By Jay Lyman LinuxInsider Part of the ECT News Network
11/24/03 9:46 AM PT
IDC analyst Dan Kusnetzky told LinuxInsider said the Debian hack was a disappointment, but added that it proved the Debian project's security checks and balances, as well as the ability to respond quickly to vulnerabilities, are all working properly.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
Several computers supporting the 10-year-old Linux development project Debian were compromised by hackers late last week, causing a delay in the release of the latest distribution of the operating system and disrupting services for the project's 1,100-plus developers.
Leaders of the open-source software project disclosed the hack -- which compromised Debian bug tracking, e-mail, security and other services -- and were working to reinstate Debian sites and services this week.
"This is a very unfortunate incident to report about," said a statement on the Debian.org site.
Some might view the hack -- which comes after reports of the Free Software Foundation's GNU project servers being compromised last spring -- as a black eye for open-source software development. But it is also a "badge of honor" and a sign that Linux is coming of age, IDC analyst Dan Kusnetzky told LinuxInsider.
"They have been successful to a point that they are now a target of such things," he said. "It's a sign that their product is in serious use."
Compromise Cleanup
Officials with Debian, an open-source Linux distribution project started in 1993 by Ian Murdoch, said they had "a reasonable overview of what happened to the various Debian servers" and indicated they were working to address the issues.
The group said services run by the compromised servers were shut off and the Debian archive would need to be verified from trusted sources before it was available again.
"All services on those machines have been shut down or moved to different machines so we can take the necessary time to determine what happened and restore the machines," a Debian leader said in a posting.
The group indicated it would explain exactly what happened and how to prevent future compromises when it has all the facts.
Bad Guy's Back Door
Independent security expert Ryan Russell told LinuxInsider that the Debian hack, as well as other open-source development compromises, are part of a trend.
"One of the things we're seeing lately is a lot more open source and related security projects being attacked," Russell said.
Russell said the goal of the open-source attacks appears to be the placement of back-door programs that attackers can leverage later when the software is in use.
Proof of Process
Kusnetzky said the Debian hack was a disappointment, but added that it proved the development project's security checks and balances, as well as the ability to respond quickly, are all working properly.
"It appears the procedure worked and this didn't go anywhere," he said. "The fact that the process of review caught this and eradicated it shows the process is working."
Kusnetzky, who said motivation for the attack ranges from political to "ego boost," indicated that the overall impact on Debian will be positive, as the Linux distribution is now on a road already traveled by major software makers such as Microsoft (Nasdaq: MSFT), IBM (NYSE: IBM) and Sun.
Badge of Hacker
Kusnetzky said the fact that the Debian project was attacked will likely have no bearing on the software distribution, but added that the incident might cause some to stay away from open-source software.
Russell said that, in a perverse way, the hack and any attempts to place back-door access into Linux distributions indicate a sense of legitimacy for the open-source movement. Russell cautioned that the placement of back-door code can be subtle, as was the case with a recent effort to compromise the Linux kernel.
"It's disappointing in the sense that one would hope these projects -- which are free, are used and loved by developers -- would get some slack," Russell said. "That doesn't appear to be the case."
Open Source in the Land of Oz November 22, 2003
Computer Associates recently ran a customer survey in Australia and New Zealand that showed 25 percent of respondents currently have Linux deployed in production and an additional 45 percent are considering it.
Related Stories
Network Security Evolves: An Interview with CA's Ian Hameroff November 21, 2003
"Any computing platform, if left in a default state and poorly maintained over its lifetime, could quickly fall prey to even the most unsophisticated hacker," Ian Hameroff, Security Strategist at Computer Associates, told TechNewsWorld.
Open Source and the 'Not Invented Here' Syndrome November 20, 2003
What made the open-source process so insanely great was the almost complete absence of "not invented here" syndrome among its earliest and strongest backers -- including both Linus Torvalds and Eric Raymond.
SCO CEO Defines, Defends Legal Strategy November 19, 2003
Aberdeen Group research director Bill Claybrook, who likened SCO's legal setup to "a hired gun to go out and kill people in the Old West," said SCO's latest statements are simply an extension of threats the company has already made. "Every time SCO elevates this, they become more hated," Claybrook told TechNewsWorld.
GandhiCon Three and the Antics of SCO November 19, 2003
This column was originally published on September 3, 2003, and is brought to you today as part of our Best of ECT News series.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.