The Grokster.com Scare Tactic

Written by Saran on June 27, 2006

There is a Slashdot article on Grokster.com changing their front page to one which displays your IP address and notes that it has been logged. As noted in many comments on Slashdot, I’d just like to say that this is no different to ordinary browsing: the web server always gets your IP address, otherwise it wouldn’t be able to send data back to you.

And usually, this address is logged with each request. There is nothing new here, and this site is just a scare tactic to put off people who don’t already know this.

It is important to draw people’s attention to this as some may believe that the site is doing something untoward, in order to obtain an IP address. In fact, any TCP connection (except spoofed packets) results in the server-side application being able to determine your IP address.

Tags: ,

Categories: News, Real-World Issues

Leave a Comment

RedHat Enterprise Linux 4 vs. Windows Server 2003

Written by clouseau on June 26, 2006

You will constantly see “religious” wars being fought between the camps of the above mentioned platforms. You’ll also see a lot of comparisons between the two on the net, all of which have a hint of bias in them. Well today I’m going to cover just facts between the two platforms to see which one comes out a clear winner, if any.
Let’s see when each platform launched. If we look up RedHat we’ll find that they launched version 4 of their highly acclaimed Enterprise Linux on February 15th, 2005 according to CRN. Microsoft Windows Server 2003 was released on March 28th, 2003 according to Microsoft’s own site. That’s nearly a two year gap between the two which in the IT world is nearly a lifetime of most software product versions themselves.
So Windows Server 2003 has a near 2 year head start on RedHat Enterprise Linux 4 to collect all sorts of vulnerabilities that we all know Microsoft is famous for. However, this is where it gets to be a tad bit surprising. Outside the hype and FUD (Fear, Uncertainty and Distrust), it’s not nearly as bad as the general tech community paints it out to be. A little research from Secunia reveals that it’s not bad at all.

Graph
Since its release in 2003, Windows Server has accumulated a total of 74 Secunia Advisories.

Now let us take a look at Redhat Enterprise Linux

graph

Since its release in 2005, Enterprise Linux 4 has accumulated a total of 128 advisories.

Wait, what? There must be some mistake. Well ok, perhaps the Enterprise Linux 4 vulnerabilities are a lot less severe than Windows Server 2003. A local vulnerability is a lot less severe than a remote vulnerability.

So let’s look at RedHat Enterprise Linux 4 first.

graph

Ok so 83 percent of all the vulnerabilities are able to be exploited remotely. That’s a pretty high number. Let’s take a look at Windows.

Graph

59 percent of all Windows Server 2003 Secunia Advisories are remotely exploitable.

Well now, this is fairly interesting. So far, dare I say, Windows is leading in terms of security.

Ah but wait, it’s not over yet. We have yet to see the type of impact most of these vulnerabilities have, and most importantly, the impact they have at the system level.

So let’s take a look at RedHat Enterprise Linux 4 first.

Graph

We see here that 30 percent of the vulnerabilities allow system access.

Now let’s take a look at Windows Server 2003.

Graph

We see here that Windows Server 2003 is a bit more severe in that 53 percent of their vulnerabilities allowed system access. That’s a fairly high percentage that is dangerous, especially in an enterprise environment.
Secunia also keeps track of vulnerabilities that they have discovered and are unpatched as of yet by the vendor, which gives us an idea of the rate at which each vendor responds to security.

The Secunia database currently contains 0 Secunia advisories marked as “Unpatched“, which affects RedHat Enterprise Linux AS 4.

That’s pretty decent, so we know that RedHat responds very quickly to any discovered security threats. Let’s have a look at Microsoft.

Currently, 8 out of 74 Secunia advisories, is marked as “Unpatched” in the Secunia database.

A much more dangerous number than zero. Although, to their credit, all of the “unpatched” vulnerabilities are not too critical. However, this still shows us how seriously Microsoft lags behind in their patching efforts. One could only attribute this to the massive complexity of the Windows system that Microsoft engineers must go through in contrast to the modular nature of Linux itself.

In conclusion, what we have here is a very interesting set of differences between the two platforms and neither comes out as a clear winner. (I know, you are disappointed!) However, we did uncover the fact that Windows Server 2003 is not nearly as bad as the general tech community paints it out to be and would be a fairly solid choice in an enterprise environment despite all the FUD.

Tags: ,

Categories: Operating Systems, Review

2 Comments

MSN Messenger Censorship

Written by Saran on June 25, 2006

It turns out that MSN are blocking the word “download.php” in MSN Messenger conversations. According to SourceForge, and verified by myself, messages containing those words simply do not get through. In addition, the conversation link is closed (but the chat window itself remains open).

I shouldn’t need to point out that many legitimate sites use download.php as a means for accessing files. Linking a less computer-savvy friend to a download page for AntiVirus software may now be impossible, thanks to MSN.

This is a totally pointless censorship, and serves no purpose whatsoever, other than to inconvenience the user.

Perhaps it is time to switch to another protocol, Jabber, for instance, built on the open XMPP protocol.

Tags: ,

Categories: Real-World Issues, Security Policies

3 Comments

Britain Plans To Monitor Every Car Journey

Written by Saran on June 24, 2006

I wrote earlier in the week about the British plans to introduce ID cards. Now, it turns out there is an even more stupid and pointless idea following. This is to use a nationwide network of cameras which can identify car number plates to track the journeys of every car in the country. Data on the time, date and location of each sighting will be stored in a central database. Information will be fed into this from roadside cameras by a secure police communications network.

This data will apparently be used by the police and the security service (MI5) in criminal investigations and anti-terrorism efforts, and to identify cars being used without insurance or road tax.

There are a number of problems with this system. Some of these are the same as the problems with the ID card system. For one, it costs a lot � the government have already allocated �24 million to this. Money which could be put to better use elsewhere.

Let us now look at some of the other problems. There is the potential for abuse. The system is going to be open to police, security services and other government departments. Anyone working for these, as well as anyone who gains access one way or another, has access to the travel patterns of the entire population of the country. If you suspect your wife is cheating on you, its just a simple matter of asking your friend in the police to check that her car actually registers as going to Tesco that night, and not some street the other side of the city, where all the investment bankers live.

Furthermore, there will be an enormous quantity of data relayed by this system. Managing this much data is difficult, and mistakes will be made. Suppose a GPS system fails, and your car is placed near the scene of a murder, at the approximate time it took place. In fact, you were nowhere near the place, but the system never lies, and will be trusted without question. What, then, is your defence?

That somewhat extreme example illustrates just one of the things which can go wrong with such systems. And this is forgetting civil liberties, and the fact that many people object to living under the watchful eye of the government. What does it matter to the government if I was 20 minutes late into work yesterday? Although, I suppose they could track the journey and figure out that it was because of the accident which blocked the road for 15 minutes!

Again, just an example, but no matter how many advantages a system like this has, the disadvantages, security problems and potential for abuse far outweigh any conceivable advantage.

The money being wasted on systems such as this would be better spent tightening security at airports, sea ports, train stations, and other such transport hubs. One excellent way to spend this money would be to improve the training of security staff at these places. Humans are far better at spotting unusual behaviour, or security risks, than automated systems are. With training, the efficiency and security of airports, etc. can be improved significantly, without the risk and public outcry associated with schemes such as ID cards and national road-traffic monitoring!

Tags:

Categories: Real-World Issues

3 Comments