kha0S Linux - It's all about Security 89
F1reF0x wrote to us with an interesting
story on Linux Today about kha0S Linux-a distribution primarily based on creating the most secure distribution possible. You can check out kha0s.org. Due to the United States "interesting" crypto laws, 0.99-pre4 is not currently availible on the FTP site.
Re:This should never have been developed in the US (Score:1)
p.s. - I am a US citizen
And what if you decided to make a distro like this? Are you going to move to another country before creating just so you can distribute it when it's done?
Adressing the concerns/confusion/questions. (Score:5)
1. Export regulations. We do have developers in other places besides the US. We also have distribution points that are not located in the US. The project leadership does originate in the US, but that does not limit us from at all. All cryptographic components are worked on by developers outside the US, and distributed from sites outside the US. There is more to this distribution besides the cryptographic components, and therefore US developers are not hindered from helping out with the project. We do audit ALL source code that has been released, and we invite you to do the same.
2. Backdoors and code auditing. Since we do audit the code, and invite you to do the same, there need not be any worries about backdoors. We are trying to PROMOTE security and the idea that linux is a secure OS. By putting backdoors in code this would not only hurt our credibility, but the credibility of the linux community in general.
3. The 'lame name'. Ok. This one is not quite as complicated as you all may think. It comes down to several things really. First, as someone else has pointed out, the name is mainly based on myth and legend of the golden apple, inscribed with Kallisti. Planted by the goddes of dischord, or chaos. Now, whoever has lately tried to reserve a domain name can tell you, try getting chaos.org, or net, or whatever. So, we had to be creative. Does it sound a little bit 'script-kiddie'ish? Probably. Can the name change? Maybe. Does everyone like the name? Probably not. Do we care? Doubtful. It comes down to this: If you like what we are doing, great, if not, great.
In closing, we are not asking anyone to trust us. In fact, we are hoping you don't. Be paranoid, check out our code. We invite you to, as we have.
kha0s is not for the light of heart in this stage. In the future this will change as we add things to the distribution to allow seasoned professionals and newcomers alike to install, configure and run kha0s without having to worry about whether you did or did not forget to turn on ssh and disable rlogin.
Should anyone wish to learn more about the project, or help in the development effort, you can subscribe to our mailing list. Send an email with the subject: Subscribe to kha0s-dev@kha0s.org and you will be subscribed.
M. Adam Kendall
mak@kha0s.org [mailto]
http://kha0s.org [kha0s.org]
Re:Good to see a less insecure linux (Score:1)
In the short run I'm sure this would result in FUD about functionality, but I bet it would be a strategic win for the reliability and security reputation.
Can none of you Read English? (Score:1)
Re:The USA is not such a free country after all (Score:1)
Re:This phucking distro is unhelpfully lagged (Score:1)
For those who are interested, the source tree is a bit sparse at the moment. Again, this is due to the fact that our snapshots have been primarily for 'in-house' use at this stage. This will be rectified over the weekend when it is tarred up and moved to the ftp sites.
Scott Fallin
saf@kha0s.org
Re:Yeah, but what if... (Score:1)
Re:9th Circuit says its legal. (Score:1)
Are they seeking C2 certification? (Score:1)
Yeah, but what if... (Score:1)
So we just add a backdoor to the C compiler. It can tell when it's compiling another C compiler and adds the back door to it. It can tell when it's compiling, say, login, and adds a back door to that. Then you just throw away the original sources and compile a compiler with your new compiler. Include that compiler and its sources to your distribution.
Just because you're paranoid doesn't mean they're not out to get you.
Re:I'd rather not find the pot of gold at the end. (Score:2)
However, speaking as a user, and having bosses that want functionality first and security second, I feel I can safely back up my claim that the general populace want security second. I don't care how secure it can be, if its difficult to use it won't be used or it will be used improperly. I am constantly arguing the benifits of an application level (proxy) firewall over a circuit (packet filter) based firewall. Its a lost cause, the monitary benifit will almost always outweigh your perceived gain in security.
