[PLUG] The lion in Salem

Cliff Wells logiplex at qwest.net
Fri Aug 29 10:44:02 UTC 2003


On Thu, 2003-08-28 at 18:49, chaos at gnutech.com wrote:

>         I happen to know MANY highly qualified IT professionals (and I
> do mean professionals in the best sense of the term) at the State of
> Oregon and they're some of the best people I've ever had the
> opportunity to work with. 

It isn't that there aren't highly competent staff working for the state,
it's simply that they seem to be in the minority.  Given the large
number of staff the state has, that still allows for a great number of
qualified staff.

> I've lurked for quite some time on this thread. It really bothered me
> how running an nmap scan on lion at DAS is considered okay - almost
> like it's your civil duty. These admins have enough to do trying to
> keep the bad guys out. If you're concerned about whether or not the
> system is secured adequately, take it up with the auditors. That's
> their job. 

And you get a hold of these auditors by...  yeah right.  Anyway, the
working assumption here is that state employees aren't doing their
jobs.  Why would state auditors be considered exempt from this
assumption?  You might ask why that assumption is being made so I'll
tell you: 

1) State employees are usually assumed to be less competent than their
private sector counterparts.  Is this a fair assumption?  Maybe not, but
it can be *very* difficult to fire a state employee and human nature
kind of dictates that a good number of people will take advantage of
that situation.  Also, as I mentioned earlier, the sheer number of state
employees has the effect of reducing the amount of accountability placed
on any single person.  Many will also take advantage of this.

2) We haven't been shown otherwise.  If you don't keep an eye on your
government, you deserve what you get.

3) The state tends to promote people to their highest level of
incompetence.  That means that while you might have many talented people
in the trenches, management often consists of shaved apes wearing shirts
and ties.  Management often dictates policy that goes directly against
what the competent people would prefer and there's often little the
competent people can do about it.  Of course, this isn't unique to the
state, but given how difficult it can be to fire state employees, the
ones considered incompetent are often promoted to a place where it is
hoped they can't actually do much harm (i.e. they can't touch a keyboard
on a critical system), but they somehow manage to mess up everyone
else's job anyway.

> This sort of activity has been, and is still, considered malicious.
> Repeated scanning results in logs being turned over to the
> authorities.

And it bothers me that running nmap is considered a crime.  It's called
"looking".  Often people use "looking" as preparation for comitting a
crime.  More often they don't.  Perhaps next time someone walks past my
house and gives it a twice-over, I should call the police.  They might
be casing the place.

> I respect the cause that you all fight for. Open Source software most
> definitely has it's advantages. Linux is a rock-solid OS. The State
> could save millions by replacing certain systems with OSS and ditching
> expensive proprietary software. But I do not, nor will I ever,
> subscribe to the notion that OSS or Linux is the "be all, end all" of
> software. Everything has a place. There's balance in there somewhere.

Agreed.  I don't think that's what this discussion is about (anymore).

> Open Source software will succeed; on its merits, not through
> legislation. Just as NO ONE who has ever stood up to Microsoft and
> tried to compete against it on the same terms has ever won. They are
> crushed under the wheels of Microsoft's market domination. But OSS and
> Linux are not on the same playing field. It'll achieve dominance on
> it's own; it'll just take time. I use OSS (mainly Linux) regularly and
> champion its merits whenever I can.

Hopefully.  And if not Linux, perhaps an OSS successor to Linux (er,
Hurd?).  But really, as far as I'm concerned it isn't because I want
Linux to be successful that this is an issue.  It's because I want the
state to run more efficiently (although a recent thread on
comp.lang.python would suggest that an efficient state might not be a
good thing).  After all, it's my tax dollars and my personal data that
are at stake.  If Microsoft gives the state a sweet deal and can
*secure* their systems and not require state employees to grant MS the
right to peruse *my* data whenever they please (read your EULAs
everyone), then by all means, use Windows.  If they can't do those
things, then don't.

Speaking of EULAs, has anyone considered demanding that state employees
who deal with public records (which, despite their name, may be
confidential) *not* click "I agree" on these EULAs?  What right does a
fairly low-level state employee have to grant Microsoft (or anyone else,
for that matter) the right to have access to this data?  Whether MS does
or not is irrelevant.  The state employee doesn't have the authority to
grant this right.


Regards,

-- 
Cliff Wells, Software Engineer
Logiplex Corporation (www.logiplex.net)
(503) 978-6726  (800) 735-0555





More information about the PLUG mailing list