[PLUG] The lion in Salem

Dylan Reinhardt plug at dylanreinhardt.com
Wed Aug 27 11:49:02 UTC 2003


On Wed, 27 Aug 2003 07:43:10, David Pool wrote:
> I think there are two approaches to 
> security. One is to discourage discussion and hope that one's 
> vulnerabilities go un-noticed. The other is to discuss stuff openly and 
> then take the precautions of the best minds available on the subject.

So there are only two approaches: the straw-man approach, and the
unrelated idea that gives you carte blanche.  

How convenient.


> I think people who are afraid of the discussion or assume malice on the 
> part of those who ask questions are in the first camp. That camp's name 
> is "Security through obscurity".

No, that camp's name is "mind your own business".

In the *study* of security, there is a strong case to be made for
improving security by fully exploring how it is implemented.

In the *application* of security, there is a strong case to be made for
fully auditing and documenting the system you're implementing.  

The desire to *probe* the security of systems that you are not
responsible for is something else entirely.  There is no strong case to
be made for your involvement at all... *particularly* not when you're
looking for a way to leverage personal gain.  


> In general, Linux/Unix people have tended to prefer the second camp. 
> (whose name is... security through applied intelligence and testing?)

I think the word you're looking for is "hacking."  That's what it is
when you're working on your own stuff, anyway.  

Once you allow yourself to feel entitled to be curious about someone
else's system, the line between hacking and cracking becomes razor thin.

Dylan





More information about the PLUG mailing list