Lobbying for insecurity (Register)
[Posted August 30, 2002 by ris]
Here is
an
article in the Register on the U.S. National Security Agency's
contribution to open-source security, Security-Enhanced Linux. "
The
most secure software in the world doesn't improve security if nobody runs
it, or if it's incompatible with what the vast majority of people
run. Standard is better than better. VINES networks might be more secure
than TCP/IP but it does little to secure the Internet as a whole. MD5
password hashing was always more secure than old Unix crypt password
hashes, but until vendors started shipping the code, and integrating it via
Pluggable Authentication Modules, it made little difference."
(
Log in to post comments)