From the Editor: January 2005 - Security on the Go

December 1st, 2004 by Don Marti in

Now that work is just a verb, not a place, are all your security assumptions wrong?
Your rating: None

It's time to question some security assumptions. Regular users' systems are always on an internal network with a firewall between them and the Internet. The only hosts reachable from the outside are a few bastion hosts. Bastion hosts run a strictly limited set of software, and only sysadmins have accounts on them. Computer security depends on physical security, because anyone who breaks into the server room can boot the server from a rescue disk and have his or her way with the files.

Meanwhile, in the real world, you have a copy of the project you're working on and a bunch of confidential e-mail on your laptop, and you're drinking La Minita at Dana Street Roasting Company while you peruse your project's Request Tracker and hold a Jabber meeting with people in three countries.

Public wireless cafés are a lot of great things, but secure corporate networks they're not. Because more and more companies would rather pay for laptops and drop-in office space than cubicles and desktops for all, you can wave bye-bye to the neat security chart with a bunch of stuff between the user and the menacing Internet Cloud.

Linux distributions are starting to offer good support for some encrypted partitions, which do the attacker no good without the key. Mike Petullo takes the process to its logical extreme and encrypts the root filesystem, which means you can encrypt everything (page 62).

The less we trust the network, the more we need encrypted e-mail. At Linux Journal, we rolled out GNU Privacy Guard (GPG) for everyone. Encrypted mail isn't the tweaky mess it used to be, now that the common mailers are integrating GPG support. Find out how to make secure mail a part of your work life in Roy Hoobler's article on page 52.

Now that everyone is outside all the time, the problem of removing unneeded software and keeping packages up to date is even more critical. Fortunately, many of the Linux distributions offer easy tools for installing new versions. Jeremy Turner shows off some screenshots on page 46. Meanwhile, we're still experimenting with SELinux, which could lock down even insecure versions of software to contain attacks. James Morris gives us a peek at the SELinux future on page 56.

The new mobile way of working isn't only a burden for sysadmins. Users often prefer to escape from cubicle-land. Why not make your company's Linux migration a productivity and multimedia treat, not a retraining chore? Just as Lincoln Durey's “Dear Laptop Vendor” was going to press in the fall of 2004, HP made the bold move of offering Linux preinstalled on a full-featured notebook computer. We had one at Linux Journal to try out, and yes, we're impressed. Get the details, including the results of a support call, on page 74.

Have fun keeping your systems secure for the real world, and if you see me editing the next issue at a coffeehouse, come over and say hi.

Don Marti is editor in chief of Linux Journal.

__________________________


Special Magazine Offer -- Free Gift with Subscription
Receive a free digital copy of Linux Journal's System Administration Special Edition as well as instant online access to current and past issues. CLICK HERE for offer

Linux Journal: delivering readers the advice and inspiration they need to get the most out of their Linux systems since 1994.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
justin's picture

HP drops Linux laptop - no replacement

On December 6th, 2004 justin (not verified) says:

I asked HP whether there was a replacement laptop with Suse Linux preinstalled - there isnt. All a bit strange considering the news coverage (and the reviews on numerous sites, including your own)

From: hpuk&i AT hp DOTcom

Thank you for your pre-sales enquiry to HP.

There is no replacement for the nx5000. There are no other notebooks with Suse Linux installed.

Anonymous's picture

Available in the USA

On December 6th, 2004 Anonymous (not verified) says:

The US order form is still showing the nx5000 with Linux. There are two instances of "HP recommends Microsoft® Windows® XP Professional" on the form, but that's just so they can keep getting the co-op marketing money from MSFT.

justin's picture

HP Linux laptop no longer sold?

On December 6th, 2004 justin (not verified) says:

"Just as Lincoln Durey's "Dear Laptop Vendor" was going to press in the fall of 2004, HP made the bold move of offering Linux preinstalled on a full-featured notebook computer. We had one at Linux Journal to try out, and yes, we're impressed. Get the details, including the results of a support call, on page 74."

i've just got word from HP in the UK that the HP nx5000 with Linux preinstalled has been discontinued. Maybe you'd like to follow that one up with HP.

Post new comment

Please note that comments may not appear immediately, so there is no need to repost your comment.
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <pre> <ul> <ol> <li> <dl> <dt> <dd> <i> <b>
  • Lines and paragraphs break automatically.

More information about formatting options

Newsletter

Each week Linux Journal editors will tell you what's hot in the world of Linux. You will receive late breaking news, technical tips and tricks, and links to in-depth stories featured on www.linuxjournal.com.
Sign up for our Email Newsletter

Tech Tip Videos

From the Magazine

July 2009, #183

News Flash: Linux Kernel 3.0 to include an on-the-go Expresso machine interface! Ok, maybe not, but Linux is definitely going mobile, from phones to e-readers. Find out more inside about Android, the Kindle 2, the Western Digital MyBook II, The Bug, and Indamixx (a portable recording studio). And if you've gone mobile and you been wanting more Emacs in your life then check out Conkeror.


To compliment the mobile we've got the stationary: parsing command line options with getopt, checking your Ruby code with metric_fu, and building a secure Squid proxy. How is this stationary you ask? What can we say? It's not. We just wanted to see if anybody actually read this part of the page :) .


All this and more, and all you have to do is get your hot sweaty hands on the latest copy of Linux Journal.





Read this issue