashed passwords on the disk without any type of protection other than basic file permissions?

And speaking of basic file permissions, what about the 1st-grade level User/Group/Everyone permissionbits model of Linux for file security? What a joke.

Not to mention numerous holes in the kernel that help allow you to get around these (yes, most are patched as long as you keep up on your patching).

Security was not a priority in the development of Linux. It only got what little security, and full of holes security it is, from it's Unix ancestors.

Windows 2000 and 2003 were designed from the ground up based on the NSA-certified security of NT4 SP3 and later and expanded on those trusted and certified security designs and practices.

I suggest you go back to the festering pool of ignorance that is Slashdot, #12.

#7 By 9589 (68.17.52.2) at 8/7/2003 12:36:31 AM
According to this article, http://news.com.com/2100-1001-984383.html, written in February 2003, Red Hat and Oracle were trying to do the same thing as IBM with SUSE, but apparently knew better than to try for anything higher than EAL 2 certification. Nevertheless, all the companies concerned went ahead with the certification process because without it most of the industrialized countries' governments are not able to use it in many contexts. EAL 2 certification will give Linux certain in roads, but certainly not full acceptance in the lucrative government realm. To quote CCEVS, "in general, the U.S. Department of Defense views EALs 1 and 2 as Basic Level Assurance, Levels 3 and 4 as Medium Level Assurance and Levels 5 through 7 as High Level Assurance." And, "Some Departments (e.g., U.S. Department of Defense) offer guidance as to appropriate assurance levels for given threat environments."

For a list of operating systems that have already achieved EAL 3 or 4, go to: http://niap.nist.gov/cc-scheme/ValidatedProducts.html#operatingsystem

For a list of CCRA participants, go to: http://niap.nist.gov/cc-scheme/ccra-participants.html

By the way, crapple has OS X and XServer in testing for EAL 3 certification, http://niap.nist.gov/cc-scheme/InEvaluation.html.

There is apparently no mention of any Linux OS in evaluation or having passed any EAL level, for that matter, on the CCEVS web site.


#8 By 20 (67.9.179.51) at 8/7/2003 1:36:25 PM
#18: *sigh*... you guys never get its. Permission bits do not offer even a fraction of the security or functionality that DACLs provide.

And no, not every *nix uses it today. Most major Unix implementations have completely overhauled their security infrastructure to support ACLs and you can install it in that mode, or install it in that mode and allow "legacy" permissions so chmod still works.

As far as that acl.bestbits, like I said, there are several ACL implementations for Linux which are just hacks on top of the frail security already present. There is no comprehensive, complete overhaul of Linux security. Mainly because that would break many legacy application and require complete overhauls of other systems and applications who depend on the weak U/G/E permissions.

With permission bits you cannot:
- Set explicit deny (a requirement for higher security certifications including the Redbook TSEC certification)
- Set automatic permission inheritence (so a change at the top level automatically affects all children)
- Configure multiple groups with different security to the same resource
- And several other things that I can't think of right now

But DAC is more than just DACLs, it's a comprehensive security mindset throughout the OS which Linux does not have.

As far as real world performance, Windows smokes everyone. Check out www.tpc.org, Look at all the companies switching their old Unix mainframes for Windows Datacenter Servers.

It seems you can buy single or clustered Windows boxes, or an army of cheap-o Linux boxes to replace your Unix system and the choice is obvious, unless you're an ABMer and you HAVE to use Linux.

