<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exchange Server Pro &#187; Linux</title>
	<atom:link href="http://exchangeserverpro.com/tag/linux/feed" rel="self" type="application/rss+xml" />
	<link>http://exchangeserverpro.com</link>
	<description>Microsoft Exchange Server news, tips, tricks and tutorials</description>
	<lastBuildDate>Tue, 31 Aug 2010 12:02:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Security Spin Cycles</title>
		<link>http://exchangeserverpro.com/security-spin-cycles</link>
		<comments>http://exchangeserverpro.com/security-spin-cycles#comments</comments>
		<pubDate>Wed, 17 Oct 2007 02:29:38 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.capslockassassin.com/2007/10/17/security-spin-cycles/</guid>
		<description><![CDATA[Jeff Jones posted a blog entry to celebrate Red Hat fixing their 1000th unique security vulnerability.  He also draws attention to a Red Hat post on their &#8220;Truth Happens&#8221; blog back in August, which itself quotes a post on Lxer.com. Jeff posts quarterly statistics on his blog that show how many vulnerabilities have been patched for various [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://blogs.technet.com/security/archive/2007/10/16/red-hat-enterprise-linux-4-passes-1000-vulnerabilities.aspx" title="Jeff Jones Blog on Technet">Jeff Jones </a>posted a blog entry to celebrate Red Hat fixing their 1000th unique security vulnerability.  He also draws attention to a Red Hat post on their <a href="http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/" title="Red Hat's Truth Happens Blog">&#8220;Truth Happens&#8221; blog </a>back in August, which itself quotes a post on <a target="_blank" href="http://lxer.com/module/newswire/view/91474/index.html" title="LXer.com">Lxer.com</a>.</p>
<p>Jeff posts quarterly statistics on his blog that show how many vulnerabilities have been patched for various operating systems.  The LXer.com post takes one of his reports and uses it to demonstrate that Linux is more secure than Windows because Linux vendors fix more security vulnerabilities.</p>
<blockquote><p>A <a href="http://blogs.technet.com/security/archive/2007/08/16/july-2007-operating-system-vulnerability-scorecard.aspx">Microsoft vulnerability report</a> suggests that Microsoft wasn&#8217;t able to fix more Windows flaws than the number of open software flaws fixed by the major open source companies . Red Hat, having forty times less employees than Microsoft, did the best job, by fixing and closing the most security bugs, also closing even minor bugs &#8211; where Microsoft didn&#8217;t even fix <em>one</em> minor bug in the same period. Even Apple did a better job than Microsoft by fixing lots of flaws in Mac OS X.</p></blockquote>
<p>Jeff found this to be a little amusing.</p>
<blockquote><p>Seriously, I <em>loved</em> this post, it made me laugh out loud!  Fixing more security vulnerabilities is apparently a good thing in the world of Red Hat Truth.</p>
<p>Well, for those who actively support that theory, I have some <strong><em>fantastic</em></strong> <strong><em>news</em></strong> for them!  According to my calculations, in July 2007, the Red Hat Enterprise Linux 4 team fixed their 1000th unique security vulnerability.  Now, 164 of these were Low severity and 479 were Medium severity, but still, that is a ton of work accomplished by that team, especially given that the product only shipped in February of 2005.</p>
<p>To put that in context, (again by my calculations) Microsoft has fixed only 649 security vulnerabilities for all supported products across the company since the year 2000.</p></blockquote>
<p>I&#8217;m not sure what to think.  Jeff is <a target="_blank" href="http://blogs.csoonline.com/methodology_sources_and_assumptions_for_monthly_vulnerability_scorecards" title="Jeff Jones - Methodology, Sources and Assumptions for Monthly Vulnerability Scorecards">quite clear on how his reports are generated</a>.  Linux supporters used to tell me that fewer vulnerabilities meant a product was more secure.  Now Linux supporters want to say that more vulnerabilities means the product is more secure, or as one comment on LXer.com puts it:</p>
<blockquote><p>You spin the data by saying &#8220;we fixed the most bugs, leaving the fewest bugs in the new code, therefore we are the best.&#8221;</p></blockquote>
