Re: Release update
On Mon, Mar 29, 2004 at 08:22:56PM +0200, Marco d'Itri wrote:
> Firewalls do not provide security, they are a policy enforcement tool.
> If you think that the default install contains insecure software
> accessible from the network then we can try to talk about it.
Whilst I am not thinking of anything specific I do believe that
we should be trying to reduce the number of network accessible
services which are installed by default.
For example portmap, nfs-server, etc. I am sure that these services
are secure but as a matter of principle I believe that nothing should
be open unless it is explicitly enabled.
That's why I would be pleased if we could offer a firewall question
in the base installer, or install someting by default.
Steve
--
Reply to: