Also: IP address management; Microsoft patch management; and more
Root of the problem
Regarding “Does open source encourage rootkits?”: The title of your story is misleading. “Open source” is a phrase heavy with meaning and connotation. The only part of it touched on in this story is that people are sharing code.
The question is whether freely sharing malicious information is a good thing, not whether freely sharing things is bad.
Dominic White
Security Services Group
Deloitte
Johannesburg, South Africa
The problem isn’t open source. The problem is the holes and total lack of security in Windows. Windows is closed source and is the problem. Maybe the answer is open source? After all, my Linux box has no problems with spyware and rootkits.
As long as a system sets up the users as administrators, they will never be secure.
Bo Weaver
Senior engineer/security administrator
MTPros
Atlanta
Regarding “Does open source encourage rootkits?”: The problem is not the rootkits; the problem is Windows, which allows the kernel to be modified without user knowledge. Until Windows is fixed so that root user privileges are required for kernel modifications, nothing will change. Using Windows is akin to playing Russian roulette — sooner or later you will lose and Microsoft really doesn’t care. Why should they care as long as consumers want the least expensive PC and Microsoft has a monopoly on that market?
Larry Sokol
Boynton Beach, Fla.
I have yet to see a rootkit published under the General Public License or Berkeley Software Distribution license. Passing a rootkit around without a written license makes it public domain, not open source. I would also like to see it explained as to why McAfee feels that open source is to blame for rootkits, especially since they mainly attack proprietary programs.
Dennis Soper
Systems administrator
University of Oregon
Eugene, Ore.
Out of control
Regarding “IP address mgmt. growing up”: IP address management should be listed under mission-critical job processes. Over the years I have watched groups and organizations fight over address ranges and whether to use private or public addresses in particular spaces.
The key to any successful network is to have a scalable address design and enough addresses to meet present and future needs. In my opinion, all internal addresses should be designed around class “A” network 10 and all public-facing addresses should be made up of the patchwork of class “C” addresses that the group was hording in order to keep assigning addresses as needed.
The various tools provided by the companies listed in the article are useful for managing an environment that has grown out of control after years of growth and acquisition. But they are only needed if the IP address environment has grown out of control.
Manuel Castrejana
Houston
Simple solution
Regarding “Microsoft to unveil new patch management software”: I found analyst Peter Pawlak’s comments regarding the reasons for using Windows Server Update Services (WSUS) vs. Systems Management Server (SMS) to be a bit condescending and simplistic. He says that WSUS is “useful to a limited group.” I believe the target for the product is significantly larger than he believes. I’ve seen discussions of companies that have thousands of computers managed by WSUS. For many of us, WSUS is exactly what we want and need. While cost is always a factor (especially in non-profits like the one I support), it simply doesn’t make sense to buy a complex solution to address a simple need.
Finally, Pawlak’s comment, “…it isn’t that overwhelming to install and manage SMS,” misses the point. Any competent IT person would make the decision on need, functionality and cost. Many of us implement and manage multiple complex solutions every day. I hardly think that many of us would consider SMS to be overwhelming.
Hank Arnold
Network administrator
Hospice, Inc.
Hyde Park, N.Y.
Phishing expedition
Regarding “Phish me once, shame on me”: Putting a Web page in front of someone that they are unable to recognize as a fake doesn’t prove a great deal of itself, as it begs the question of how the user got to such a site in the first place. If users are trained in safe procedures for accessing sensitive Web sites, then it’s somewhat academic whether they can recognize a fake site or not. One thing we do know about phishing sites: They don’t appear from nowhere! They get there like any other Web site, as a result of some action you took. The relevant question is: What action did you take?
I would question the value of this report. It’s entitled “Why Phishing Works,” yet it makes only passing reference to the most fundamental answer to that question: unsafe user practices. This is analogous to publishing an investigation showing that many people are unable to distinguish a genuine salesman from a confidence trickster, without saying anything about the way in which they engaged the salesman in the first place. The subject is interesting in its own right but of limited value in a practical security context.
The fact is, and the authors have effectively shown this, that far more sophistication is required of a user to recognize phishing sites than to avoid such sites altogether.
G.A. Joseph
Canberra, Australia
Desktop search
Regarding “Desktop search tools seen raising red flags”: The statements from many of the IM managers quoted in this article are comical at best and disturbing at worst. While they were off deploying massive, costly, questionably useful (but job security ensuring) enterprise/knowledge/customer relationship/fill-in-the-corporate-sinkhole management suites, simple but highly effective indexing and search software utilities came out of left field, and the people these managers are supposed to be serving voted with their feet. IM managers just finished spraying digital Raid on all of those “productivity-wasting” IM clients — now they have to whip up a new batch for desktop search utilities. What’s their first defense — the old saw that these “untested” apps are screwing up their user’s desktops? (I’ve beta-tested them all on numerous laptops and desktops running Win2000/XP with nary a problem.) The concern for indexing network drives is legitimate, but can be easily solved at both the client and server end.
Message to IM managers: If you spent more time keeping apprised of useful technology, corporate usage trends and educating users, and less time in techno-babble obfuscation, your job and the jobs of the people you are supposed to be serving would be much more pleasant. The deer-in-the-headlights look when desktop search hits the streets is not going to cut it. Get educated or get packing!
William Daunch
Cary, N.C.
Market for Boot Camp
Regarding Kevin Tolly’s column, “Apple’s Boot Camp: A step backward”: As IT professionals we might need to step back to see that there will be a market for this, especially if Apple and Microsoft support it as they should. There are thousands of computer users who would welcome the space-saving convenience of having one piece of hardware that will run both Windows and Mac. Many of these people may not be willing or able to run a Virtual PC solution to accomplish this.
Running Windows on Apple hardware makes more sense than trying to run OS X on every other PC makers’ hardware. It seems to me that if Apple and Microsoft both put some effort into supporting this dual boot technology for the “average” end user, it will be a step forward for both camps. Consumers don’t automatically embrace the best technologies. Marketing and support are vital. Remember Beta-Max VCRs and High Speed Token-Ring?
Richard Manning
Lockport, N.Y.