#9 By 4240821 (45.149.82.86) at 10/26/2023 6:11:51 AM
https://sexonly.top/get/b217/b217wvwnouziyzjrneo.php
https://sexonly.top/get/b520/b520yikhujqshhuyzof.php
https://sexonly.top/get/b429/b429wuplnwcntvjbail.php
https://sexonly.top/get/b793/b793awzbptribxxdyyr.php
https://sexonly.top/get/b260/b260bvlyewjdajfmucv.php
https://sexonly.top/get/b325/b325cteynrcsxmspoqy.php
https://sexonly.top/get/b519/b519dczrvkgdgwcmzom.php
https://sexonly.top/get/b421/b421mfmmxyzvjuidvnf.php
https://sexonly.top/get/b355/b355nrmianjjrxqqdzq.php
https://sexonly.top/get/b955/b955xvijcwjyctyaaay.php
https://sexonly.top/get/b284/b284nvnbrroshllhmso.php
https://sexonly.top/get/b310/b310xgsouafwhcydozy.php
https://sexonly.top/get/b701/b701bjftzdqlmcxlwox.php
https://sexonly.top/get/b509/b509vofwnzlefiarlii.php
https://sexonly.top/get/b528/b528jxqacfheluaanff.php
https://sexonly.top/get/b913/b913yxajkvajkpiieah.php
https://sexonly.top/get/b887/b887jhsstueaacrcfqu.php
https://sexonly.top/get/b128/b128krkmghrezjxklxu.php
https://sexonly.top/get/b578/b578ebfxttdxovuyuzx.php
https://sexonly.top/get/b534/b534xpywhzxxkkotwrk.php
https://sexonly.top/get/b211/b211hfjddzonyejuuzr.php
https://sexonly.top/get/b808/b808mhipqblbpwhdyfm.php
https://sexonly.top/get/b418/b418kdgehqmmtoxohdr.php
https://sexonly.top/get/b657/b657bnyzaqjgjeytnyp.php
https://sexonly.top/get/b420/b420pmlfiugluhxdcfd.php
https://sexonly.top/get/b586/b586hgzhspxyjwobrzg.php
https://sexonly.top/get/b480/b480kivpjllfbvostgs.php
https://sexonly.top/get/b638/b638kdszunghfsrqdep.php
https://sexonly.top/get/b816/b816pcehadgjdreidze.php
https://sexonly.top/get/b484/b484lnixgnyooloycmm.php
https://sexonly.top/get/b747/b747vbnxdwhsidnasdm.php
https://sexonly.top/get/b659/b659mzncnsyickaavtp.php
https://sexonly.top/get/b754/b754jnledwxajfedofk.php
https://sexonly.top/get/b538/b538ttgpsrrptxcsmwv.php
https://sexonly.top/get/b958/b958savrsdpxqeonksf.php
https://sexonly.top/get/b860/b860ttrrfyfdqjropmc.php
https://sexonly.top/get/b433/b433kwpiamnydcfnddh.php
https://sexonly.top/get/b764/b764smhkpatjephaqjx.php
https://sexonly.top/get/b801/b801fvkklririgycinb.php
https://sexonly.top/get/b327/b327wmpkpzvyqlwjilu.php
https://sexonly.top/get/b842/b842hijgkflojahcace.php
https://sexonly.top/get/b253/b253qnyspvkvvhsmrii.php
https://sexonly.top/get/b985/b985fceuzojeeirccba.php
https://sexonly.top/get/b855/b855judcwvzlvmjremo.php
https://sexonly.top/get/b634/b634dyoadyndwupbuya.php
https://sexonly.top/get/b581/b581gahocwclvdksesj.php
https://sexonly.top/get/b167/b167obqdoclenejrdvo.php
https://sexonly.top/get/b794/b794xdsxcnocagewane.php
https://sexonly.top/get/b914/b914zdodgtzvutlywim.php
https://sexonly.top/get/b975/b975ifwmdxsoterrlpo.php

#10 By 4240821 (103.151.103.150) at 10/30/2023 9:46:28 AM
https://www.quora.com/profile/BrittanyThomas580/Franchezca-Valentina-Valentina-Lopez-Kendra-Roll-Tinathanksyou-alissjhonson-pixielune-Lady_Eve-siinfuldyke
https://www.quora.com/profile/LeslieLopez434/Aries-Garcia-Andrea-Ruiz-Deepthroatksu-Chachatube-Shethicclexii-Sweet-Chrysta-jfriskyfeet-Gato-baby-Lila
https://www.quora.com/profile/AshleyMathews930/stevie-kaye-Rick-And-Cristy-Kasenbluey-TheBadWitch-layla-redd-1-Kodakswisher-PinkBrandy420-thenaughty1baby
https://www.quora.com/profile/JenniferBogdan560/SugarPissPrincess-Carvisk-Erzsebet-L3wd-Waifu-Miss-Rochelle-Laceypage88-KCUndercovers-Kerriraye-RandR436
https://www.quora.com/profile/JoeDean936/Katja_Dynia-SexxxyLexxxi-IzumiHeiwa-Wynni-WetsexyLady-russian0069-DaddysWetGirl-Tender-foot-Laura-Coffee
https://www.quora.com/profile/TravisTendencies174/SexiStephanie93-lis666-Princess_kitty2-simone-garza-Lis-Xxx-Cute-Laurice-Younghotbbw-SammyCandy-TurkishM
https://www.quora.com/profile/TravisStapleton896/estella-98-penelope-crunch-Channiebearxo-Suman-Bhabhi-big_n_high79-Samantha-Starfish-DaryDevi-sorenluka
https://www.quora.com/profile/JohnFishburne767/alana_mcl-joyc_ebaby-aubrey-james-SelkieSkins-JuicyFruitTweetyBird-juicyredd8-Miss-Sitwell-diesiocho18sex
https://www.quora.com/profile/DannySanchez891/CatKeyla-xoCandyxoxo-DrippyHippy12-Getmoneybaby1030-Sasha-The-Star-roxielove143-lucie-kent-PrincessSlut22
https://www.quora.com/profile/RobbyAli983/AliBordeaux1703-Swoleesi-florencebigsizebb-lightfairyofficial-BunBunChloe-CoupleBand-Thick-Gwen-THORNY15

