Open BSD has to be the weakest secure system evAr...

The place for technology related posts.

Moderator: Moderators

Post Reply
User avatar
complacent
DCAWD Founding Member
Posts: 11651
Joined: Sun Aug 29, 2004 8:00 pm
Location: near the rockies. very.
Contact:

Open BSD has to be the weakest secure system evAr...

Post by complacent »

I mean, come on people!! This is what, like the [/b]SECOND[/b] security patch released in the past 10 years?!?!

Rank amateurs I tells ya.

:roll:










:rolllaugh:
colin

a tank, a yammie, a spaceship
i <3 teh 00ntz
chicken n waffles
Moderator
Posts: 6314
Joined: Wed Oct 19, 2005 1:15 am
Location: Alexandria

Post by chicken n waffles »

Image
-Ben
Image
User avatar
Cereb Daithi
DCAWD Groupie
Posts: 3747
Joined: Wed Apr 26, 2006 11:07 pm
Location: Pittsburgh, PA
Contact:

Post by Cereb Daithi »

Image

It takes them a while
schvin
DCAWD Groupie
Posts: 1659
Joined: Fri Nov 19, 2004 7:00 pm
Location: washington, dc
Contact:

Post by schvin »

dude... when i saw the subject...

i KNOW you're just trying to get a rise out of somebody :)
2004 impreza outback
1964 beetle
User avatar
complacent
DCAWD Founding Member
Posts: 11651
Joined: Sun Aug 29, 2004 8:00 pm
Location: near the rockies. very.
Contact:

Post by complacent »

schvin wrote:dude... when i saw the subject...

i KNOW you're just trying to get a rise out of somebody :)
It was too funneh to pass up. There isn't anoth operating system in the entire world that is as secure as OpenBSD. Nothing even comes remotely close.

Can you imagine *ANY* other OS being that secure?!? We'd all be jobless... Especially you! :wink:
colin

a tank, a yammie, a spaceship
i <3 teh 00ntz
User avatar
Sabre
DCAWD Founding Member
Posts: 21432
Joined: Wed Aug 11, 2004 8:00 pm
Location: Springfield, VA
Contact:

Post by Sabre »

lol, when I saw the title, I figure it was a ruse... You KNOW you'd get a rise out of me for that one ;)

<goes back to installing FreeBSD on a server.... no, I'm not kidding...>
Sabre (Julian)
Image
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
schvin
DCAWD Groupie
Posts: 1659
Joined: Fri Nov 19, 2004 7:00 pm
Location: washington, dc
Contact:

Post by schvin »

complacent wrote:
schvin wrote:dude... when i saw the subject...

i KNOW you're just trying to get a rise out of somebody :)
It was too funneh to pass up. There isn't anoth operating system in the entire world that is as secure as OpenBSD. Nothing even comes remotely close.

Can you imagine *ANY* other OS being that secure?!? We'd all be jobless... Especially you! :wink:
truth :)
2004 impreza outback
1964 beetle
avriette
DCAWD Groupie
Posts: 1316
Joined: Sun Oct 01, 2006 3:48 pm
Location: Arlington, VA
Contact:

Re: Open BSD has to be the weakest secure system evAr...

Post by avriette »

complacent wrote:I mean, come on people!! This is what, like the [/b]SECOND[/b] security patch released in the past 10 years?!?!
You know, I've actually been lecturing on this all week. I've been really surprised at how much faith people put in "secure systems." OpenBSD is phenomenally secure. They have more or less the right idea for how to create a secure system (DISA tends to recommend that you "turn off things you don't need." The correct approach for securing systems is to only turn on things you need, leaving everything off. OpenBSD calls this 'secure by default', and it is the right approach).

However, even today (this is the last day of the class, they're getting the exam tomorrow), I had to give like a half hour lecture on why the very secure isn't. They looked at me in amazement when I explained:

"So let's imagine the world's most secure system. You have a network and applications that are absolutely impenetrable. You're storing all your fancy mission data on it, knowing that your targeting data and intelligence data are absolutely safe on the system.

At the end of the day, you leave the office, comforted by the fact your data is safe.

When you get home, you say hello to the wife and kids, and fire up your email client and answer an e-mail from your mother asking how you're doing and what you've been up to, by voicing your frustrations with the way the war is going, including mission data."

I thought this kind of thing was glaringly obvious.

So, sure, OpenBSD is secure. But, human elements make it only as secure as the least secure part of it. Pricks like Theo screaming from the hilltops about how secure it is (making it a huge target; I'm sure we remember the *GOBBLES* days – these were aimed squarely at Theo, not just the OS), and idiot sysadmins who install it thinking that by running the world's most secure operating system, there is no way their data can be compromised.

See also: SELinux. Trusted Solaris.
rocket scientist
schvin
DCAWD Groupie
Posts: 1659
Joined: Fri Nov 19, 2004 7:00 pm
Location: washington, dc
Contact:

Post by schvin »

yeah. welcome to life. good point though.
2004 impreza outback
1964 beetle
schvin
DCAWD Groupie
Posts: 1659
Joined: Fri Nov 19, 2004 7:00 pm
Location: washington, dc
Contact:

Post by schvin »

schvin wrote:yeah. welcome to life. good point though.
that came off a bit harsher than intended. pls disregard. long day.
2004 impreza outback
1964 beetle
User avatar
complacent
DCAWD Founding Member
Posts: 11651
Joined: Sun Aug 29, 2004 8:00 pm
Location: near the rockies. very.
Contact:

Post by complacent »

schvin wrote:
schvin wrote:yeah. welcome to life. good point though.
that came off a bit harsher than intended. pls disregard. long day.
I see no fault in that statement man. Ppls r being not smart. Everyday. "We" are always the weakest link in ANY network....

Did anyone read that vulnerability study done at a (I think) swiss bank? The infosec team placed like 50 usb flashdrives in the parking lot of the bank, each drive containing various scripts and malware... By noon the same day ALL 50 drives had reported back to their server, containing various passwords, documents, etc. Like I said, ppls r being dumb.


(Poor Theo, always getting picked on! ) hahaha ;)
colin

a tank, a yammie, a spaceship
i <3 teh 00ntz
User avatar
WRXWagon2112
DCAWD Founding Member
Posts: 3314
Joined: Mon Aug 23, 2004 8:00 pm
Location: Livin' the dream

Re: Open BSD has to be the weakest secure system evAr...

Post by WRXWagon2112 »

avriette wrote:But, human elements make it only as secure as the least secure part of it.
I can't remember where I heard/read/saw it but apparently the most often used means to hack into a system is the use of social engineering - not actual computer skillz.

You're absolutely right - a secure system is only as secure as the people who use it.

--Alan
schvin
DCAWD Groupie
Posts: 1659
Joined: Fri Nov 19, 2004 7:00 pm
Location: washington, dc
Contact:

Post by schvin »

yeah, that swiss thing was hilarious! good stuff :)
2004 impreza outback
1964 beetle
User avatar
Libra Monkee
Moderator
Posts: 6478
Joined: Wed Mar 29, 2006 11:04 pm
Location: The Ether
Contact:

Re: Open BSD has to be the weakest secure system evAr...

Post by Libra Monkee »

WRXWagon2112 wrote:
avriette wrote:a secure system is only as secure as the people who use it.

--Alan
Didn't Kevin Mitnik say that in "The Art of Deception"?
Image

Libra Monkee- "Helping DCAWD meet its Equal Opportunity requirement since 2006."
Post Reply