From the Editor - Security
You can talk about cost savings, performance and flexibility all you want, but the advantage driving more and more companies toward Linux is security. Just look how much time the big cheeses in the proprietary OS business spend telling the media about their catch-up plans. Thanks to some bad mistakes in the design of one vendor's browser and mail client, CIOs are asking vendors for Linux answers faster than the vendors were expecting.
Some OSes are born ubiquitous, others attain ubiquity and Linux is having ubiquity thrust upon it. Customer pull is nothing new to the Linux vendors, and they'll cope. And for you, the Linux professional, it's opening night at the big show. Everyone bought a ticket to see the amazing singing, dancing, secure operating system. They're waiting for the curtain to go up, and you're the stage manager.
Don't panic. Security depends more on policies and attention to detail than on any program or product. And you have a secret weapon. As you move more systems to Linux, you can start enforcing more secure policies and conceal the changes in the smoke and mirrors of the OS migration. If anyone points out that you could relax security to the way you had it in your old OS, you can say “that's the way it's normally done under Linux.” Yes, Linux will get some of the credit for your good decisions, but you'll get credit for putting in Linux.
Everyone will tell you to run Nmap to keep track of open ports and get an early warning of unnecessary or misconfigured software, but when you're keeping track of thousands of systems, that's a lot of data to watch. Log your Nmap data to an SQL database with Hasnain Atique's article on page 56.
Makan Pourzandi and Axelle Apvrille are bringing security to the Linux cluster environment (page 64). If you're sharing a cluster among multiple project teams, have a look.
SELinux is one of the most promising developments in Linux security, and it's worth keeping an eye on. No more will an attacker be able to “get root” on a whole system by compromising one dæmon. I'm planning to use SELinux at first for simple bastion hosts such as name servers, then add it to other systems as the administration tools get better. SELinux is complicated, though, so watch Linux Journal for more articles about it. James Morris explains SELinux and filesystems on page 22.
Finally, we normally don't bother with making fun of proprietary operating systems, because we're just quietly replacing them and interoperating with them where they're still in use. But Marcel Gagné got a little too annoyed by the latest batch of worms targeting other OSes that clobbered his network, so he blew off a little steam with some games on page 30. Have fun, keep your systems secure and enjoy the issue.
Don Marti is editor in chief of Linux Journal.
|Happy Birthday Linux||Aug 25, 2016|
|ContainerCon Vendors Offer Flexible Solutions for Managing All Your New Micro-VMs||Aug 24, 2016|
|Updates from LinuxCon and ContainerCon, Toronto, August 2016||Aug 23, 2016|
|NVMe over Fabrics Support Coming to the Linux 4.8 Kernel||Aug 22, 2016|
|What I Wish I’d Known When I Was an Embedded Linux Newbie||Aug 18, 2016|
|Pandas||Aug 17, 2016|
- Happy Birthday Linux
- Download "Linux Management with Red Hat Satellite: Measuring Business Impact and ROI"
- ContainerCon Vendors Offer Flexible Solutions for Managing All Your New Micro-VMs
- What I Wish I’d Known When I Was an Embedded Linux Newbie
- Updates from LinuxCon and ContainerCon, Toronto, August 2016
- NVMe over Fabrics Support Coming to the Linux 4.8 Kernel
- New Version of GParted
- Tor 0.2.8.6 Is Released
- All about printf
With all the industry talk about the benefits of Linux on Power and all the performance advantages offered by its open architecture, you may be considering a move in that direction. If you are thinking about analytics, big data and cloud computing, you would be right to evaluate Power. The idea of using commodity x86 hardware and replacing it every three years is an outdated cost model. It doesn’t consider the total cost of ownership, and it doesn’t consider the advantage of real processing power, high-availability and multithreading like a demon.
This ebook takes a look at some of the practical applications of the Linux on Power platform and ways you might bring all the performance power of this open architecture to bear for your organization. There are no smoke and mirrors here—just hard, cold, empirical evidence provided by independent sources. I also consider some innovative ways Linux on Power will be used in the future.Get the Guide