<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Open Source Security &#187; Planet LTC</title>
	<atom:link href="http://www.ratliff.net/blog/index.php/category/planet-ltc/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ratliff.net/blog</link>
	<description>A blog about open source and security and open source security</description>
	<pubDate>Wed, 28 May 2008 15:18:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Linux Blueprint - Protecting Data at Rest</title>
		<link>http://www.ratliff.net/blog/index.php/2008/05/28/linux-blueprint-protecting-data-at-rest/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/05/28/linux-blueprint-protecting-data-at-rest/#comments</comments>
		<pubDate>Wed, 28 May 2008 15:18:59 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/?p=74</guid>
		<description><![CDATA[My colleagues have written a comprehensive step-by-step guide to enabling disk encryption in your choice of RHEL 5.2 or SLES 10 SP2. This is pretty much as easy as it gets. If you have questions or comments about the paper, they also have an online forum for security discussions. I suggest the PDF version which [...]]]></description>
			<content:encoded><![CDATA[<p>My colleagues have written a comprehensive <a href="http://publib.boulder.ibm.com/infocenter/systems/topic/liaai/liaaiprotectdata.htm?tocNode=int_761">step-by-step guide</a> to enabling disk encryption in your choice of RHEL 5.2 or SLES 10 SP2. This is pretty much as easy as it gets. If you have questions or comments about the paper, they also have an <a href="http://www.ibm.com/developerworks/forums/forum.jspa?forumID=1271">online forum</a> for security discussions. I suggest the <a href="http://publib.boulder.ibm.com/infocenter/systems/topic/liaai/BPrhelsecurity.pdf">PDF version</a> which packages the whole (short) paper up into a single, easily consumable whole. </p>
<p>This document is just the first of the <a href="http://publib.boulder.ibm.com/infocenter/systems/topic/liaai/liaaiblueprint.htm?tocNode=int_92">new series of &#8220;Linux blueprints&#8221;</a> (step-by-step guides for accomplishing specific tasks with Linux) which will be published on the <a href="http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/linuxinformation/linuxparent.htm&#038;tocNode=int_10">IBM Systems Information Center</a> (Info Center).</p>
<p>Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/05/28/linux-blueprint-protecting-data-at-rest/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Red Hat Enterprise Linux 5.2 contains two security Technology Previews</title>
		<link>http://www.ratliff.net/blog/index.php/2008/05/21/red-hat-enterprise-linux-52-contains-two-security-technology-previews/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/05/21/red-hat-enterprise-linux-52-contains-two-security-technology-previews/#comments</comments>
		<pubDate>Wed, 21 May 2008 21:47:29 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[Products]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/?p=72</guid>
		<description><![CDATA[Red Hat Enterprise Linux 5.2 was released today. That is significant news in and of itself, but I am especially excited because it contains Technology Previews of  eCryptfs, TrouSerS, and tpm-tools! As Technology Previews, they are not yet supported for production use, but this is the first step to allow for experimentation and time [...]]]></description>
			<content:encoded><![CDATA[<p>Red Hat Enterprise Linux 5.2 was <a href="http://www.press.redhat.com/2008/05/21/red-hat-enterprise-linux-52/">released</a> today. That is significant news in and of itself, but I am especially excited because it contains Technology Previews of  <a href="http://ecryptfs.sourceforge.net/">eCryptfs</a>, <a href="http://trousers.sourceforge.net/">TrouSerS</a>, and tpm-tools! As Technology Previews, they are not yet supported for production use, but this is the first step to allow for experimentation and time for ripening. I&#8217;m happy to see Red Hat&#8217;s continued dedication to security. If you try these packages out in RHEL, I&#8217;d love to hear of any successes or problems that you encounter.</p>
<p>[1] <a href="http://www.press.redhat.com/2008/05/21/red-hat-enterprise-linux-52/">http://www.press.redhat.com/2008/05/21/red-hat-enterprise-linux-52/</a><br />
