I was being 100% sarcastic about SELinux.<br><br><div class="gmail_quote">On Sun, Sep 2, 2012 at 1:41 AM, Tristan Santore <span dir="ltr">&lt;<a href="mailto:tristan.santore@internexusconnect.net" target="_blank">tristan.santore@internexusconnect.net</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">On 02/09/12 09:33, Dan Mashal wrote:<br>
&gt; I&#39;m not just an ambassador. I&#39;m a Sysadmin too.<br>
&gt;<br>
&gt; Have you heard of suckit rootkit and rst?<br>
&gt;<br>
&gt; Times have changed.<br>
&gt;<br>
&gt; Had there been links to CVEs and other articles with hard evidence my<br>
&gt; response would have been different.<br>
&gt;<br>
&gt; Besides! We have SELinux now! :D<br>
&gt;<br>
&gt; Dan<br>
&gt;<br>
&gt; On Sun, Sep 2, 2012 at 1:31 AM, Tristan Santore<br>
&gt; &lt;<a href="mailto:tristan.santore@internexusconnect.net">tristan.santore@internexusconnect.net</a><br>
</div><div class="im">&gt; &lt;mailto:<a href="mailto:tristan.santore@internexusconnect.net">tristan.santore@internexusconnect.net</a>&gt;&gt; wrote:<br>
&gt;<br>
&gt;     On 02/09/12 09:20, Dan Mashal wrote:<br>
&gt;     &gt; This is a bunch of BS.<br>
&gt;     &gt;<br>
&gt;     &gt; No direct links or hard evidence in the article. Even if there<br>
&gt;     was, this<br>
&gt;     &gt; is a browser issue. Not an OS issue.<br>
&gt;     &gt;<br>
&gt;     &gt; Dan<br>
&gt;     &gt;<br>
&gt;     &gt; On Sun, Sep 2, 2012 at 1:19 AM, Tristan Santore<br>
&gt;     &gt; &lt;<a href="mailto:tristan.santore@internexusconnect.net">tristan.santore@internexusconnect.net</a><br>
&gt;     &lt;mailto:<a href="mailto:tristan.santore@internexusconnect.net">tristan.santore@internexusconnect.net</a>&gt;<br>
</div>&gt;     &gt; &lt;mailto:<a href="mailto:tristan.santore@internexusconnect.net">tristan.santore@internexusconnect.net</a><br>
<div class="im">&gt;     &lt;mailto:<a href="mailto:tristan.santore@internexusconnect.net">tristan.santore@internexusconnect.net</a>&gt;&gt;&gt; wrote:<br>
&gt;     &gt;<br>
&gt;     &gt;     On 02/09/12 03:04, Danishka Navin wrote:<br>
&gt;     &gt;     &gt; Is this true? (for Linux)<br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;<br>
&gt;     <a href="http://news.efytimes.com/e1/89929/New-Trojan-Threatens-Mac-OS-X-Linux-Machines" target="_blank">http://news.efytimes.com/e1/89929/New-Trojan-Threatens-Mac-OS-X-Linux-Machines</a><br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;     &gt; Btw, I could not find any source other than this.<br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;     &gt; Thanks,<br>
&gt;     &gt;     &gt; --<br>
&gt;     &gt;     &gt; Danishka Navin<br>
&gt;     &gt;     &gt; <a href="http://danishkanavin.blogspot.com" target="_blank">http://danishkanavin.blogspot.com</a><br>
&gt;     &gt;     &gt; <a href="http://twitter.com/danishkanavin" target="_blank">http://twitter.com/danishkanavin</a><br>
&gt;     &gt;     &gt; <a href="http://www.flickr.com/photos/danishkanavin/" target="_blank">http://www.flickr.com/photos/danishkanavin/</a><br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;     &gt;<br>
&gt;     &gt;     &gt; --<br>
&gt;     &gt;     &gt; ambassadors mailing list<br>
&gt;     &gt;     &gt; <a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a><br>
&gt;     &lt;mailto:<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a>&gt;<br>
</div>&gt;     &gt;     &lt;mailto:<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a><br>
<div><div class="h5">&gt;     &lt;mailto:<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a>&gt;&gt;<br>
&gt;     &gt;     &gt; <a href="https://admin.fedoraproject.org/mailman/listinfo/ambassadors" target="_blank">https://admin.fedoraproject.org/mailman/listinfo/ambassadors</a><br>
&gt;     &gt;     If it is, it just reinforces that you cannot rely on anything for<br>
&gt;     &gt;     security, because there is no such thing as a secure system,<br>
&gt;     as long as<br>
&gt;     &gt;     us filthy useless humans write code. Nobody in the linux<br>
&gt;     community ever<br>
&gt;     &gt;     made such promises any way.<br>
&gt;     &gt;<br>
&gt;     &gt;     Just keep updated, install and run clamav every so often,<br>
&gt;     maybe install<br>
&gt;     &gt;     and configure tripwire/aide, do not download dodgy stuff,<br>
&gt;     follow and<br>
&gt;     &gt;     click random dodgy links. Same applies to any other operating<br>
&gt;     system<br>
&gt;     &gt;     really.<br>
&gt;     &gt;<br>
&gt;     &gt;     Compared to many other systems, GNU operating systems can<br>
&gt;     still have<br>
&gt;     &gt;     issues, but far less, and if they do the issue is fixed much<br>
&gt;     quicker.<br>
&gt;     &gt;<br>
&gt;     &gt;     Not much else to say really apart from Keep Calm and carry on!<br>
&gt;     &gt;<br>
&gt;     &gt;<br>
&gt;     &gt;     Regards,<br>
&gt;     &gt;<br>
&gt;     &gt;     Tristan<br>
&gt;     &gt;<br>
&gt;     &gt;     --<br>
&gt;     &gt;     Tristan Santore BSc MBCS<br>
&gt;     &gt;     TS4523-RIPE<br>
&gt;     &gt;     Network and Infrastructure Operations<br>
&gt;     &gt;     InterNexusConnect<br>
&gt;     &gt;     Mobile <a href="tel:%2B44-78-55069812" value="+447855069812">+44-78-55069812</a> &lt;tel:%2B44-78-55069812&gt;<br>
&gt;     &lt;tel:%2B44-78-55069812&gt;<br>
&gt;     &gt;     <a href="mailto:Tristan.Santore@internexusconnect.net">Tristan.Santore@internexusconnect.net</a><br>
&gt;     &lt;mailto:<a href="mailto:Tristan.Santore@internexusconnect.net">Tristan.Santore@internexusconnect.net</a>&gt;<br>
</div></div>&gt;     &gt;     &lt;mailto:<a href="mailto:Tristan.Santore@internexusconnect.net">Tristan.Santore@internexusconnect.net</a><br>
<div class="im">&gt;     &lt;mailto:<a href="mailto:Tristan.Santore@internexusconnect.net">Tristan.Santore@internexusconnect.net</a>&gt;&gt;<br>
&gt;     &gt;<br>
&gt;     &gt;     Former Thawte Notary<br>
&gt;     &gt;     (Please note: Thawte has closed its WoT programme down,<br>
&gt;     &gt;     and I am therefore no longer able to accredit trust)<br>
&gt;     &gt;<br>
&gt;     &gt;     For Fedora related issues, please email me at:<br>
&gt;     &gt;     <a href="mailto:TSantore@fedoraproject.org">TSantore@fedoraproject.org</a> &lt;mailto:<a href="mailto:TSantore@fedoraproject.org">TSantore@fedoraproject.org</a>&gt;<br>
</div>&gt;     &lt;mailto:<a href="mailto:TSantore@fedoraproject.org">TSantore@fedoraproject.org</a> &lt;mailto:<a href="mailto:TSantore@fedoraproject.org">TSantore@fedoraproject.org</a>&gt;&gt;<br>
<div class="im">&gt;     &gt;     --<br>
&gt;     &gt;     ambassadors mailing list<br>
&gt;     &gt;     <a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a><br>
&gt;     &lt;mailto:<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a>&gt;<br>
</div>&gt;     &gt;     &lt;mailto:<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a><br>
<div class="im">&gt;     &lt;mailto:<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a>&gt;&gt;<br>
&gt;     &gt;     <a href="https://admin.fedoraproject.org/mailman/listinfo/ambassadors" target="_blank">https://admin.fedoraproject.org/mailman/listinfo/ambassadors</a><br>
&gt;     &gt;<br>
&gt;     &gt;<br>
&gt;     &gt;<br>
&gt;     &gt;<br>
&gt;     &gt; --<br>
&gt;     &gt; ambassadors mailing list<br>
&gt;     &gt; <a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a><br>
</div>&gt;     &lt;mailto:<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a>&gt;<br>
<div><div class="h5">&gt;     &gt; <a href="https://admin.fedoraproject.org/mailman/listinfo/ambassadors" target="_blank">https://admin.fedoraproject.org/mailman/listinfo/ambassadors</a><br>
&gt;     As ambassador you should know better to make such definitive statements.<br>
&gt;     fact is we do not know any facts yet, so please do not make such views<br>
&gt;     public, especially as ambassador. People with less experience will look<br>
&gt;     for your guidance. So, provide them with facts, not fiction or innuendo.<br>
&gt;<br>
&gt;     The fact is, there have been viruses and the like, affecting GNU linux<br>
&gt;     based systems before, however, thanks to the way GNU linux systems work,<br>
&gt;     such as privilege separation and a &quot;secure&quot; source of software, issues<br>
&gt;     are far reduced.<br>
&gt;<br>
&gt;     I believe there were no more than a few hand full of viruses affecting<br>
&gt;     GNU operating systems, however I never found any research document<br>
&gt;     stating factual relevant numbers.<br>
