Re: Writes to mounted devices containing file-systems.

Alan Cox (alan@lxorguk.ukuu.org.uk)
Fri, 10 Aug 2001 14:07:50 +0100 (BST)


> Aug 10 08:05:18 quark sendmail[66]: rejecting connections on daemon MTA: load average: 16
> Aug 10 08:05:18 quark sendmail[66]: rejecting connections on daemon MSA: load average: 16
> Aug 10 08:05:33 quark sendmail[66]: rejecting connections on daemon MTA: load average: 13
> Aug 10 08:05:33 quark sendmail[66]: rejecting connections on daemon MSA: load average: 13
> Aug 10 08:05:48 quark sendmail[66]: accepting connections again for daemon MTA

Thats your mailer laughing at someones pitiful attempt to knock it over.
Sendmail does load protection. Anyone with effectively equivalent or better
bandwidth can always DoS a system. Ask yahoo.

> In this company, they hired a "CIO" who thinks that no computers
> should have any local storage or boot capability. They must all
> boot from some secure (M$) file-server. They will not be allowed
> to have local disks and, horrors -- of course no floppy drives or
> CD-ROMS.

Good policy (well maybe not the choice of fileserver OS) in many
environments. How do you think McDonalds unix based tills run 8) - no
floppy believe me.

> He doesn't care that we are in the business of making software-driven
> machines so we require access to the guts of computers and their
> operating systems.

Smart people migrate, company or division goes out of business, another large
company eventually buys small company that the people who left formed
repeat cycle.

> So, if it is at all possible to help improve its security without
> hurting its performance very much, it's really a matter of life-or-
> death for Linux. Otherwise "they" will get us.

I think not. Look at the fate of companies whose bosses adopted X.400
because TCP/IP was "some crazy hacker thing" "not industry strength" "had no
telco support" "couldnt provide the needed QoS" ...

Alan
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/