[2] <a href="http://ecryptfs.sourceforge.net/">http://ecryptfs.sourceforge.net/</a><br />
[3] <a href="http://trousers.sourceforge.net/">http://trousers.sourceforge.net/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/05/21/red-hat-enterprise-linux-52-contains-two-security-technology-previews/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Fedora users love SELinux</title>
		<link>http://www.ratliff.net/blog/index.php/2008/04/10/fedora-users-love-selinux/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/04/10/fedora-users-love-selinux/#comments</comments>
		<pubDate>Thu, 10 Apr 2008 17:19:15 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[metrics]]></category>

		<category><![CDATA[selinux]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2008/04/10/fedora-users-love-selinux/</guid>
		<description><![CDATA[Fedora Weekly News continues to be a(n unexpectedly) great source for security content. I&#8217;ve recently been cleaning up the backlog of my email and have discovered nuggets of valuable information such as 
94% of Fedora 8 installs have SELinux enabled
in Fedora Weekly News Issue 121 (Feb. 18, 2008). Now if you read the article, the [...]]]></description>
			<content:encoded><![CDATA[<p>Fedora Weekly News continues to be a(n unexpectedly) great source for security content. I&#8217;ve recently been cleaning up the backlog of my email and have discovered nuggets of valuable information such as </p>
<p><strong>94% of Fedora 8 installs have SELinux enabled</strong></p>
<p>in <a href="http://fedoraproject.org/wiki/FWN/Issue121#head-35d6cd0e48a356c31336109690072f3116231d24">Fedora Weekly News Issue 121</a> (Feb. 18, 2008). Now if you read the article, the number I selected to highlight is the raw number that James got off-list. 47%, 50%, and 74% were also tossed out there. Dan Walsh said that the statistics are misleading but being improved and Yaakov Nemoy says that smolt only measures 10% of Fedora machines. So, they are still working out the details. Even so, what they have measured so far is a quite a bit different from the statistics that we see about enterprise customers. I expect it is probably because Fedora users are satisfied with a completely open source stack and do not install as many 3rd party ISV applications which are not as integrated and do not have application specific SELinux policy. Still, this is an incredibly encouraging statistic. Once the Fedora community has been collecting the statistics a little longer, collects whether SELinux is enforcing or not, and starts publicizing these statistics widely, they may be able to help drive ISV adoption (or at least tolerance) of SELinux which will encourage commercial customers to follow the Fedora wave of early adopters on short order.</p>
<p>P.S. Yes, the title is tongue in cheek with a nod to the guys who participated in the discussion.</p>
<p><a href="http://fedoraproject.org/wiki/FWN/Issue121">http://fedoraproject.org/wiki/FWN/Issue121</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/04/10/fedora-users-love-selinux/feed/</wfw:commentRss>
		</item>
		<item>
		<title>So, would you call it SESolaris? SEOpenSolaris?</title>
		<link>http://www.ratliff.net/blog/index.php/2008/03/05/so-would-you-call-it-sesolaris-seopensolaris/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/03/05/so-would-you-call-it-sesolaris-seopensolaris/#comments</comments>
		<pubDate>Wed, 05 Mar 2008 22:46:20 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[community]]></category>

		<category><![CDATA[open source]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[selinux]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2008/03/05/so-would-you-call-it-sesolaris-seopensolaris/</guid>
		<description><![CDATA[In a major validation of the FLASK architecture, the OpenSolaris community has created a new project called Flexible Mandatory Access Control (fmac) to adapt the FLASK architecture to OpenSolaris. (The FLASK architecture that is the basis for SELinux.) Stephen Smalley will be one of the community leads. OSNews picked up the email thread today with [...]]]></description>
