by Jim Romeo

CIO Reality Check: Linux Security

News
Aug 12, 20086 mins

The open source community might be abuzz with security discussions, but what do the CIOs of real-world companies have to say? We spoke with the experts at Linux-using firms.

In our conversations, we spoke to Sam Lamonica, CIO of Rudolph and Sletten Construction, a general building contractor based in Redwood, California; Philipp Huber, CTO/COO of the UK based XCalibre Communications, a hosting firm located in the UK; Clyde Williams, Infrastructure Systems Manager for Southeast Alabama Medical Center, a hospital located in Dothan, Alabama; and Walt Cornelison, Director of Information Technology for Tropitone Furniture, a manufacturer or high-end outdoor furniture located in Irvine, California. Here’s how our conversation went:

Linuxworld.com: From your perspective how great of a concern has security been, and how great of a concern is it at present, in an open source environment for you?

Sam Lamonica, CIO of Rudolph and Sletten Construction: From experience, we are not concerned about open source in our environment any more or less than the proprietary software we utilize. For example, we’ve been using GroundWork Monitor Professional—an open source systems and network monitoring and management solution—since 2005, and we have yet to experience any security breaches related to it because it’s open source.

Philipp Huber, CTO/COO, XCalibre Communications:* [A] major concern. We are often asked by our customers how we can ensure that data security is guaranteed.

Clyde Williams, Infrastructure Systems Manager, Southeast Alabama Medical Center: From my perspective, and in my own opinion, open source software has enjoyed security through lack of widespread adoption. When the market share of any single open source application gets large enough, it will become a target for exploitation.

Walt Cornelison, Director of Information Technology, Tropitone Furniture: Security is always a concern. I have to balance security with an ability to operate and function. I find security to be less of a concern on the Linux side. I’m pretty confident on that side of our business. We have to balance operations performance, [with] user need and security. Security cannot be so obtrusive that we cannot operate.

Linuxworld.com: What could enhanced security mean for the open source and Linux community?

Sam Lamonica: From a perception perspective, enhanced security means more peace of mind for the open source and Linux community. But in reality, all software is vulnerable at some level to attack and the idea that open source and Linux is more susceptible because it is open is flawed. I think Mark Stone’s O’Reilly blog on the subject from way back in 2004 still holds true:

“Too often people assume that secrecy equals security. Nothing could be further from the truth….Open Source software is based on a similar notion of security. Hiding source code is a bad way to assume you’ll achieve security, because even a powerful and highly proprietary company can’t guarantee that source code won’t leak out. Instead, security should be based on a worst-case scenario: assume your ‘adversary’ has access to the source code.”

Philipp Huber: It would mean that we could start convincing high-level customers (i.e. financial institutions) to use cloud services that are based on components they trust.

Clyde Williams: A great deal of complexity. Security takes a lot of communication and resources to implement and maintain. The nature of the open source community lends itself well to innovation, but may not lend itself well to the kind of orchestrated communication that may be required to maintain adequate security.

Walt Cornelison: Enhanced security has improved the reliability in the open source community, If IT, who uses the products, find improved security, it enhances the desirability and the product itself.

Linuxworld.com: Are you using SELinux or AppArmor?

Sam Lamonica: No

Philipp Huber: No

Clyde Williams: No

Walt Cornelison: AppArmor is what we have been using for several years now. We have been using it since we first started our implementation.

Linuxworld.com: Some vendors want to offer applications as “virtual appliances” bundled with an OS image. Are you concerned about the need to keep common platform software updated in what could amount to one OS image per application?

Sam Lamonica: Without adequate IT control, applications as “virtual appliances” bundled with an OS image can be unwieldy. One reason – automatic patching systems often don’t recognize them, leaving them without critical updates.

Philipp Huber: Yes we are very much so. Increasingly, we don’t believe in the very popular snapshot based images anymore (we still offer them) simply because with the zig’million combinations, you couldn’t keep all the images from (OS, middle-ware, Db, application, etc.,) up to date. The only way you can overcome the challenge is by dynamically building the stacks with the latest and patched components. We internally use Cfengine to do that. We are already partnering with CohesiveFT. We are talking to rPath and have JumpBox on our radar. They all offer, with some variations, technology that lets you build stacks on-demand.

Clyde Williams: It’s on our mind now, but not necessarily a concern yet. While we have experimented with the concept of virtual appliances, we have not deployed any into production, and this is one of the reasons: It’s hard enough keeping track of updates for the operating systems we already support, without worrying about the OS’s on any virtual appliances we run. If and when, we do deploy a production virtual appliance, we’ll make sure it comes from a vendor with experience in the physical appliance market.

Walt Cornelison: Not really. Knowing and understanding the bundles of virtual appliances, I have found too much concern with the need to have a consistence operating system across the whole enterprise. The Linux piece runs in the background of the application. It’s always like it’s invisible and not a major concern.

Linuxworld.com: What are the vendor and open source scenes pushing that you don’t want? What aren’t they pushing that you do want?

Sam Lamonica: In general, the one thing I see lacking from open source vendors is what Serdar Yegulalp from InformationWeek calls a “workable transition path.” He notes “The open source community needs to come up with a workable transition path from proprietary intellectual property to open source. Like it or not, the world of proprietary intellectual properties —patents, restrictive licensing, the whole ball of sticky wax—is still king. What do you do if you’re trying to move from a proprietary intellectual property licensing system to something more open, and you find it may not be possible to do so?

Some OS vendors push an “us vs. them” attitude towards proprietary software. That “push” serves no one as today’s IT infrastructures at most organizations are more of a mosaic with proprietary and OS solutions needing to work together in harmony.

Walt Cornelison: I guess there are a lot of products in the open source side that we don’t have a need for. It has to be viewed on a needs basis. If we have a need and the product to fit that need well then I’d be interested.

This is the second in the “CIO Reality Check” series. See also: CIO Reality Check: Linux and Virtualization.