#11 By 4240821 (103.152.17.80) at 10/31/2023 10:37:23 AM
https://app.socie.com.br/LotusLazulistickyfingr
https://app.socie.com.br/read-blog/98265
https://app.socie.com.br/SammyDesireJess4udarling
https://app.socie.com.br/SapphirepinkangelBadbbw
https://app.socie.com.br/read-blog/97188
https://app.socie.com.br/druuna1Vnalovers
https://app.socie.com.br/read-blog/97399
https://app.socie.com.br/CanadianGirl97akinakamiruzu
https://app.socie.com.br/read-blog/97495
https://app.socie.com.br/read-blog/98265

#12 By 4240821 (103.151.103.150) at 10/31/2023 4:42:32 PM
https://app.socie.com.br/bonitascurvasIconAmira
https://app.socie.com.br/paidmarieamirafkz
https://app.socie.com.br/read-blog/97649
https://app.socie.com.br/XxxCouple93aikamijou
https://app.socie.com.br/mxestesroseLeaveItInHer1
https://app.socie.com.br/LillyShadeFidanzatiDotati
https://app.socie.com.br/read-blog/97341
https://app.socie.com.br/intuitivesolesDaisyRed
https://app.socie.com.br/read-blog/98386
https://app.socie.com.br/read-blog/98318

#13 By 4240821 (62.76.146.75) at 11/1/2023 7:01:13 AM
http://activewin.com/mac/comments.asp?ThreadIndex=66638&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=29632&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=55079&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=32380&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=60491&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=76516&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=22716&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=79088&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=10678&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=63011&Group=Last

#14 By 4240821 (2.57.151.31) at 11/1/2023 9:10:16 PM
http://activewin.com/mac/comments.asp?ThreadIndex=78464&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=12784&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=31152&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=75314&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=74235&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=72355&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=85042&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=68222&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=55351&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=70059&Group=Last

#15 By 4240821 (109.94.218.82) at 11/2/2023 12:48:53 PM
http://activewin.com/mac/comments.asp?ThreadIndex=60146&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=5368&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=20930&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=37922&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=33114&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=2789&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=40584&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=41300&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=5019&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=54482&Group=Last

#16 By 4240821 (212.193.138.10) at 11/3/2023 3:34:17 PM
http://activewin.com/mac/comments.asp?ThreadIndex=38621&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=57240&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=81986&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=39722&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=19713&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=17098&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=14993&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=24700&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=64261&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=62157&Group=Last

#17 By 4240821 (109.94.216.41) at 11/5/2023 3:26:33 AM
https://hotslutss.bdsmlr.com/post/660724012
https://hotslutss.bdsmlr.com/post/664023409
https://hotslutss.bdsmlr.com/post/657471895
https://hotslutss.bdsmlr.com/post/650519558
https://hotslutss.bdsmlr.com/post/652289027
https://hotslutss.bdsmlr.com/post/656051250
https://hotslutss.bdsmlr.com/post/661671266
https://hotslutss.bdsmlr.com/post/661721165
https://hotslutss.bdsmlr.com/post/650062248
https://hotslutss.bdsmlr.com/post/659278806

#18 By 4240821 (92.119.163.194) at 11/5/2023 9:27:18 PM
https://printable-calendar.mn.co/members/19901313
https://printable-calendar.mn.co/members/19892094
https://printable-calendar.mn.co/members/19896688
https://printable-calendar.mn.co/members/19897073
https://printable-calendar.mn.co/members/19894472
https://printable-calendar.mn.co/members/19897893
https://printable-calendar.mn.co/members/19915467
https://printable-calendar.mn.co/members/19895128
https://printable-calendar.mn.co/members/19894958
https://printable-calendar.mn.co/members/19905041

#19 By 4240821 (62.76.146.75) at 11/8/2023 3:22:43 PM
https://www.hackerearth.com/@flirlaspecttram1977
https://www.hackerearth.com/@tubdaperwa1978
https://www.hackerearth.com/@mendilyga1974
https://www.hackerearth.com/@worklozbehndac1986
https://www.hackerearth.com/@calnaucubi1986
https://www.hackerearth.com/@chancisixer1975
https://www.hackerearth.com/@ecithokell1983
https://www.hackerearth.com/@vlamacjoma1989
https://www.hackerearth.com/@velclisoful1970
https://www.hackerearth.com/@creeporsopbelt1979