This hopefully means that the only thing I will have to do to ensure my computer is "safe" will be to check for their security upgrades, instead of keeping track of CERT advisories, rootshell.com, et.al.
Yikes! Now that is a scary notion. Microsoft, Sun, SGI, HP, Red Hat, etc... all fail at this. Even relying on Bug Traq and the like for your security measures is only a secondary response to a primary issue. If someone is good enough, they will get in. And a distribution like this will give people like yourself a false sense of security. You do what you can, where you can, when you can. And you keep doing it over and over. You build application architectures as securely as you can, and then limit access to those applications to only the people who need the access. Then you stick in your safe guards against those who would attempt to thwart those restrictions. A generic rule of thumb at best, yes.
In very few cases are functionality pushed down because of security. It is usually the other way around. All the functionality can usually be kept by doing things a little different. A little more secure.
How large a network do you work in? Did you build the network yourself or did you have to take it over? How large is your security team? Maybe you know something fundemental that I don't. Security isn't as easy, and when you talk to the bean counters, if the possible loss isn't high enough then security will be pushed under the rug.
Again, I do think its nice that this distro is coming out, I do applaud thier efforts. But no one can make a secure Linux or *insert OS here* distribution that will make me any happier. The secure distribution that is best is the one you put together yourself for the job at hand. You do this by taking the one that is easiest for you to use (the one you feel most comfortable with) and shredding it to pieces. Leave nothing but what is absolutely needed, then secure it - first from the network, then from the users.
Re:ftp.khaos.org - why keep it in the USA? (Score:1)
Think practical tracking. It's not hugely likely that the development of this distribution can be geographically traced. So, if they'd never announced that it had originated in the US then they could have probably got away with burning a CD, taking it over the border _then_ uploading it. One advantage for community development here -they can't necessarily tell where you are when you write something, but it's pretty obvious where the MS campus is...
Greg
Re:This should never have been developed in the US (Score:1)
But if I wanted to do what khaOs is doing, I'd have to choose between moving and not doing it. And I am unhappy about it, too. I used to think this was a free country, but when it doesn't allow me to share the product of my intellect even when it doesn't infringe on my neighbors' rights and freedoms...I declare those rights and freedoms to be gone.
Why the Netboy Speak? (Score:1)
I just want to know why the net-boy speak for the name of the distribution. Can you see the guys on irc #linux now:
#m0j0f1ght3r> I run the fr33kin' kha0s, y0u w0n't b3 abl3 to crackz my a$$.
That is why I think I might try one of the other secure distributions that were anounnced on BUGTRAQ.
Than again, I could be dead wrong, and the name could be like danish or sweedish or something...
-AP
Ummmm.... (Score:1)
--
A mind is a terrible thing to taste.
Re:Why the lame name? (Score:1)
They tend to write things like
Crypto development should be moved overseas (Score:1)
They should immediately release the code less the crypto log. subs. and develop those elsewhere to make a product that the U.S. export laws can't touch.
Re:ftp.khaos.org - why keep it in the USA? (Score:2)
If you're talking about export regs, that question is irrelevant. If you have strong crypto code within the US, it is illegal to export it even if it was imported. The place of origin is irrelevant.
BTW, NAI [nai.com] has a neat way of dealing with it. All these export regs do not apply to source code in the form of a printed book. Publish, scan, and compile. And, voila! Legally exported code. NAI does this to ship their code to their international site [pgp-international.com] in the Netherlands.
Other secure linux projects. (Score:1)
Re:This should never have been developed in the US (Score:1)
Re:The USA is not such a free country after all (Score:1)
The US is free for US citizens, NO ONE ELSE. There are tens of millions of people detained and kicked out of the country every year for entering the country illegally, or simply for not having the appropriate paperwork. The US is hardly responsible for the freedom of people outside of the US.
Re:Why the lame name? (Score:1)
Re:Backdoors (Score:1)
Re:The USA is not such a free country after all (Score:1)
Who said US was responsible for freedom to non-US citizens? The beyond-stupid export regulations bring more harm than good. IMHO the same applies to the constitutional right to possess a 12 gauge shotgun; sure it's every person's right to protect their home, but AFAIK gun-related deaths/accidents outnumber homes actually saved by having a gun in the house. Don't get me wrong. Surely the Congress or the House of Senate means well, but unfortunately things don't work the way they should.
This is a good thing (Score:1)
i always wanted to see such a distribution and to see how it will perform against OpenBSD
Way to go guys
Backdoors (Score:1)
Crypto laws (Score:1)
Re:Crypto laws (Score:1)
also the decision only pertains to source code or algorithms. as these are in (relatively) clear language they are subject to free speech protection. OTOH if it's a binary release it's still subject to current restrictions.
This should never have been developed in the USA (Score:1)
p.s. - I am a US citizen
Re:Backdoors (Score:1)
Linux is GPL'd, and if they keep everything open source then you can get the source and compile it youself.
But if you are paranoid to this point you can do your own secure distro
Why the lame name? (Score:1)
Re:Backdoors (Score:2)
When such a distribution becomes available, I imagine that lots of people will be taking a very close look at the source, to check for back doors... that's one of the big strengths of Open-Source - it's very hard to "slip something in" without it being easily noticeable.
ObMSbash: compare and contrast NT - do you trust all of Microsoft's programmers?
Re:Backdoors (Score:1)
I would rather trust MS programmer's, they have a lot of good programmers, what i wouldn't trust is their high management.
But in the case of crypto this is not only the management that is bad, but the state too. They must do edulcored versions of the encryptions algorithms to export their products.
I'd rather not find the pot of gold at the end... (Score:2)
I applaud efforts such as these, and I hope the end up with a successful distro. But I doubt they will. No matter what the headlines read, people want functionality before security. And while I hope to enjoy the fruits of thier labor on such a project, I will most likely never use it in production.
Instead I will end up looking at how it works, and taking the bits and pieces that I think I can gain the most secure functionality from. Possibly even repackaging them for easier installation on my own personal favorite distribution.
A grand idea indeed. But I much prefer the right tool for the right job approach, then the use a flamethrower to light my cigarette approach.
ftp.khaos.org - why keep it in the USA? (Score:2)
Re:Backdoors (Score:1)
By your reasoning any code can have a back door. Much of it may even. But at least with Open Source type stuff you get the code and can check if there are backdoors. Hey you could even use those same backdoors. Anybody could do it. Apple, M$, Amiga, SGI, Red Hat, Debian, any distributor could. If you buy the disk and run it straight from the box then you are implicitly trusting them not to have put an undocumented hole in your system. Or at least trusting them not to use that hole. Actually its possible that any software you install has this implicit hole. Well at least if you have to install it as root or the equivelevnt.
If you are that paranoid then write your own OS or read all of the source. Otherwise you aren't truly paranoid
-cpd
Re:Why the lame name? (Score:1)
Re:Why the lame name? (Score:1)
insanity is a stateof beingcommonly misunderstood by the masses as an undesirable trait.....
there -> their (Score:1)
Re:ftp.khaos.org - why keep it in the USA? (Score:1)
Doug
Why "bsd-style"? (Score:1)
I can imagine the need for a line by line examination and I know there was a project out there that was doing that, dunno if kha0s is. But why adopt the bsd-style development?
---
Put Hemos through English 101!
US Export Regulations (Score:1)
Translation for the non-133T (Score:1)
I ran it through the de-kiddigizer.
Not really... (Score:1)
A little later in the dev cycle, I really want to try this distro out...
Re:Yeah, but what if... (Score:2)
In every system you have to put your trust somewhere (or to recode all in hex like the precedent poster did). In this case I would rather put my trust in RMS and the FSF than in any closed source software.
Of course you can do what you did (and this already have been done) but you can do a program that check for this kind of backdoor too I think. or you can compile the things in assembly language and then verify that their is no back door before feeding it to the assembler (don't know if this is the correct English word). Of course this can be the assembler that implement the back door...or this can be the linker that add the back door at loading time.....
Re:Backdoors (Score:1)
Re:ftp.khaos.org - why keep it in the USA? (Score:1)
On the other hand, US/Canadian people with 128 bit ssl who don't mind leaving verified and logged data will be able to get those packages soon, and I think that I can get a written guarantee from the BXA that they will not ask to see the logs without a very specific subpoena. Not optimal, especially for the privacy advocates, but good enough for a start.
And all of the stuff that I am working with was done outside of the US, too.
This will pass y'all -- it is just a matter of time. WRITE YOUR CONGRESSMAN AND SENATOR ABOUT IT. Email gets you nowhere. Use good paper, too, and provide contact info. Make your voice heard on this and it will change.
Then I won't have to worry about jail for trying to keep Linux on my Thinkpad with minimal security.
When they came for... (Score:1)
"When they came for the Jews, I did not resist, as I was not a Jew.
When they came for the Blacks I did not resist, for I had fair skin.
When they came for the Muslims, I did not resist because I don't pray to Allah.
When they came for the Atheists, I did not resist because I believe in a higher power.
When they came for the Christians, I resisted, but no one was left to fight for me."
Don't let shortsightedness condemn us all.
Re:Why the lame name? (Score:1)
I know a number of people who are very capable of analysing systems for potential or actual security problems, yet I doubt any of them have broken into a system for years.
Good to see a less insecure linux (Score:2)
Re:Backdoors (Score:1)
Re:I'd rather not find the pot of gold at the end. (Score:1)
Security is important. And it is very nice to see a security oriented distro like this one come out. This hopefully means that the only thing I will have to do to ensure my computer is "safe" will be to check for their security upgrades, instead of keeping track of CERT advisories, rootshell.com [rootshell.com], et.al.
That is of course only if I feel I can trust the kha0s people to do their side.
Having a security oriented distro might also make RedHat, SuSE, Debian, etc. incorporate some of the ideas as well, and we will all be much happier.
In very few cases are functionality pushed down because of security. It is usually the other way around. All the functionality can usually be kept by doing things a little different. A little more secure.
Re:Why the lame name? (Score:1)
certianlymore interesting than say Red Hat, or caldera
also on a ftp in europe as far as i could tell (Score:1)
ftp.replay.com
Due to U.S. restrictions on the export of cryptographic material, 0.99-pre4 is not available at ftp.kha0s.org
"
this is from their own site...www.kha0s.org, and the ftp site they mention there, ftp.replay.com DOES have the
weird eh?
kha0s - Lame name, good idea (Score:1)
Anyway, I would like to see this thing offer GPL alternatives to SSH 2.0 and PGP, along with all the tools that come with the two floppy distribution, Trinux.
I wonder if Packet Storm Security [harvard.edu] has posted a link to this yet...
Re:Good to see a less insecure linux (Score:1)
i take it back (Score:1)
Re:ftp.khaos.org - why keep it in the USA? (Score:2)
Take SSH. I assume it will be in this distro. SSH is currently located in Finland. Putting it in an american based distro is import, not export. (Why are there no legislations on importing things the american government don't want to be exported?)
But since a distro is basically a collection of software, how can anybody say for sure that it was collected in the USA? If say, i log into an ftp server in Belgium on a shell account, and then downloads the software packages from servers in Finland, Norway, Iran, whatever to that computer. Bundles them together and call them a distro. Even if I do that from the US, I still haven't exported anything, since none of it has come through the US.
Re:Why the lame name? (Score:1)
To me it sounds like you are just angry that they may be just rying to come up with yet another viable Linux Distro. apparently you are a programmer according to your web site. Download it try it and then complain about what they may be. Im sure you dont write all of your code by hand either.
Re:Why the Netboy Speak? (Score:1)
Re:Why the lame name? (Score:1)
Re:Why the lame name? (Score:1)
not worth much (Score:1)
sc
packetstorm has been taken down. (Score:1)
www.attrition.org has all the juicy details.
Re:Why the lame name? (Score:1)
=)
-awc
Re:I'd rather not find the pot of gold at the end. (Score:1)
Re:kha0s - Lame name, good idea (Score:1)
-awc
Re:Backdoors (Score:1)