			<content:encoded><![CDATA[<p>In a major validation of the FLASK architecture, the OpenSolaris community has created a <a href="http://www.opensolaris.org/os/project/fmac/">new project</a> called <a href=" http://www.opensolaris.org/jive/thread.jspa?messageID=204568&#204568">Flexible Mandatory Access Control (fmac)</a> to adapt the FLASK architecture to OpenSolaris. (The FLASK architecture that is the basis for SELinux.) Stephen Smalley will be one of the community leads. <a href="http://www.osnews.com/thread?303491 ">OSNews</a> picked up the email thread today with some interesting comments. </p>
<p>James Morris notes related work in his <a href="http://james-morris.livejournal.com/2008/03/05/">blog posting from this morning</a> and offers to help the community preserve interoperability with SELinux. </p>
<p>Personally, I would be delighted to see widespread adoption of the FLASK architecture lead to usability improvements and complexity reduction across the board. </p>
<p>[1] <a href="http://www.opensolaris.org/os/project/fmac/">http://www.opensolaris.org/os/project/fmac/</a><br />
[2] <a href=" http://www.opensolaris.org/jive/thread.jspa?messageID=204568&#204568"> http://www.opensolaris.org/jive/thread.jspa?messageID=204568&#204568</a><br />
[3] <a href="http://www.osnews.com/thread?303491 ">http://www.osnews.com/thread?303491 </a><br />
[4] <a href="http://james-morris.livejournal.com/2008/03/05/">http://james-morris.livejournal.com/2008/03/05/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/03/05/so-would-you-call-it-sesolaris-seopensolaris/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New Article on Polyinstantiation at developerWorks</title>
		<link>http://www.ratliff.net/blog/index.php/2008/02/29/new-article-on-polyinstantiation-at-developerworks/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/02/29/new-article-on-polyinstantiation-at-developerworks/#comments</comments>
		<pubDate>Fri, 29 Feb 2008 23:33:51 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2008/02/29/new-article-on-polyinstantiation-at-developerworks/</guid>
		<description><![CDATA[One of the cool new features included in Red Hat Enterprise Linux 5 was VFS polyinstantiation. This work was in support of the Multi Level Security configuration. It allows files to exist in a directory at different security classifications. The subset of files visible to the user depends on the user&#8217;s clearance. There is an [...]]]></description>
			<content:encoded><![CDATA[<p>One of the cool new features included in Red Hat Enterprise Linux 5 was VFS polyinstantiation. This work was in support of the Multi Level Security configuration. It allows files to exist in a directory at different security classifications. The subset of files visible to the user depends on the user&#8217;s clearance. There is an excellent description of the functionality in both section 4.1.2 of <a href="http://download.boulder.ibm.com/ibmdl/pub/software/dw/linux/lspp-rbac.pdf">Extending Linux for Multi-Level Security</a> by Klaus Weidner, George Wilson and Loula Salem, as well as Russell Coker&#8217;s article <a href="http://www.coker.com.au/selinux/talks/sage-2006/PolyInstantiatedDirectories.html">Polyinstantiation of directories in an SELinux system</a>.</p>
<p>Now there is an excellent new article on <a href="http://www.ibm.com/developerworks/linux">developerWorks</a> by Robb Romans <a href="http://www.ibm.com/developerworks/linux/library/l-polyinstantiation/">Improving Security with polyinstantiation</a> which describes in simple and detailed terms how administrators can polyinstantiate /tmp (and other world writable directories) to help prevent attacks through /tmp. This technique usable whether or not SELinux is enabled. This article helps answer calls for the complete elimination of world writable directories so as to defeat resource exhaustion attacks (quotas were described as &#8220;non-optimal&#8221;). One can instead use the method described in this paper to polyinstantiate world writable directories to completely different devices to effectively eliminate the attack. (Yes, they grok TMPDIR. And, yes, unfortunately there are customers who won&#8217;t use SELinux.)</p>
<p>So if you were wondering how you can get your feet wet with polyinstantiation, give the steps described in Robb&#8217;s article a try.</p>
