A thesis: Sun should fork Solaris

Right now, Sun has two markets for Solaris, that being the people whoalready run Solaris (their current customers), and the people that Sunwould like to persuade to run Solaris, based on attractive things likeZFS and DTrace.

The first group has generally been running Solaris for years (usually onSPARC, which is one reason that it lingers on). They care a lot aboutbackwards compatibility, and so they want Solaris administration and soon to keep working just the way they are used to.

The


My view on vi and vim (and nvi et al)

I have a confession: for all that I use it fairly often, I am a fairlybasic user of vi. As such, I have a pretty unsophisticated view ofwhat vi is; if I type ' vi ' and something starts up that behaves likevi and is not too freakishly super-intelligent ,I call it vi and don't think more about it, regardless of the nameof the actual implementation. Unless I actively think about it, I'monly vaguely aware that there are at least


Server problems caused by 'transparent' self-signed SSL certificates

One of the issues with allowing self-signed SSL certificates to beautomatically used for transparent encryption over https URLs is theproblems that they cause for server-side applications.

Right now, a server-side program that care can more or less assume thata SSL-encrypted connection means either that it is securely talkingto the real end user's machine or that the end user has been activelycompromised (which it can't do anything about). It may thus use thingslike 'you can only talk


Good editors aren't better or worse, just different

It's common to compare text editors and say that one is better or worsethan another. But after a certain point this is wrong. Editors are oftennot better or worse but different than each other, each better atspecific things. Such differences mean that there is no absolute scaleof better and worse, and indeed that the question of which is a bettereditor in general is meaningless.

Let me illustrate this using the differences between the three editorsthat I use most frequently:


Why rootkits targeted at Red Hat Enterprise would make me especially nervous

A while back, I wrote in passing that I wouldbe especially nervous if I ran across a rootkit that specificallytargeted Red Hat Enterprise systems (for example, to the extent ofcorrupting the RPM database checksums ). TodayI feel like elaborating on that.

(Right off the bat I'll say that it's not because we use RHEL here.Our use of RHEL is small and so far none of it is in machines thatare particularly exposed to users or the world.)

What would make me


The practical insecurity of self-signed SSL certificates on the web

Here is a modest suggestion from the devil's advocate: web browsersshould forbid self-signed SSL certificate entirely, with no 'no,really, let me through' button, option, or extended dialog . They should do this because in practice and ingeneral there is no way to make self-signed SSL certificates at allsecure.

Self-signed certificates are insecure in general unless you reallytruly know what you are doing. Most users do not know what they aredoing in this sense, and for


One consequence of mathematical security thinking

This realization struck me after writing yesterday's entry :

One consequence of the security paranoia way of thinking (or if youwant to use the polite term, of the mathematically correct security way of thinking) is that false negatives areconsidered unacceptable. Either they are flaws in the implementationor they are flaws in the theory underlying the security system, and ineither case they must be eliminated; it is incorrect to allow one toremain.

(By false negatives here I mean situations where the security systemfails to detect


The problem with security alerts, and indeed all alerts

We know that in practice, users have been conditioned to treat securityalerts and other caution dialogs as obstacles; they will blindly clickwhatever option makes the dialog get out of the way of whatever they'redoing, no matter what. It has recently struck me that there is an obviousreason why, and it's even something I've written about before: it's theproblem of false positives .

Unless you have really serious problems, your system is almost alwaysdoing what you want and you almost


My sign of a good graphical interface

Here is a thesis I have about really good graphical interfaces,especially in the context of text editors:

In a good graphical interface, you not only can use the mouse, you want to .

There are a good number of graphical interfaces that are ordinaryand decent and good enough. They make effective use of the mouse andgraphics, they're nice, and they by and large fail to fill me with anyparticular actual enthusiasm for those graphical features. They're justsort of there, in an ordinary


Why I hate 'security questions'

You know 'security questions'; they are the extra questions thatwebsites (and other services) attach to your account that willtheoretically let you regain access to the account if you forget yourpassword. I really don't like them, and it's not because they are aterrible security idea. Well, not directly.

Hopefully everyone already knows the primary problem with securityquestions: if you pick questions and answers that you can remember, it'squite likely that an attacker can work out the answers