Linux Leader Expounds on His Colorful Comments

Somewhat known for his vivid — and sometimes vituperative — commentary, Linus Torvalds is no stranger to controversy. That experience may do him well this week, as the torches and pitchforks have come out and are marching his way after an interview with Network World reignited the flames fanned by last month's colorful commentary on security.

Just over a month ago, a message from the Hacker-in-Chief hit the Linux kernel mailing list with a detailed description of just how Mr. Torvalds feels about "security people" and the culture they promote. The message — which included such memorable phrases as "a bunch of masturbating monkeys" — caused an uproar among security advocates, particularly in the OpenBSD community, which was singled out by name.

The controversy is back on the front pages this week, as Linus rehashed the issue in his Network World interview, saying he's fed up with the "security circus," describing it as PR posturing on the part of two different, but equally irritating, camps. On one side, he says, are those who want total secrecy, refusing to disclose any bug until it has been patched, and on the other are those who "revel" in finding and disclosing bugs, which he attributes to a desire to embarrass vendors — "proof that the vendors are corrupt and crap, which admittedly mostly are." Torvalds described both groups as "crazy" and "idiots" more interested in the publicity surrounding their work than actually patching the vulnerabilities.

Linus says he practices a middle path — "the Unix model" — where bugs are reported privately, but are not kept secret indefinitely, vendors are compelled to patch vulnerabilities, without being publicly shamed, and the focus remains on fixing bugs and produces as little fanfare as possible. While that may certainly be the case for kernel bugs, "as little fanfare as possible" certainly doesn't describe the reception of his comments.


Justin Ryan is a Contributing Editor for Linux Journal.

One Click, Universal Protection: Implementing Centralized Security Policies on Linux Systems

As Linux continues to play an ever increasing role in corporate data centers and institutions, ensuring the integrity and protection of these systems must be a priority. With 60% of the world's websites and an increasing share of organization's mission-critical workloads running on Linux, failing to stop malware and other advanced threats on Linux can increasingly impact an organization's reputation and bottom line.

Learn More

Sponsored by Bit9

Linux Backup and Recovery Webinar

Most companies incorporate backup procedures for critical data, which can be restored quickly if a loss occurs. However, fewer companies are prepared for catastrophic system failures, in which they lose all data, the entire operating system, applications, settings, patches and more, reducing their system(s) to “bare metal.” After all, before data can be restored to a system, there must be a system to restore it to.

In this one hour webinar, learn how to enhance your existing backup strategies for better disaster recovery preparedness using Storix System Backup Administrator (SBAdmin), a highly flexible bare-metal recovery solution for UNIX and Linux systems.

Learn More

Sponsored by Storix