<p>[1] <a href="http://download.boulder.ibm.com/ibmdl/pub/software/dw/linux/lspp-rbac.pdf">http://download.boulder.ibm.com/ibmdl/pub/software/dw/linux/lspp-rbac.pdf</a><br />
[2] <a href="http://www.coker.com.au/selinux/talks/sage-2006/PolyInstantiatedDirectories.html">http://www.coker.com.au/selinux/talks/sage-2006/PolyInstantiatedDirectories.html</a><br />
[3] <a href="http://www.ibm.com/developerworks/linux">http://www.ibm.com/developerworks/linux</a><br />
[4] <a href="http://www.ibm.com/developerworks/linux/library/l-polyinstantiation/">http://www.ibm.com/developerworks/linux/library/l-polyinstantiation/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/02/29/new-article-on-polyinstantiation-at-developerworks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Not with a bang, but a whimper</title>
		<link>http://www.ratliff.net/blog/index.php/2008/02/14/not-with-a-bang-but-a-whimper/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/02/14/not-with-a-bang-but-a-whimper/#comments</comments>
		<pubDate>Fri, 15 Feb 2008 04:04:38 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[Products]]></category>

		<category><![CDATA[community]]></category>

		<category><![CDATA[open source]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2008/02/14/not-with-a-bang-but-a-whimper/</guid>
		<description><![CDATA[Roy Fielding[1] finally quit the OpenSolaris community today, see his resignation letter[2]. The kettle finally boiled over and the realization come to many (but not all) that Sun is publishing their Solaris code for marketing purposes, rather than creating an independent, community-led, open source project with the ability to make real decisions. 
It seemed so [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Roy_Fielding">Roy Fielding</a>[1] finally quit the OpenSolaris community today, see <a href="http://mail.opensolaris.org/pipermail/ogb-discuss/2008-February/004488.html">his resignation letter</a>[2]. The kettle finally boiled over and the realization come to many (but not all) that Sun is publishing their Solaris code for marketing purposes, rather than creating an independent, community-led, open source project with the ability to make real decisions. </p>
<p>It seemed so promising at first: &#8220;[T]hey made promises about it being an open development project. &#8230; Sun gave up its right to make arbitrary decisions regarding the phrase &#8216;OpenSolaris&#8217; as part of its public agreement with the community in the form of the Charter.  That was a self-imposed restriction in exchange for the benefits of community-driven development, freely made, and cannot be changed except in accordance with the charter itself (for example, by amending or dissolving the charter).&#8221; (excerpt from Roy Fielding&#8217;s resignation letter) But it was a sham: &#8220;The charter has therefore been violated. &#8230; Sun agreed that &#8216;OpenSolaris&#8217; would be governed by the community and yet has refused, in every step along the way, to cede any real control over the software produced or the way it is produced, and continues to make private decisions every day that are later promoted as decisions for this thing we call OpenSolaris.&#8221; (excerpt from Roy Fielding&#8217;s resignation letter)</p>
<p>To be fair, most developers recognized the community as a sham right away merely based on the copyright and patent assignments required by the contributors agreement[3]. To date, Sun has received 578 patches[4], which represents a rate of 0.6 patches a day (first patch dated 6/17/05, there were some earlier undated contributions). Linus gets more patches while he is brushing his teeth than OpenSolaris gets in a week. Despite Roy&#8217;s efforts to build a real community, contributing to OpenSolaris always has been and seemingly always will be, corporate welfare.</p>
<p>For me, the realization that Sun just doesn&#8217;t get it, and never will, was crystallized the day I was turned away from an OpenSolaris Users&#8217; Group meeting for refusing to sign an NDA. </p>
