From the Editor - Security
You can talk about cost savings, performance and flexibility all you want, but the advantage driving more and more companies toward Linux is security. Just look how much time the big cheeses in the proprietary OS business spend telling the media about their catch-up plans. Thanks to some bad mistakes in the design of one vendor's browser and mail client, CIOs are asking vendors for Linux answers faster than the vendors were expecting.
Some OSes are born ubiquitous, others attain ubiquity and Linux is having ubiquity thrust upon it. Customer pull is nothing new to the Linux vendors, and they'll cope. And for you, the Linux professional, it's opening night at the big show. Everyone bought a ticket to see the amazing singing, dancing, secure operating system. They're waiting for the curtain to go up, and you're the stage manager.
Don't panic. Security depends more on policies and attention to detail than on any program or product. And you have a secret weapon. As you move more systems to Linux, you can start enforcing more secure policies and conceal the changes in the smoke and mirrors of the OS migration. If anyone points out that you could relax security to the way you had it in your old OS, you can say “that's the way it's normally done under Linux.” Yes, Linux will get some of the credit for your good decisions, but you'll get credit for putting in Linux.
Everyone will tell you to run Nmap to keep track of open ports and get an early warning of unnecessary or misconfigured software, but when you're keeping track of thousands of systems, that's a lot of data to watch. Log your Nmap data to an SQL database with Hasnain Atique's article on page 56.
Makan Pourzandi and Axelle Apvrille are bringing security to the Linux cluster environment (page 64). If you're sharing a cluster among multiple project teams, have a look.
SELinux is one of the most promising developments in Linux security, and it's worth keeping an eye on. No more will an attacker be able to “get root” on a whole system by compromising one dæmon. I'm planning to use SELinux at first for simple bastion hosts such as name servers, then add it to other systems as the administration tools get better. SELinux is complicated, though, so watch Linux Journal for more articles about it. James Morris explains SELinux and filesystems on page 22.
Finally, we normally don't bother with making fun of proprietary operating systems, because we're just quietly replacing them and interoperating with them where they're still in use. But Marcel Gagné got a little too annoyed by the latest batch of worms targeting other OSes that clobbered his network, so he blew off a little steam with some games on page 30. Have fun, keep your systems secure and enjoy the issue.
Don Marti is editor in chief of Linux Journal.
Realizing the promise of Apache® Hadoop® requires the effective deployment of compute, memory, storage and networking to achieve optimal results. With its flexibility and multitude of options, it is easy to over or under provision the server infrastructure, resulting in poor performance and high TCO. Join us for an in depth, technical discussion with industry experts from leading Hadoop and server companies who will provide insights into the key considerations for designing and deploying an optimal Hadoop cluster.
Sponsored by AMD
If you already use virtualized infrastructure, you are well on your way to leveraging the power of the cloud. Virtualization offers the promise of limitless resources, but how do you manage that scalability when your DevOps team doesn’t scale? In today’s hypercompetitive markets, fast results can make a difference between leading the pack vs. obsolescence. Organizations need more benefits from cloud computing than just raw resources. They need agility, flexibility, convenience, ROI, and control.
Stackato private Platform-as-a-Service technology from ActiveState extends your private cloud infrastructure by creating a private PaaS to provide on-demand availability, flexibility, control, and ultimately, faster time-to-market for your enterprise.
Sponsored by ActiveState
| Speed Up Your Web Site with Varnish | Jun 19, 2013 |
| Non-Linux FOSS: libnotify, OS X Style | Jun 18, 2013 |
| Containers—Not Virtual Machines—Are the Future Cloud | Jun 17, 2013 |
| Lock-Free Multi-Producer Multi-Consumer Queue on Ring Buffer | Jun 12, 2013 |
| Weechat, Irssi's Little Brother | Jun 11, 2013 |
| One Tail Just Isn't Enough | Jun 07, 2013 |
- Speed Up Your Web Site with Varnish
- Containers—Not Virtual Machines—Are the Future Cloud
- Linux Systems Administrator
- Lock-Free Multi-Producer Multi-Consumer Queue on Ring Buffer
- Non-Linux FOSS: libnotify, OS X Style
- Senior Perl Developer
- Technical Support Rep
- UX Designer
- Web & UI Developer (JavaScript & j Query)
- RSS Feeds
- Reply to comment | Linux Journal
1 hour 3 min ago - Reply to comment | Linux Journal
5 hours 3 min ago - Yeah, user namespaces are
6 hours 19 min ago - Cari Uang
9 hours 50 min ago - user namespaces
12 hours 44 min ago - yea
13 hours 10 min ago - One advantage with VMs
15 hours 38 min ago - about info
16 hours 11 min ago - info
16 hours 12 min ago - info
16 hours 13 min ago
Featured Jobs
| Linux Systems Administrator | Houston and Austin, Texas | Host Gator |
| Senior Perl Developer | Austin, Texas | Host Gator |
| Technical Support Rep | Houston and Austin, Texas | Host Gator |
| UX Designer | Austin, Texas | Host Gator |
| Web & UI Developer (JavaScript & j Query) | Austin, Texas | Host Gator |
Free Webinar: Hadoop
How to Build an Optimal Hadoop Cluster to Store and Maintain Unlimited Amounts of Data Using Microservers
Realizing the promise of Apache® Hadoop® requires the effective deployment of compute, memory, storage and networking to achieve optimal results. With its flexibility and multitude of options, it is easy to over or under provision the server infrastructure, resulting in poor performance and high TCO. Join us for an in depth, technical discussion with industry experts from leading Hadoop and server companies who will provide insights into the key considerations for designing and deploying an optimal Hadoop cluster.
Some of key questions to be discussed are:
- What is the “typical” Hadoop cluster and what should be installed on the different machine types?
- Why should you consider the typical workload patterns when making your hardware decisions?
- Are all microservers created equal for Hadoop deployments?
- How do I plan for expansion if I require more compute, memory, storage or networking?




Comments
Re: From the Editor -- October 2004: Security
"Several sites noted that migration to Open Source desktops provided an opportunity for revising work practices and operational standards, as well as procedures for administration, system management and security."
Her Majesty's Open Source report
Re: From the Editor -- October 2004: Security
The coming years are going to be testing times for GNU/Linux for sure, it can only attract more attention from "evil doers". The Linux community needs to keep, and enforce, the "security as a process" policy we have all practiced since day one, and then educate new arrivals on doing the same.
A closer look at SELinux would be greatly appreciated!
Re: From the Editor -- October 2004: Security
This is what Linux is all about. I do not know whether we should be happy or sad, that nobody noticed this article. One thing is obvious though, those that care do not advertise their identities, and more importantly do not wish to reveal more than is needed to the flies circling the honey pot.