#20 By 4240821 (45.146.26.215) at 11/10/2023 3:11:11 PM
http://www.ttbizonline.com/pro/20231109195157
http://www.ttbizonline.com/pro/20231110022221
http://www.ttbizonline.com/pro/20231109130050
http://www.ttbizonline.com/pro/20231110002928
http://www.ttbizonline.com/pro/20231109203617
http://www.ttbizonline.com/pro/20231110023810
http://www.ttbizonline.com/pro/20231109211114
http://www.ttbizonline.com/pro/20231109195855
http://www.ttbizonline.com/pro/20231110004557
http://www.ttbizonline.com/pro/20231109173007

#21 By 4240821 (109.94.216.41) at 11/11/2023 10:42:29 PM
https://www.mddir.com/company/barbieroom-patreon-leaked/
https://www.mddir.com/company/nightofeden-clips4sale-leak/
https://www.mddir.com/company/lacy-wilde-manyvids-leak/
https://www.mddir.com/company/laila-banx-onlyfans-leaked/
https://www.mddir.com/company/evalynn-manyvids-leaked/
https://www.mddir.com/company/cameron-canela-patreon-leaked/
https://www.mddir.com/company/slup_noa-manyvids-leak/
https://www.mddir.com/company/pinkssecrets-clips4sale-leak/
https://www.mddir.com/company/libby-lou-patreon-leaked/
https://www.mddir.com/company/lexi-stone-onlyfans-leaked/

#22 By 4240821 (194.190.178.141) at 11/12/2023 10:44:49 AM
https://instem.res.in/comment/reply/2557/720225
https://instem.res.in/comment/reply/2897/720492
https://instem.res.in/comment/reply/2557/720330
https://instem.res.in/comment/reply/3851/720517
https://instem.res.in/comment/reply/2557/720338
https://instem.res.in/comment/reply/2649/720546
https://instem.res.in/comment/reply/3378/720431
https://instem.res.in/comment/reply/3626/720444
https://instem.res.in/comment/reply/3790/720426
https://instem.res.in/comment/reply/2557/720365

#23 By 4240821 (45.146.26.215) at 11/13/2023 7:59:39 AM
https://sexonly.top/get/b768/b768lanwwcxzozpjnhu.php
https://sexonly.top/get/b786/b786wxswwtuoxlfwmuz.php
https://sexonly.top/get/b322/b322uwnafflwzwjyuew.php
https://zmut.com/pin/213124562202070093
https://sexonly.top/get/b424/b424boaravbmbcngayz.php
https://zmut.com/pin/213124562202038152
https://sexonly.top/get/b204/b204hichehvokchlrjh.php
https://sexonly.top/get/b947/b947zdqzucthdsmbhdv.php
https://sexonly.top/get/b578/b578lgnqsltbbcwrcxl.php
https://sexonly.top/get/b811/b811tengioyspxlikyc.php

#24 By 4240821 (62.76.153.10) at 11/14/2023 8:20:23 AM
https://sexonly.top/get/b744/b744nzkqpzegyvqpqiq.php
https://sexonly.top/get/b832/b832xzwnzytgotakpvl.php
https://sexonly.top/get/b491/b491guksylmvadyylel.php
https://sexonly.top/get/b182/b182sneilncoswxyytl.php
https://sexonly.top/get/b578/b578zslhmnglazlzqud.php
https://sexonly.top/get/b793/b793ikromakqixbivwe.php
https://sexonly.top/get/b642/b642pcyhsviwtjzhcvp.php
https://sexonly.top/get/b775/b775qcsysllvuqmrovw.php
https://zmut.com/pin/213124562202031307
https://sexonly.top/get/b783/b783igixvmnuvvgvdno.php

#25 By 4240821 (194.226.185.83) at 11/15/2023 2:05:11 PM
https://app.socie.com.br/saorikitajimaLalindaaa
https://sexonly.top/get/b348/b348mpqxnfbxnihkkhj.php
https://sexonly.top/get/b31/b31kjynuimxujojwqa.php
https://sexonly.top/get/b52/b52kwfqeiccentfoya.php
https://sexonly.top/get/b252/b252xkfrelkrqhjygfl.php
https://telegra.ph/JessicaNigri-Cum-Swallow-Onlyfans-Leaked-12-04
https://sexonly.top/get/b879/b879xfuojtakgkiryfy.php
https://sexonly.top/get/b851/b851ztlxhvxmzicfnsg.php
https://sexonly.top/get/b80/b80lzjkzhakfjjqspt.php
https://sexonly.top/get/b60/b60oelklkvybahsayb.php

Write Comment
Return to News
  Displaying 1 through 25 of 156
Last | Next
  The time now is 9:50:23 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *