| By Linux News Desk | Article Rating: |
|
| May 18, 2004 12:00 AM EDT | Reads: |
15,647 |
Dan O'Dowd is back. He has reached Week Five now in his self-appointed mission to eradicate the "evil" that is Linux from the nation's defense systems by publishing a series of (commercially self-serving) "white papers."
This week the topic is the same as all previous weeks - the use of Linux in U.S. defense installations.
In "Linux in Defense: An Urgent Threat to National Security" O'Dowd, who is CEO of a company that supplies an OS that he claims is more secure than Linux, argues that the nation ought not to be reliant on an operating system that - unlike his own company's offering, naturally - cannot be proven secure "by mathematically sound methods like the Common Criteria Evaluation Assurance Level 7."
"Given that juvenile delinquents are able to find and exploit Linux security vulnerabilities in their spare time," Green Hills Software CEO O'Dowd writes, in much the same vein as he has written all four times previously, "imagine how easy it is for foreign intelligence and military services with enormous resources."
He continues:
"And unlike juvenile delinquents, hostile agents do not revel in their success when they compromise one of our systems; they secretly collect data, passwords, encryption keys and other intelligence. After a foreign intelligence or military service compromises one of our systems they install a back door so that even if the exploited vulnerability is eventually patched, the system will remain compromised."
Then O'Dowd paints a picture taken directly, he claims, from the Cold War:
"Those who say that no one is intentionally inserting malicious code into software that they know is going to be used in military systems or critical infrastructure are not familiar with history. In the early 1980's, the U.S. Central Intelligence Agency (CIA) inserted Trojan horses and back doors into software that the Soviet Union acquired from the West. A CIA Trojan horse in the software that controlled the trans-Siberia gas pipeline caused a massive explosion. It is incredibly naive to believe that other countries and terrorist organizations would not exploit an easy opportunity to sabotage our military or critical infrastructure systems when we have been doing the same thing to them for over twenty years!"LinuxWorld as usual leaves the reader to form his or her own conclusions by reading O'Dowd first-hand.
We also repeat our offer to carry a rebuttal of O'Dowd's arguments as soon as someone sends one along. As we have seen already this week, from Linus Torvalds' response to the Alexis de Tocqueville Institute's claims that he didn't invent Linux, nothing works more effectively than a quick response - so that technology news media carry the rebuttal in close enough promixity to the claims being rebutted to have some definite effect.
Published May 18, 2004 Reads 15,647
Copyright © 2004 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
- Dan O'Dowd Reminds World of UNIX Creator Ken Thompson's Security Stunt
- "Subversive Software" - O'Dowd's Linux Security Controversy Continues
- "Foreign Powers Will Deploy Spies to Infiltrate Linux," Argues O'Dowd
- "Every Principle of Security is Being Violated," Says O'Dowd
- Linux Infections Rare, Says Report
More Stories By Linux News Desk
SYS-CON's Linux News Desk gathers stories, analysis, and information from around the Linux world and synthesizes them into an easy to digest format for IT/IS managers and other business decision-makers.
