On Sun, May 07, 2000 at 12:00:21PM +1200, Del wrote:
>
> But seriously, folks, what we've all known for years is:
>
> - Take a copy of [.*]x out of the box, install it, and the binary files in
> /usr/bin, /usr/lib, /lib, etc, are world readable, and not world writeable.
> Joe Average User can't launch a virus that writes to a system DLL.
True most out of box installs of Unix are pretty secure.
>
> - Take a copy of Microsoft Windows [.*] out of the box, install it, and
> C:\WINNT\SYSTEM32\KERNEL32.DLL and the rest are all world writeable. The
> registry is world writeable. Joe Average User is sitting on an operating
> system with a built in virus installation mechanism.
Here I disagree with you. Most out of box Windows _NT_ installs are secure;
the problem arises because most people add themselves to the "Administrators"
group (equivalent to changing your userid to 0 -- root's -- effectively).
They do this "in order to do stuff" like set the clock, install programs, etc.
Microsoft have only lately realised that people running Windows NT on a single
user box don't have the ability to change credentials (like sudo allows)
easily. So most people don't bother and choose the simplest option.
The large sites that I know of don't add their users into the Administrators
group so OS installation corruption isn't an issue with virii/worms.
> This is what Microsoft are culpable for. Fine grained access lists are worth
> nothing unless it's all set up by default.
No what they guilty of is perpetuating the myth that computers are simple
to use and operate. Unix System Administrator is a recognised job, Windows
System Administrator is starting to become one.
Anand
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text