<p>It is a credit to the Solaris engineers that a few hearty souls want to soldier on amidst the wreckage: &#8220;Nonetheless I believe the time has come for a reboot and I am looking for other like-minded people to stand and form a full Board for positive change.&#8221;[5] And others who are even contemplating forking: &#8220;We will need to build out our infrastructure so that we can host development, mailing-lists and etc.. Once that is done, we will need to make the case to start moving development to the new organization/infrstructure. This will mean that even Sun employees will have to chose to move their development work to a community &#8216;controlled&#8217; development infrastructure.&#8221;[6] It is to them, that I dedicate the title.</p>
<p>[1] <a href="http://en.wikipedia.org/wiki/Roy_Fielding">http://en.wikipedia.org/wiki/Roy_Fielding</a><br />
[2] <a href="http://mail.opensolaris.org/pipermail/ogb-discuss/2008-February/004488.html">http://mail.opensolaris.org/pipermail/ogb-discuss/2008-February/004488.html</a><br />
[3] <a href="http://www.opensolaris.org/os/about/sun_contributor_agreement/">http://www.opensolaris.org/os/about/sun_contributor_agreement/</a><br />
[4]<a href="http://www.opensolaris.org/os/bug_reports/request_sponsor/">http://www.opensolaris.org/os/bug_reports/request_sponsor/</a><br />
[5] <a href="http://mail.opensolaris.org/pipermail/ogb-discuss/2008-February/004487.html">http://mail.opensolaris.org/pipermail/ogb-discuss/2008-February/004487.html</a> (Yes, the author of this email is a Sun employee.)<br />
[6] <a href="http://mail.opensolaris.org/pipermail/ogb-discuss/2008-February/004477.html">http://mail.opensolaris.org/pipermail/ogb-discuss/2008-February/004477.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/02/14/not-with-a-bang-but-a-whimper/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Hal Finney&#8217;s Experimental Privacy CA</title>
		<link>http://www.ratliff.net/blog/index.php/2008/01/14/hal-finneys-experimental-privacy-ca/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/01/14/hal-finneys-experimental-privacy-ca/#comments</comments>
		<pubDate>Mon, 14 Jan 2008 21:34:52 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2008/01/14/hal-finneys-experimental-privacy-ca/</guid>
		<description><![CDATA[A longstanding limitation of doing remote attestation between &#8220;strangers&#8221; has been eased through some experimental work that Hal Finney recently announced on the TrouSerS user&#8217;s list. Hal has announced that he has created a Privacy CA at PrivacyCA.com. Question 2.1 of the TrouSerS FAQ contains a graphic showing the prerequisite pieces for doing remote attestation. [...]]]></description>
			<content:encoded><![CDATA[<p>A longstanding limitation of doing remote attestation between &#8220;strangers&#8221; has been eased through some experimental work that <a href="http://sourceforge.net/mailarchive/forum.php?thread_name=da7b3ce30801131643j74be4064l52daa8c0e90efa83%40mail.gmail.com&#038;forum_name=trousers-users">Hal Finney recently announced</a> on the TrouSerS user&#8217;s list. Hal has announced that he has created a Privacy CA at <a href="http://privacyca.com/">PrivacyCA.com</a>. <a href="http://trousers.sourceforge.net/faq.html#2.1">Question 2.1 of the TrouSerS FAQ</a> contains a graphic showing the prerequisite pieces for doing remote attestation. Hal has filled in the Privacy CA and notes that Infineon does supply the Endorsement Credential. He also provides a &#8220;test and debug mode&#8221; so that users of other TPMs can still experiment with the service without the guarantee that they are using real TPMs. Up to now, attestation keys had to be exchanged via sneaker net (manual exchange and verification before attestation was possible) to enable machines to do remote attestation. Hal&#8217;s announcement represents a great leap forward in the usefulness of TPMs.</p>
<p>1. <a href="http://sourceforge.net/mailarchive/forum.php?thread_name=da7b3ce30801131643j74be4064l52daa8c0e90efa83%40mail.gmail.com&#038;forum_name=trousers-users">http://sourceforge.net/mailarchive/forum.php?<br />
thread_name=da7b3ce30801131643j74be4064l52daa8c0e90efa83%40mail.gmail.com&#038;forum_name=trousers-users</a><br />
2. <a href="http://privacyca.com/">PrivacyCA.com</a><br />
2. <a href="http://trousers.sourceforge.net/faq.html#2.1">http://trousers.sourceforge.net/faq.html#2.1</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/01/14/hal-finneys-experimental-privacy-ca/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Yellow Journalism and Software Bugs</title>