<p>Round and round we go.</p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/how-to-configure-a-relay-connector-for-exchange-server-2010" title="How to Configure a Relay Connector for Exchange Server 2010">How to Configure a Relay Connector for Exchange Server 2010</a></li><li><a href="http://exchangeserverpro.com/causes-of-mapiexceptionnotauthorized-error-sending-to-public-folders" title="Causes of MapiExceptionNotAuthorized Error Sending to Public Folders">Causes of MapiExceptionNotAuthorized Error Sending to Public Folders</a></li><li><a href="http://exchangeserverpro.com/gfi-languard-tutorial" title="GFI LANGuard Tutorial">GFI LANGuard Tutorial</a></li><li><a href="http://exchangeserverpro.com/bruce-schneier-on-certificate-authorities" title="Bruce Schneier on Certificate Authorities">Bruce Schneier on Certificate Authorities</a></li><li><a href="http://exchangeserverpro.com/well-designed-security-systems-fail-gracefully-sonicwall-does-not" title="Well-designed security systems fail gracefully, SonicWALL does not">Well-designed security systems fail gracefully, SonicWALL does not</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/security-spin-cycles">Security Spin Cycles</a> is © 2007 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/security-spin-cycles/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Software Advocates Resorting To Graffiti</title>
		<link>http://exchangeserverpro.com/free-software-advocates-resorting-to-graffiti</link>
		<comments>http://exchangeserverpro.com/free-software-advocates-resorting-to-graffiti#comments</comments>
		<pubDate>Wed, 24 Jan 2007 11:28:47 +0000</pubDate>
		<dc:creator>Paul Cunningham</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Linux]]></category>

		<guid isPermaLink="false">http://www.capslockassassin.com/2007/01/24/free-software-advocates-resorting-to-graffiti/</guid>
		<description><![CDATA[Someone at the Free Software Foundation seems to think that an effective means of promoting free software is to actively campaign against Microsoft&#8217;s new Vista operating system, and created the Bad Vista website.  I personally think this is somewhat like negative campaigns in policital races &#8211; attack the opposition rather than promote your own strengths. [...]]]></description>
			<content:encoded><![CDATA[<p>Someone at the <a href="http://www.fsf.org" target="_blank">Free Software Foundation</a> seems to think that an effective means of promoting free software is to actively campaign against Microsoft&#8217;s new Vista operating system, and created the <a href="http://badvista.fsf.org" target="_blank">Bad Vista website</a>.  I personally think this is somewhat like negative campaigns in policital races &#8211; attack the opposition rather than promote your own strengths.</p>
<p>As a user of free software such as Linux and BSD on my servers,  I&#8217;m a little disappointed to see this website.  I&#8217;m even more disappointed to see them <a href="http://badvista.fsf.org/blog/tagging-vista-at-amazon.com" target="_blank">encouraging</a> what is effectively <a href="http://www.defectivebydesign.org/en/amazon" target="_blank">online graffiti</a>.</p>
<p>This sort of action does more harm than good to the image of free software advocacy.  I&#8217;m all for promoting the free, open-source software I use, and will do so here on the site as appropriate.  But undertaking a negative campaign (some of it based on misinformation) and encouraging ridiculous stunts like Amazon tagging just makes the free software community look like a bunch of mouth foaming zealots.</p>
<p>Stick to the positives, compete on features, usability, and support.  Thats how to win users over.</p>
<h3  class="related_post_title">Related posts:</h3><ul class="related_post"><li><a href="http://exchangeserverpro.com/security-spin-cycles" title="Security Spin Cycles">Security Spin Cycles</a></li></ul><hr />
<p>This article <a href="http://exchangeserverpro.com/free-software-advocates-resorting-to-graffiti">Free Software Advocates Resorting To Graffiti</a> is © 2007 ExchangeServerPro.com</p>
<p>Get more <a href="http://exchangeserverpro.com">Exchange Server tips</a> at <a href="http://exchangeserverpro.com">ExchangeServerPro.com</a></p>]]></content:encoded>
			<wfw:commentRss>http://exchangeserverpro.com/free-software-advocates-resorting-to-graffiti/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
