Red Hat gains security certification (News.com)
Posted Apr 30, 2004 6:21 UTC (Fri) by
anselm (subscriber, #2796)
In reply to:
Red Hat gains security certification (News.com) by Soruk
Parent article:
Red Hat gains security certification (News.com)
Remember that at these levels EAL certification mostly means that
somebody has checked that the documentation is complete. It does not
involve looking at the actual system in any detail, let alone doing so
from the point of view of a dedicated attacker.
Even the Windows EAL4
certification doesn't say much more than that the system may be
reasonably secure if nobody on it is misbehaving (and that includes
the programmers of third-party applications). If I remember right,
the Windows machine in question was one with no networking and no
software installed beyond the actual operating system.
(
Log in to post comments)