		<link>http://www.ratliff.net/blog/index.php/2008/01/09/yellow-journalism-and-software-bugs/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/01/09/yellow-journalism-and-software-bugs/#comments</comments>
		<pubDate>Wed, 09 Jan 2008 17:51:21 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[metrics]]></category>

		<category><![CDATA[open source]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2008/01/09/yellow-journalism-and-software-bugs/</guid>
		<description><![CDATA[Oh boy, I thought I had quibbles with the news story on the Coverity announcement yesterday and today someone points out the worst piece of yellow journalism that I have seen in quite some time: Open  Source Code Contains Security Holes. First the title is atrocious and this quote &#8220;the popular open source backup [...]]]></description>
			<content:encoded><![CDATA[<p>Oh boy, I thought I had quibbles with the news story on the Coverity announcement yesterday and today someone points out the worst piece of yellow journalism that I have seen in quite some time: <a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=205600229">Open  Source Code Contains Security Holes</a>. First the title is atrocious and this quote &#8220;the popular open source backup and recovery software running on half a million servers, were all found to have dozens or hundreds of security exposures and quality defects&#8221; may (have) be(en) accurate, but without context sounds worse than it really is. The truth, as George Wilson said, is that this is an article along the lines &#8220;And in other news, fire is hot and water is wet.&#8221; I personally consider this irresponsible journalism. They had to willfully ignore older stories based on information from Coverity and Carnegie Mellon such as <a href="http://www.linuxtoday.com/developer/2006031800826OSCYDV">Open Scrutiny of Open Source Code</a> which contains the nugget &#8220;The average defect rate of the open source applications was 0.434 bugs per 1000 lines of code. This compares with an average defect rate of 20 to 30 bugs per 1000 lines of code for commercial software, according to Carnegie Mellon University&#8217;s CyLab Sustainable Computing Consortium.&#8221; This is simply yellow journalism whose primary intention is to drive traffic and raise the ire of open source fans! Harrumph! Outrageous! </p>
<p>Note to Charles Babcock: software has bugs, even security bugs. If you want to drive down the number of bugs in the software that you are using, use open source. </p>
<p>This type of crappy response comes up almost every time Coverity announces a significant improvement. See this similar news story from ZDNet back in October 2006: <a href="http://blogs.zdnet.com/open-source/?p=809">Most open source is better</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/01/09/yellow-journalism-and-software-bugs/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Coverity Announces that 11 Open Source Project have achieved &#8220;Rung 2&#8243;</title>
		<link>http://www.ratliff.net/blog/index.php/2008/01/08/coverity-announces-that-11-open-source-project-have-achieved-rung-2/</link>
		<comments>http://www.ratliff.net/blog/index.php/2008/01/08/coverity-announces-that-11-open-source-project-have-achieved-rung-2/#comments</comments>
		<pubDate>Tue, 08 Jan 2008 22:11:50 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[metrics]]></category>

		<category><![CDATA[open source]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2008/01/08/coverity-announces-that-11-open-source-project-have-achieved-rung-2/</guid>
		<description><![CDATA[Coverity has announced &#8220;Rung 2&#8243; and that 11 open source projects have achieved &#8220;Rung 2&#8243;. This means that they have resolved all Rung 1 defects found by the latest release of Coverity Prevent. There is news coverage at news.com: 11 open-source projects certified as secure which claims that the projects &#8220;have been certified as free [...]]]></description>
			<content:encoded><![CDATA[<p>Coverity has <a href="http://scan.coverity.com/">announced &#8220;Rung 2&#8243;</a> and that 11 open source projects have achieved &#8220;Rung 2&#8243;. This means that they have resolved all Rung 1 defects found by the latest release of Coverity Prevent. There is news coverage at news.com: <a href="http://www.news.com/8301-10784_3-9843682-7.html?tag=nefd.top ">11 open-source projects certified as secure</a> which claims that the projects &#8220;have been certified as free of security defects&#8221;. The 11 projects with bragging rights are Amanda, NTP, OpenPAM, OpenVPN, Overdose, Perl, PHP, Postfix, Python, Samba, and TCL. The Coverity announcement itself says &#8220;resolved all of the defects identified at Rung 1&#8243;. Looking at the <a href="http://scan.coverity.com/">Rung 2</a> page, it appears to me that there are uninspected defects remaining at Rung 2 which may or may not represent actual defects (and/or actual security flaws), so I&#8217;m not sure that the news article&#8217;s claim is justified. I also would quibble with the use of the word &#8220;certified&#8221; which is at risk of becoming overused and rendered meaningless when applied in this context. Despite my quibbles with the news story, Coverity has done us all a major service by exercising their excellent source scanning tools on hundreds of open source projects and reporting the results in a controlled fashion. The 11 projects: Amanda, NTP, OpenPAM, OpenVPN, Overdose, Perl, PHP, Postfix, Python, Samba, and TCL, have done themselves proud by grinding through the reports and fixing defects found. Thanks to Homeland Security for sponsoring this effort, I appreciate this use of taxpayer money. Congratulations and a hearty Thanks! to Coverity and Amanda, NTP, OpenPAM, OpenVPN, Overdose, Perl, PHP, Postfix, Python, Samba, and TCL!</p>
<p>http://scan.coverity.com/<br />
http://www.news.com/8301-10784_3-9843682-7.html?tag=nefd.top<br />
http://scan.coverity.com/rung2.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2008/01/08/coverity-announces-that-11-open-source-project-have-achieved-rung-2/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New book on Trusted Computing</title>
		<link>http://www.ratliff.net/blog/index.php/2007/12/19/new-book-on-trusted-computing/</link>
		<comments>http://www.ratliff.net/blog/index.php/2007/12/19/new-book-on-trusted-computing/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 21:59:18 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[Products]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2007/12/19/new-book-on-trusted-computing/</guid>
		<description><![CDATA[Current and former co-workers, Kent Yoder, Dave Challener, Ryan Catherman, Dave Safford, and Leedert van Doorn have written a book called A Practical Guide to Trusted Computing. It&#8217;s now available for pre-order on Amazon and will available on Jan. 7, 2008. The authors have been instrumental in the creation of the TCG specs and key [...]]]></description>
			<content:encoded><![CDATA[<p>Current and former co-workers, Kent Yoder, Dave Challener, Ryan Catherman, Dave Safford, and Leedert van Doorn have written a book called <code>A Practical Guide to Trusted Computing</code>. It&#8217;s now available for pre-order on Amazon and will available on Jan. 7, 2008. The authors have been instrumental in the creation of the TCG specs and key open source software, for example, Dave led the TSS Working Group for years and Leendert was on the Board of Directors. I reviewed an early copy of the book almost exactly a year ago. My favorite parts of the version that I read were the chapters on TSS along with the sample code for how to use the TSS API and the chapter on use cases for Trusted Computing (for the sheer fun of it). I think that it definitely lives up to its billing as a practical guide and it provides a complete grounding in the concepts of trust, attestation, measurement, etc. that are foundational to Trusted Computing. It is very readable and is a faster read and shorter than it seems because of the reference information included. I haven&#8217;t yet seen the ultimate version of the book, but I&#8217;m eagerly awaiting my copy from Amazon. Congratulations to the authors for sticking through the long haul and providing such a useful book!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/index.php/2007/12/19/new-book-on-trusted-computing/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
