ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

British businesses advised to avoid Linux

Will Knight ZDNet.co.uk

Published: 04 Nov 1999 16:34 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A British security consultant has drawn fierce criticism from Linux experts after advising companies the open source operating system is not secure enough for commercial use.

Speaking Wednesday at the UK Compsec conference in London, Stan Dormer of IT security training firm Stan Dormer Associates, dedicated an entire presentation to the subject entitled: "Linux Security: is it good enough for commercial use?"

Dormer criticised the portrayal of Linux in the media as a practical alternative to Windows variants claiming that for the average user, Linux is not a secure option. His conclusions are based on research carried out by his company over a number of weeks.

According to Dormer's research:

  • Linux requires more user expertise and knowledge than other operating systems, meaning higher administrative and maintenance costs

  • Different Linux distributions install with unknown levels of security

  • Linux requires an inordinate amount of work to prevent passwords being captured and reused. Dormer said the command line prompt makes it easier for input processes to be hijacked

  • Linux has inferior standard logging capabilities

  • NetWare and NT are more flexible

  • Freeware may contain bugs and is not as widely available as commercial software

One Linux security specialist, who requested anonymity, challenged Dormer's research and his credibility: "You shouldn't run Linux if you can't support it and obviously this guy couldn't. As for not being as secure as something like Windows NT, I see many bugs in NT and I can't say I trust it. You certainly can't trust the vendor to fix the bugs."

The security source also disputed whether Linux is difficult to set-up securely. "In about ten minutes you can get a Linux box pretty unhackable running Apache and SSL. NT is an administrative nightmare as the whole logging process slows it down so much." He also questioned whether a novice should be involved with setting up any company's security measures.

But Dormer hit back arguing that his assertions need to be taken in context. He said that in Britain many relatively inexperienced IT managers are charged with making sure their company is shored-up against computer attack. "I'm not knocking Linux," he said, "I'm just being a hard-nosed businessman. With Windows what's going on is far more visible and you can bring your experience of working with Windows 98 and 95 to it."

British Linux developer Jason Clifford attacked Dormer's presentation as wildly inaccurate and misleading. "What was he trying to sell people? You can't get much more secure than having access to source code. Most distributions of Linux have nice utilities for security and I'd say that it's as easy, if not more, to make Linux as secure as any other operating system."

Clifford also pointed out that security is an important issue in itself, regardless of the operating system. "No system is exactly easy to secure. Security is about best practice and if you know good practice it's easier to be secure on any operating system.

Take me to the Linux Lounge

Do you agree with Dormer's research? Tell the Mailroom

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
27 out of 72 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Oracle Technical Architect

Design of the layout of applications and database environments - Design of the security architecture - Design of the availability architecture - ...

Associate Director of Business Intelligence

The Dudley Group of Hospitals NHS Trust provides a wide range of medical, surgical and rehabilitation services to the people of Dudley and ...

Desktop Support Analyst - Financial Services - West London c30k

From a qualification standpoint, my client would like you to hold MCPs in Windows NT and 2000 or 20003 and ideally your degree (or equivalent) will ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.