On Thu, 16 Feb 2012 00:54:50 +0000, Lusotec wrote:
Nothing of interest except frothing and twitching as he gets
ROPE-A-DOPED.
http://news.cnet.com/8301-1009_3-57...ys-mcafee/
"The amount of malicious software hitting Android devices in the
third quarter jumped almost 37 percent, boding that 2011 will be the
busiest year ever for malware."
http://blogs.cio.com/security/16631...are-magnet
"Google¢s Android OS has become a malware magnet. Its dominance as a
smartphone platform is turning it into a much bigger security risk
compared to place Apple¢s iPhone.
Since July there has been a 472 percent increase in spyware and
viruses targeting Android, according to a report from Juniper
Networks. The report says most of the threats come from apps
downloaded from third-party sites which are not part of Google¢s
Android Market. Apple users don¢t have the same problem because all
apps must first be approved by the company and can only be
downloaded from the company¢s own store."
OS | new malware in 3Q 2011
Android/Linux | bit less than 100
Mac OSX | bit more than 150
Windows | more than 4.500.000
Did someone hit a nerve here? And now you must act like chris(v)ictim,
lunatic 7, and Christina Ahlstrom on a point counter point on a "pop
goes the weasel cause the weasel pop' post. :)
On Wed, 15 Feb 2012 20:03:52 -0500, Big Steel wrote:
On 2/15/2012 7:54 PM, Lusotec wrote:
Hash: SHA256
OS | new malware in 3Q 2011
Android/Linux | bit less than 100
Mac OSX | bit more than 150
Windows | more than 4.500.000
Did someone hit a nerve here? And now you must act like chris(v)ictim,
lunatic 7, and Christina Ahlstrom on a point counter point on a "pop
goes the weasel cause the weasel pop' post. :)
Yea.
I hit LOSERtec's nerve right between the eyeballs.
I was talking about Android's shit security and all of a sudden
LOSERtec extrapolates to traditional desktop / server operating
systems in order to mask Android's horrid security.
He got caught and he doesn't like it at all.
ROPED AND DOPED is LOSERtec.
I'll let it go now that I've wiped the floor with him and his
idiocy.
Lusotec wrote this copyrighted missive and expects royalties:
OS | new malware in 3Q 2011
Android/Linux | bit less than 100
Mac OSX | bit more than 150
Windows | more than 4.500.000
Microsoft Windows, the security shitware OS!
Looks like Flounder's chronic trolling did the job this time.
THE SINGLE MOST FUNNY DRUNKEN INSANE RANT "HADRON" HAS HITHERTO POSTED
-
A recent thread "Works for me" has amazed me. A group of COLA
"contributors" have decided that it IS ok to download source, unarchive
it configure it and compile it under a su (as root) shell. This is
amazing since common sense and best practice in ALL *nix development
arenas I have been have mandated that the only phase ones uses as root
is the install itself.
Of course even thinking about it slightly makes this obvious. Accessing
ANY program as root which accesses the web is daft. Unarchiving as root
means one typo could see that archive wipe your machine. One problem in
the make file could see the file system hosed or something rooted. One
doesnt have to be a genius to see this.
However group luminaries have different opinions. And have laughed at my
reasonings. Some even suggesting I dont know what I'm talking about.
Chris Ahlstrom and Gregory Sheaman (yes he of a "good UI is a waste of a
programmers time" fame) and to a lesser extent TomB, have dictated that
I dont know what I'm talking about and its perfectly ok to do all of
this and more in an su shell. Indeed, why bother with sudo at all eh?
So what happens when they make a mistake? Amazingly "thats ok" as they
have backups. Yes folks. They have "backups". So lets fuck up the system
but thats ok - they have backups. Clearly not admins on multiuser
servers then. Not that anyone thought them competent enough in the first
place.
Those not convinced need to look up sudo. Not only that they need to
look up debian sudo and see how the sudoers file needs to be edited.
So COLA : its ok.
Rest of world : Its not ok and is downright foolish.
Some links follow to highlight how clueless Ahlstrom most of all is
(he's there laughing and patting people on the back about all the
crazzeeeee things he does as root). Also keep in mind how that thread
started - I was highlighting how silly it was to do things as root for a
nOOb. It soon degenerated thanks to COLA dicks as to how it was
perfectly ok to do it ALL as root. I am, frankly, astonished as to how
little these guys seem to understand about the Linux security access
methods and how they should be used to maintain a systems
integrity. There willingness to risk compromising servers (and, as a
result anyone that logs into them) is unnerving to say the least.
The Links: https://forum.openwrt.org/viewtopic.php?id654
,-
| Doing anything as root without a DAMN good reason is a very stupid
| idea
`-
,-
| The reason I don't want to compile as root is that frankly I don't trust the code, and I don't really feel like browsing every makefile and every source file to make sure that no harm will be done to my system. Compiling as root has never been considered a safe practice.
| Also, it's completely redundant because the system uses fakeroot. You
| don't need root privs.
`- https://www.linuxquestions.org/ques...oot-69452/
,-
| well... it's all about security
| , I'm not sure, but in Linux philosophy, you should NEVER do ANYTHING at
| root, except things you are FORCED to do. So, since you can "configure"
| and "make" at user but need to be root to "make install" you should only
| be root to do make install. I suppose this way, you can avoid bad code,
| evil configure script or things like this.
`- http://andrey.mikhalchuk.com/2009/0...e-809.html
,-
| Good news is OpenWRT 8.09 got recently released. Bad news is that you
| can’t compile it as root. Yes, compiling as root is bad,
`- http://in.answers.yahoo.com/question/index?qid 071009033127AAuaV9Z
,-
| As a rule of thumb, if it doesn't /have/ to be done as root, then don't
| do it as root. If you aren't running as root then it (intentionally, or
| by accident, or because you made a typo, etc) can't destroy your system
| or install a rootkit.
`-
To summarise : You guys should be ashamed of yourself saying its
ok. This is almost as embarrassing for Ahlstrom as him maintaining Peter
was right when he thought he could access a field of a struct in C from
a NULL pointer after boasting about how he crafts world class C code.
Replies