Re: [SLUG] Lindows -> Linux

From: Matt Moen (mattlists@younicks.org)
Date: Thu Jan 30 2003 - 08:32:44 EST


Thus spake Paul M Foster on the 29 day of the 01 month in the year 2003:
-snip-
> You do in fact run as root on this machine. There are no other users
> configured out of the box.
-snip-

I'm just waiting for someone to find a vulnerability in the version of
Mozilla that comes with Lindows, or with it's default e-mail client, or
something like that. Even better would be a vulnerability in a daemon,
although hopefully there aren't any of those running. Since everything
is running as root, the machine will be toast and require a complete
reinstall after such an intrusion.

Just think of the IRC bot, or DDOS possibilities of a legion of Lindows
machines being run by people who don't know any better. If the
underground isn't working on it already, it won't be long until they
notice that there's a huge collection of these machines out there, free
for the taking by the first worm to strike.

So my question is, how will this affect people's perception of Linux
_when_ this occurs. (There are no if's about this one.)

The only good outcome I see is that Lindows sounds like Windows so
perhaps people will realize that making Linux almost exactly like
Windows is a bad idea.

The lousy outcome (at least for the Linux community) is that the press
will have a feeding frenzy. Just think of the stories saying things
like "So much for this Linux thing being more secure than Windows." One
can only hope the mass media will contact someone from the Linux
community like Bruce Perens for comment on how horrid Lindows is
and how other Linux versions /are/ more secure. Even so, damage control
will be rough.

An even more disturbing outcome would be ISP's blocking Linux machines
based on TCP/IP fingerprinting "in order to stop the spread of this worm".

-- 
Matthew Moen

Outlook is as attractive to email viruses as a heap of dead and rotting cows is to a fly. So long as that maggot-filled pile of corpses is there, swatting at the flies isn't going to work. Alan Bellingham, SDM



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 13:59:41 EDT