&gt;     The main issue are remotely exploitable loopholes, found in pretty much<br>
&gt;     any software that has a listening port open to the outside world.<br>
&gt;     Browsers of course are included in this as they go around to unverified<br>
&gt;     locations. So, this might be the most likely source of catching a cold,<br>
&gt;     so to speak. However, as we now all use Instant Messaging and silly<br>
&gt;     (anti)social-networking, email hosted by third-parties, etc.. you<br>
&gt;     sometimes get emails/instant messages from &quot;friends&quot;, saying click here<br>
&gt;     or download this file, and it was not sent by your friend, even though<br>
&gt;     it came from his account. And there you go, you caught a cold.<br>
&gt;<br>
&gt;     So, by all means, do not assume stuff, because in most cases you will be<br>
&gt;     wrong.<br>
&gt;<br>
&gt;     It best to be vigilant and distrust everything, especially your own code<br>
&gt;     you are writing ;-p.<br>
&gt;<br>
&gt;     Regards,<br>
&gt;     Tristan<br>
&gt;<br>
&gt;     --<br>
&gt;     Tristan Santore BSc MBCS<br>
&gt;     TS4523-RIPE<br>
&gt;     Network and Infrastructure Operations<br>
&gt;     InterNexusConnect<br>
&gt;     Mobile <a href="tel:%2B44-78-55069812" value="+447855069812">+44-78-55069812</a> &lt;tel:%2B44-78-55069812&gt;<br>
&gt;     <a href="mailto:Tristan.Santore@internexusconnect.net">Tristan.Santore@internexusconnect.net</a><br>
&gt;     &lt;mailto:<a href="mailto:Tristan.Santore@internexusconnect.net">Tristan.Santore@internexusconnect.net</a>&gt;<br>
&gt;<br>
&gt;     Former Thawte Notary<br>
&gt;     (Please note: Thawte has closed its WoT programme down,<br>
&gt;     and I am therefore no longer able to accredit trust)<br>
&gt;<br>
&gt;     For Fedora related issues, please email me at:<br>
&gt;     <a href="mailto:TSantore@fedoraproject.org">TSantore@fedoraproject.org</a> &lt;mailto:<a href="mailto:TSantore@fedoraproject.org">TSantore@fedoraproject.org</a>&gt;<br>
&gt;     --<br>
&gt;     ambassadors mailing list<br>
&gt;     <a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a><br>
&gt;     &lt;mailto:<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a>&gt;<br>
&gt;     <a href="https://admin.fedoraproject.org/mailman/listinfo/ambassadors" target="_blank">https://admin.fedoraproject.org/mailman/listinfo/ambassadors</a><br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; ambassadors mailing list<br>
&gt; <a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a><br>
&gt; <a href="https://admin.fedoraproject.org/mailman/listinfo/ambassadors" target="_blank">https://admin.fedoraproject.org/mailman/listinfo/ambassadors</a><br>
</div></div>If you believe selinux prevents exploits, then you also factually<br>
incorrect. Selinux contains exploits and limits impact. Again, you are<br>
making assumptions. Please do not do that! Also, the fact that there are<br>
&quot;kits with exploits&quot; is quite irrelevant. What is relevant is, that no<br>
software is 100% secure, if anything the notion back in the day that<br>
image/video formats could not be exploited, also proved incorrect.<br>
<br>
So you see, nothing is secure, nothing will probably ever be 100%<br>
secure. Because we are human, we make errors and as such machines make<br>
them too.<br>
<div class="HOEnZb"><div class="h5"><br>
Regards,<br>
<br>
Tristan<br>
<br>
--<br>
Tristan Santore BSc MBCS<br>
TS4523-RIPE<br>
Network and Infrastructure Operations<br>
InterNexusConnect<br>
Mobile <a href="tel:%2B44-78-55069812" value="+447855069812">+44-78-55069812</a><br>
<a href="mailto:Tristan.Santore@internexusconnect.net">Tristan.Santore@internexusconnect.net</a><br>
<br>
Former Thawte Notary<br>
(Please note: Thawte has closed its WoT programme down,<br>
and I am therefore no longer able to accredit trust)<br>
<br>
For Fedora related issues, please email me at:<br>
<a href="mailto:TSantore@fedoraproject.org">TSantore@fedoraproject.org</a><br>
--<br>
ambassadors mailing list<br>
<a href="mailto:ambassadors@lists.fedoraproject.org">ambassadors@lists.fedoraproject.org</a><br>
<a href="https://admin.fedoraproject.org/mailman/listinfo/ambassadors" target="_blank">https://admin.fedoraproject.org/mailman/listinfo/ambassadors</a></div></div></blockquote></div><br>