[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
server and client in one package -> security issue (was: Add murmur)
From: |
Hartmut Goebel |
Subject: |
server and client in one package -> security issue (was: Add murmur) |
Date: |
Sun, 12 Feb 2017 13:23:09 +0100 |
User-agent: |
Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0 |
Am 09.02.2017 um 23:50 schrieb Ludovic Courtès:
> I think the only reason to separate things usually is size, not
> “aesthetics.” So I’d be in favor of keeping both in the same output if
> there’s no size problem.
Separating clients and servers is not an "aesthetic" thing. It's a
matter of security.
One basic rule for hardening systems is: "only install the required
software". If we munge server and clients packages, this obeys this rule.
In my day-business I'm a security consultant (CISSP, CSSLP and ISO
27001 Lead Implementer). And from my point of view Guix already has a
medium problem of acceptance since it munges development-files and
run-time files into one package - as we do for all libraries. This
already contradicts the above mentioned basic rule.
Now if Guix starts munging server and client components into one
package, this plain disqualifies GuixSD from any security sensitive
system. [*]
[*] OTOH it opens up chances for big business: selling "Secure GuixSD"
to customers.
--
Regards
Hartmut Goebel
| Hartmut Goebel | address@hidden |
| www.crazy-compilers.com | compilers which you thought are impossible |
- Re: Add murmur., (continued)
- Re: Add murmur., ng0, 2017/02/12
- Re: Add murmur., David Craven, 2017/02/12
- Re: Add murmur., ng0, 2017/02/12
- Re: Add murmur., David Craven, 2017/02/12
- Re: Add murmur., Hartmut Goebel, 2017/02/12
- Re: Add murmur., pelzflorian (Florian Pelz), 2017/02/12
- Re: Add murmur., Ludovic Courtès, 2017/02/13
- Re: Add murmur., David Craven, 2017/02/12
- Re: Add murmur., Hartmut Goebel, 2017/02/14
- Re: Add murmur., ng0, 2017/02/14
- server and client in one package -> security issue (was: Add murmur),
Hartmut Goebel <=
- Re: server and client in one package -> security issue (was: Add murmur), ng0, 2017/02/12
- Re: server and client in one package -> security issue (was: Add murmur), David Craven, 2017/02/12
- Re: server and client in one package -> security issue, Hartmut Goebel, 2017/02/12
- Re: server and client in one package -> security issue, Ludovic Courtès, 2017/02/13
- Re: server and client in one package -> security issue, Hartmut Goebel, 2017/02/14
- Re: server and client in one package -> security issue, Andy Wingo, 2017/02/14
- Re: server and client in one package -> security issue (was: Add murmur), Danny Milosavljevic, 2017/02/14
- Re: server and client in one package -> security issue (was: Add murmur), ng0, 2017/02/14
- Re: server and client in one package -> security issue, Hartmut Goebel, 2017/02/14