Live data from Hacker News

Ubuntu scores highest in UK Gov security assessment

insights.ubuntu.com

11–20 of 27 posts

Re: Ubuntu scores highest in UK Gov security assessment

#11
post #8

Earlier quoted context omitted.

Care to summarize? Each OS is a different document.

There's not going to be any one line answers but the section https://www.gov.uk/government/publications/end-user-devices-... is illuminating. Not least for recommending the use of TPMs for disk encryption

Maybe I am a crank but I distrust TPM.

Re: Ubuntu scores highest in UK Gov security assessment

#12
Wait what? Secure Boot can be turned off by anyway can it not? It's just it's on by default...

> Ubuntu’s response, from Ubuntu 12.10 onwards is to adopt Grub2 as the default bootloader, with support for Secure Boot, but with anability to turn off secure boot to modify the OS, if required. This is explained in John Melamut’s blog post here [13]. We believe thisgives users and enterprises the best compromise between security and ability to customise after sale.

Re: Ubuntu scores highest in UK Gov security assessment

#13
post #5

Earlier quoted context omitted.

It was apparently written by a Canonical employee, FWIW.

The article was written by a Canonical employee but not the study. If I were Canonical I would avoid writing/publishing such an article, as anything that the government recommends for security is probably seen by many as potentially backdoored.

Don't be ridiculous. Most crypto algorithms that back major standards today have been approved by the NSA, and to date no backdoors have been found. For example, the change to NSA suggested for DES s-boxes _strengthened_ the standard.

[Disclaimer: I am a Canonical employee, but I had nothing to do with this.]

Re: Ubuntu scores highest in UK Gov security assessment

#14
post #13

Earlier quoted context omitted.

The article was written by a Canonical employee but not the study. If I were Canonical I would avoid writing/publishing such an article, as anything that the government recommends for security is probably seen by many as potentially backdoored.

Don't be ridiculous. Most crypto algorithms that back major standards today have been approved by the NSA, and to date no backdoors have been found. For example, the change to NSA suggested for DES s-boxes _strengthened_ the standard. [Disclaimer: I am a Canonical employee, but I had nothing to do with this.]

The A5/1-encryption standard was artificially weakened - short key length with padding of zeros - to make mobile phones easier to eavesdrop on.

http://www.aftenposten.no/nyheter/uriks/Sources-We-were-pres...

Given their past behaviour with respect to weakening security, why ought someone to trust them now?

Re: Ubuntu scores highest in UK Gov security assessment

#15

Systems under test were: - Android 4.2 - iOS 6 - OSX 10.8 - Blackberry 10.1 - Google Chrome OS 26 - Ubuntu 12.04 - Windows 7 and 8 - Windows 8 RT - Windows Phone So pretty much a statement that a modern open linux can be made the most secure.

> So pretty much a statement that a modern open linux can be made the most secure.

Why didn't they test any other Linux distributions besides Ubuntu (and Android, if you want to include that)?

I also wonder why, if they were really interested in conducting a thorough test, they didn't include any of the BSDs (e.g., FreeBSD, OpenBSD).

Re: Ubuntu scores highest in UK Gov security assessment

#16

This raises a lot of questions about Ubuntu if a government that wants to tap everything has no problem and is "indirectly" recommending it for security.

I believe the CESG has done this study to see how other goverment and industrial branches can least be tapped, not to see how it can best tap everyon.

Re: Ubuntu scores highest in UK Gov security assessment

#17

Systems under test were: - Android 4.2 - iOS 6 - OSX 10.8 - Blackberry 10.1 - Google Chrome OS 26 - Ubuntu 12.04 - Windows 7 and 8 - Windows 8 RT - Windows Phone So pretty much a statement that a modern open linux can be made the most secure.

> So pretty much a statement that a modern open linux can be made the most secure. Why didn't they test any other Linux distributions besides Ubuntu (and Android, if you want to include that)? I also wonder why, if they were really interested in conducting a thorough test, they didn't include any of the BSDs (e.g., FreeBSD, OpenBSD).

If its the government, there is no *BSD experience anywhere. I doubt they'd recommend it. Everything is purchased based on the ability to fill the purchaser's pocket on the side. Yes I have witnessed this - I did contract work for NHS and one of the PCTs had taken on a vendor for a cash back promise.

Re: Ubuntu scores highest in UK Gov security assessment

#18
post #13

Earlier quoted context omitted.

Don't be ridiculous. Most crypto algorithms that back major standards today have been approved by the NSA, and to date no backdoors have been found. For example, the change to NSA suggested for DES s-boxes _strengthened_ the standard. [Disclaimer: I am a Canonical employee, but I had nothing to do with this.]

The A5/1-encryption standard was artificially weakened - short key length with padding of zeros - to make mobile phones easier to eavesdrop on. http://www.aftenposten.no/nyheter/uriks/Sources-We-were-pres... Given their past behaviour with respect to weakening security, why ought someone to trust them now?

I don't see where it says NSA weakened the GSM standard in Europe?

Re: Ubuntu scores highest in UK Gov security assessment

#19
post #13

Earlier quoted context omitted.

The article was written by a Canonical employee but not the study. If I were Canonical I would avoid writing/publishing such an article, as anything that the government recommends for security is probably seen by many as potentially backdoored.

Don't be ridiculous. Most crypto algorithms that back major standards today have been approved by the NSA, and to date no backdoors have been found. For example, the change to NSA suggested for DES s-boxes _strengthened_ the standard. [Disclaimer: I am a Canonical employee, but I had nothing to do with this.]

I think you might need to distinguish between the old, secretive, possibly creepy NSA and the current slurp the world volcano lair NSA.

Re: Ubuntu scores highest in UK Gov security assessment

#20
post #18

Earlier quoted context omitted.

The A5/1-encryption standard was artificially weakened - short key length with padding of zeros - to make mobile phones easier to eavesdrop on. http://www.aftenposten.no/nyheter/uriks/Sources-We-were-pres... Given their past behaviour with respect to weakening security, why ought someone to trust them now?

I don't see where it says NSA weakened the GSM standard in Europe?

It doesn't. If you want NSA stuff, here you go:

http://www.heise.de/tp/artikel/5/5263/1.html

Short version: ADVAPI.DLL contains - or contained - keys, one controls the implementation of crypto to help with US export regs. The NSA looks highly likely to own the second key (MS devs failed to remove the debugging information in NT4 Service Pack 5 and it was labelled as 'NSAKEY'.) The third key was supposedly a surprise to the MS folks.

#

That said, I'm not sure why you'd want me to respond along those lines given that we're talking about a UK Gov report.

Post reply on HN