Robert Pogson

One man, closing all the windows.

Daily Archives / Saturday, June 16, 2012

  • Jun 16 / 2012
  • 13
technology

US-CERT Shows the Value of FLOSS

A US-CERT notice of vulnerability to many systems running many OS on Intel 64-bit processors shows the value of FLOSS:

  • for years Wintel systems were vulnerable to privilege escalation attacks due to a flaw in Intel 64-bit CPUs,
  • notified in early May of the flaw, M$ took a month to push out an update compensating for the flaw, and
  • Debian took 2 days to fix the flaw.

Once again the importance of diversity in IT is shown. Relying on M$ and Intel for all your IT is a recipe for disaster. It is only luck that prevented the collapse of IT as we know it had cyber-whatnots found the vulnerability first. Eventually, that will happen. When it does, having Wintel running IT will be your worst nightmare. What’s running your IT?

I recommend Debian GNU/Linux. It will work for you.

see US-CERT Vulnerability Note VU#649219 – SYSRET 64-bit operating system privilege escalation vulnerability on Intel CPU hardware.