[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Release update



On Mon, Mar 29, 2004 at 08:22:56PM +0200, Marco d'Itri wrote:

> Firewalls do not provide security, they are a policy enforcement tool.
> If you think that the default install contains insecure software
> accessible from the network then we can try to talk about it.

  Whilst I am not thinking of anything specific I do believe that
 we should be trying to reduce the number of network accessible
 services which are installed by default.

  For example portmap, nfs-server, etc.  I am sure that these services
 are secure but as a matter of principle I believe that nothing should
 be open unless it is explicitly enabled.

  That's why I would be pleased if we could offer a firewall question
 in the base installer, or install someting by default.

Steve
--



Reply to: