Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 22 Sep 2000 12:24:59 +1100 (EST)
From:      Stanley Hopcroft <Stanley.Hopcroft@IPAustralia.Gov.AU>
To:        security@FreeBSD.ORG
Subject:   Re: sysinstall DOESN'T ASK, dangerous defaults! (Was: Re: whats  so special about freeBSD?)
Message-ID:  <Pine.BSF.4.21.0009221158400.640-100000@stan>
In-Reply-To: <4.3.2.7.2.20000921182152.046d6ee0@localhost>

next in thread | previous in thread | raw e-mail | index | archive | help
Dear Ladies and Gentlemen,

I am writing to suggest that the criteria for deciding about these
things is consider who will benefit from changing the default settings
or what market one aims for ?

If ones customers are naive users, then sure take the MS Windows
approach and do it (whatever it is) all for them and hope they
eventually realise what you have done for/to them and appreciate it.

If there's a benefit by adopting the firewall principal of disabling
whatever's unnecessary, or equivalently, a reducible or unacceptable
cost in not doing so, then disabling stuff seems sensible.

As Mr Glass says, optimising these settings to harden many of the boxen
I deal with (routers, terminal servers, DNS servers etc) is time
consuming. It would be nice to only enable what I want rather than bear
the risk of *not* disabling stuff.

That said, one of the lovely things about Unix is that it *is*
configurable.

The only thing I might add is that setting up a workstation on memory
strapped hardware (eg the a P133/32 MB when I'd like to run kde,
netscape etc) is unfortunately fairly painful and shows up the
different trade offs in the MS and Unix environment. 

Since this has no bearing on seecurity and is probably caused by
applications or the different kernel approaches (not to mention the
disgusting lack of MS integrity that surely must infect their code),
its hardly worth mentioning in this context.

However, it would be a lovely advertisement to be able to highlight the
robustness and grunt of FreeBSD by showing it run good looking
applications with the same apparent carelessness as MS Windows on the
same gutless hardware.

As for me, my workstations happy thrashing FreeBSD.

Thank you,

Yours sincerely.

S Hopcroft
Network Specialist
IP Australia

+61 2 6283 3189
+61 2 6281 1353 FAX





To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0009221158400.640-100000>