Original Sender : "B. 'Avatar' Avianto" <[EMAIL PROTECTED]>
---------------------------------
Responding to Y. Ignatius Erik Arya's mail on Sat, 07 Aug 1999:
#>> Lah? Downnya karena overload kok... ya kebanyakan HIT atau
#>> kebanyakan DoS... Nggak ada yang karena 'hack-attempt"
#>
#>Hmmm.... kayaknya dari berita di atas ada yang menanggapi tantangan
#>microsoft bukan?
#>
#>Server overload, DoS, hack, crack, dlsb tetap berisi data kelemahan
#>system tersebut. Server overload bisa menunjukkan seberapa jauh
#>OS bisa menghandle request pada satu platform hardware. DoS bisa
#>menunjukkan adanya kelemahan pada satu program (Kernel, Stub, HAL,
#>DLL, VxD dan lainnya). Crack/Hack bisa menunjukkan kelemahan
#>alogarithm, sistem design atau implementasi dari program/hardware-nya.
Sekedar Info yang diambil dari milis SEKURITI, Bugtraq...:
----
Since nobody has pointed it out yet it has been said by various people, at
least one of them in print, (including Spafford, I think) that these
challenges are unlikely to attract the real experts, who can charge large
consulting fees. It simply makes no sense for these people to give their
services for no charge by attacking such machines.
Suppose a criminal uses the testing period to find a really devsating bug. Do
you think they tell the people running the machine about it or do they instead
use it for extortion, theft or other evil purposes later? Further some of the
most devasting exploits really require a test machine you have root, or
equivilent access, to find the information needed and develop the code. Until
windows 2000 is released such machines seem unlikely to be avialable.
----
#>Pada kasus microsoft ini, terlihat mereka tampaknya mulai menanggapi
#>dengan serius terhadap keamanan OS mereka. Mungkin ini karena mulai
#>tahun depan (Hopefully!) mereka akan mulai merelease hanya satu OS
#>untuk personal dan server (windows2000).
Belum baca white-paper soal Windows2000 ya?
Memang namanya hanya 1: Windows2000, tapi punya berbagai macam flavour dan
lisence: ada yang Profesional, Development, etc... etc... Coba deh referensinya.
#>> Apalagi selama 'source code'nya WIndows masih dirahasiakan... =(
#>
#>"Closed Source" sih menurut saya ada gunanya juga. Karena akan
#>sedikit mempersulit memperoleh cara-cara melakukan DoS/Crack/Hack.
#>Hal ini juga untuk melindungi intellectual property mereka karena
#>tentunya kita tahu OS mereka adalah salah satu produk komersial
#>mereka. Sebanyak kita ingin tahu "source code" mereka, kita harus
#>menghormati tindakan mereka melindungi hal ini.
Jawaban anda (intellectual property, security through obscurity) dibahas panjang
lebar di: http://www.opensource.org
Banyak pemahaman yang keliru mengenai konsep "Open Source" dan mungkin sedikit
referensi ke situs tersebut akan menghilangkan pemahaman tersebut
#>Pada vendor UNIX variant pun tidak semua source code mereka dibuka.
#>Program-program komersial mereka tidak ada source code-nya.
Loh? UNIX bukan 'opensource' kan?
#>Tinggal saya ingin menyaksikan apakah dengan begitu banyak incident
#>tersebut, akankah microsoft akan menghasilkan OS yang "robust" pada
#>akhirnya.
Setuju...
Walaupun akhirnya kita kembali kepada Microsoft karena kita memang tergantung
pada pengembangan mereka... well, IMHO ini adalah salah satu "The Dark
Side of Closed Source Model"... ketergantungan akan vendor... =(
--
Wassalam,
B. 'Avatar' Avianto
[EMAIL PROTECTED] - http://www.avianto.com
-------------------------------------------
Nothing will come of nothing, speak again -- King Lear
----------------------------------------------------------------
Compu-Mania MailingList is provided by PT Centrin Utama
Maintained by : [EMAIL PROTECTED]
To Post a msg : Send mail to [EMAIL PROTECTED]
To Unsubscribe : Mail to [EMAIL PROTECTED]
BODY : unsubscribe Compu-Mania
For more information, send mail to [EMAIL PROTECTED]
with "HELP" in the BODY of your mail (without quote).
----------------------------------------------------------------