![]() |
EagleUK 05/21/04 12:26:46 AM EDT | |||
Gosh, we're all being just a tad xenophobic, aren't we? I understand Mr. O'Dowd's motivation ($$) for bashing offshore development. The truth is that none of the OS software is developed entirely in the USA, and programmers in countries like Russia and India produce some excellent code at a much lower cost. All of it has to be reviewed (even M$) before it is used anyway. Everyone seems to be judging these other countries based on national bias rather than facts. Where have most of the various viruses, worms, trojan horses, etc that we've been subjected to over the last few years originate? (Hint: Made in USA). Get a grip, folks. |
||||
![]() |
mister tibbs 05/20/04 05:12:26 PM EDT | |||
Well, as Linux is sh*t anyway its all true? |
||||
![]() |
Anything can be infiltrated 05/20/04 04:41:54 PM EDT | |||
Smithy: if the US was so good about security, there would never have been any mole at the CIA. If somebody wants to infiltrate badly enough, they will do it. It's that simple. |
||||
![]() |
ZT 05/19/04 02:08:05 PM EDT | |||
First the ultra paranoid should go for OSS as atleast then they get to see the source code themselves. Second, not computer system is 100% secure. The only ones that are are not turned on and are not connected to the network. If the military is really worried about what they are getting they'd higher a team of computer and sofware engineers that would rival M$ and design their own or atleast demand the source code that they can inspect and modify if need be and then compile it themselves. Which they can do with OSS. |
||||
![]() |
baustiech 05/19/04 04:55:32 AM EDT | |||
MY GAWD, MY GAWD. It's a placeholder -- this zany idea of ZERO -- but it came from NON-WHITE PEOPLE!!!! IT MUST BE IGNORED! We must not incorporate it into mathematics! |
||||
![]() |
Tazor 05/19/04 02:34:32 AM EDT | |||
Smithy: No, that was not what I was trying to say. I'm saying that no matter where software comes from, it must be checked if it going to be used in a very secure enviroment. |
||||
![]() |
Chris 05/18/04 07:44:36 PM EDT | |||
Without objective criteria, this discussion of "security" all just a bunch of fluff. I believe the government still uses orange book standards that specify the level of security needed, and in turn, the orange book codes "B2", "C1", etc. specify the standards for creation of the code. If Linux fits the standard then it must be OK. |
||||
![]() |
Me My Business 05/18/04 11:58:17 AM EDT | |||
I posted this a while ago against one of O'Dowd's earlier ramblings, but it seems to fit better here.... Where is most US commercial software being coded? China, India, Indonesia, The Phillipines, or anywhere else that labour is 40 cents a day (remember, it's all about profits and "maximizing shareholder value"). Al Qaeda or similar organizations wouldn't have operatives working in any of those countries, would they?. Surely where are no anti-American groups there.... Wake up! This isn't about software security, it's all about the almighty dollar. God bless America, where doing business means you get to do whatever is necessary to fill your pockets and protect your piece of the pie, and damn the truth or social responsibility. Seriously, it's hard to believe the word or opinion of anyone who is an interested party, and it's in Mr O'Dowd's best interest to do everything he can to stop competition from taking away his business. |
||||
![]() |
Smithy 05/18/04 10:36:31 AM EDT | |||
Tazor : "Do the US government trust software from any non-open source company? I hope not" |
||||
![]() |
Tazor 05/18/04 09:34:45 AM EDT | |||
How hard is it for "foreign intelligence and military services with enormous resources" to education a spy to code, send him to the US, get him to work for a software company and plant a backdoor? Do the US government trust software from any non-open source company? I hope not. I do not live in the US but i really hope that US government look into the code they are recieving, from any source. Can Dan O'Dowd really say that none of this employees are spies? Spies are good at hiding their real occupation, that is what makes them spies. |
||||
![]() |
Benjamin 05/18/04 09:18:57 AM EDT | |||
Actually, the NSA link doesn't claim that Linux is pretty damn secure: "There is still much work needed to develop a complete security solution." But then again I can't recall anyone ever saying that Linux was a mission critical OS. Is anyone running their nuclear power plant's control systems on Linux boxes? Linux is nice but its not the answer to everything... |
||||
![]() |
pair-a-noyd 05/18/04 08:40:06 AM EDT | |||
The NSA seems to think that Linux can be made pretty damn secure. |
||||
![]() |
LostCluster 05/18/04 08:37:51 AM EDT | |||
Annonymous anything is annoying to the military. They need to be able to trust who and what they're dealing with. They want to be friendly with the Iraqis in the street as much as possible, but when they can't tell the difference between a needy kid and a suicide bomber, they end up treating every kid they see as a bomber until they know therwise... So, the issue of "Can we trust this?" is a big one here. OSS might be trustworthy enough for my desk, but the military has higher standards. |
||||
![]() |
bonch 05/18/04 08:36:49 AM EDT | |||
OSS isn't some sort of unstoppable secure force. Check out LinuxSecurity's security advisories for weekly Linux distro security advisories--all the buffer overflows and exploits you thought only Windows had. And let's not forget the hacking of GNOME, Debian, Gentoo, and GNU (twice!). |
||||
![]() |
aNON 05/18/04 08:29:50 AM EDT | |||
O'Dowd's Russian/Chinese BS is just that and you know it. It never fails to please the crowd by blaming China or Russia. I thought only the lame election year politicians know it. |
||||
![]() |
Jah-Wren Ryel 05/18/04 08:28:39 AM EDT | |||
With all the off-shoring of work that large companies like Microsoft, HP and IBM do there is at least a perception on their part that when selling to the DoD that they should downplay the fact that foreign nationals, in foreign countries, not only have read access to the source code for the OSes (NT/XP/HPUX/AIX) that most DoD contractors don't have themselves, but that these same foreign nationals also, in many cases have write access to that source code too. Whether most DoD contractors care, I don't know, but like I said, the vendors often remind their customer interaction people to gloss over those kind of details. |
||||
![]() |
goombah99 05/18/04 08:27:25 AM EDT | |||
RTOS has some inherent reliability advantages. Any RTOS is going to tend to have a more deterministic event queue than Linux by definition of what you mean by REAL TIME. Thus to a certain extent testing harnessess can more exhaustively evaluate race conditions and much of the finite states you expect the system to progress through. For embedded systems and mission critical appliances this ought to give better reliability. This is not to say a Real Time Operating Systems can't be badly written or contain bugs. Its just that determininsm makes testing easier. It also does not mean a RTOS is more efficient than Linux. |
||||
![]() |
beacher 05/18/04 08:25:56 AM EDT | |||
Same old same old. back in April he was spouting "Everyday new code is added to Linux in Russia, China and elsewhere throughout the world. Everyday that code is incorporated into our command, control, communications and weapons systems. This must stop." ... Cmon he has a vested interest... His own company puts out it's own RTOS. Go to that link. Now. Read the TOP of the middle column "Real-Time Operating Systems Must be Highly Reliable" This is FUD and he does have a vested interest. |
||||
- The Top 150 Players in Cloud Computing
- Cloud CEOs, CTOs & SVPs to Speak at 4th International Cloud Computing Expo
- 4th International Cloud Computing Conference & Expo Starts Today
- SYS-CON.TV: Cloud Computing Expo Power Panel
- Exclusive Q&A with Rich Marcello - Unisys President, Systems & Technology
- Unisys Named “Platinum Sponsor” of Cloud Computing Expo
- Why IBM’s Server Chief Got Busted
- Vizioncore Named Bronze Sponsor of 4th Virtualization Conference & Expo
- 1st Annual GovIT Expo: Letter from the Technical Chair
- Deputy CIO of the CIA to Keynote 1st Annual GovIT Expo
- The Top 150 Players in Cloud Computing
- Cloud Computing Expo Europe 2009 in Prague: Themes & Topics
- Cloud Computing Expo 2009 West: Call for Papers Now Closed
- Virtualization Conference & Expo 2009 West: Call for Papers Closing
- Cloud CEOs, CTOs & SVPs to Speak at 4th International Cloud Computing Expo
- 4th International Cloud Computing Conference & Expo Starts Today
- SYS-CON.TV: Cloud Computing Expo Power Panel
- Exclusive Q&A with Rich Marcello - Unisys President, Systems & Technology
- Unisys Named “Platinum Sponsor” of Cloud Computing Expo
- Anatomy of a Java Finalizer
- FullArmor GPAnywhere Secures Microsoft Application Virtualization Applications Through Group Policy
- Where Are RIA Technologies Headed in 2008?
- SYS-CON's Virtualization Conference & Expo: Themes & Topics
- SYS-CON's Virtualization Journal Opens Its "Readers' Choice Awards" Nominations
- Application Virtualization: Instant Migration to Vista, Fast Delivery, Secure Access, Side-by-Side Deployments
- Integration with Windows Vista, Microsoft Excel, and Microsoft Application Virtualization
- "Virtualization Is Now a Key Strategic Theme," Says Citrix CTO
- mValent Extends Automated Application Configuration Management to Virtualization Environments
- Will Microsoft Buy Citrix?
- Has the Technology Bounceback Begun?

































