Note to IBM... Wuz Re: Informix Warehouse Accelerator Prerequisites
Posted in 2011
So it took 20 years for this security hole to get fixed? Kinda shows how certain product managers treat security. Oooh Snap! Sorry Jerry, I guess closing security holes just aren't high on the customer's wish list so that they take a back seat to a failed product. Ok, sorry, that was unfair. Red's comments are valid because he is questioning what is written on IBM's site. They say it's a prerequisite and frankly changing to ssh is *trivial*. Getting back to Fernando and the Morris worm. Not everything was made public so it wasn't captured in Wikipedia. In order to use .rhosts as an attack vector you already need access to the machine as root. So the question is... How did the worm get on the machine in the first place? I think that was made public... But don't feel too bad. It tok 8-10 years for Sun to fix it... Just out of curiosity... Wall something or other is one of IBM's largest customers as well as one of Informix's. One has to ask how many copies of IWA have they purchased? The reason I ask this is that there's a group from that company based in SF looking for Hadoop expertise. Somehow even there, I doubt that Tom Deutch's winning personality is going to get them to even consider IBM as their Big Data vendor of choice. (Duh Winning!) But hey! What do I know? Ok, just to be serious for a second... IWA is a dead product out of the gate. You can not make a value proposition that makes sense. It's too expensive and doesn't scale. There are already alternatives on the market that offer a much better value proposition and have a referencable market base. To start with a relatively small customer base, you are creating a further niche product. It a loss right out o the gate. It's as if someone is trying to pull a rabbit out of their ass just to make IDS relevant when customers' dollars are being spent on big data. This is a losing strategy. This isn't to say that IDS is a bad product. It isn't. As I have said in earlier posts, IWA is based on stuff done in the Financial Foundation data blades. 10 years ago it would have been interesting. Today? Not so much... It's a joke. Especially when the answer is staring back at them, right in front of their face! It takes bright product managers as well as division execs to recognize what they have and how to properly utilize their talent. And this boys and girls is what IBM is lacking... On Aug 22, 2011, at 2:56 AM, Fernando Nunes <domusonline@gmail.com> wrote: > > > On Mon, Aug 22, 2011 at 4:08 AM, Ian Michael Gumby <im_gumby@hotmail.com> wrote: > IBM/Informix has in the past talked about using .rhosts and the hosts.equiv . Has this changed? > Why are .rhosts and hosts.equiv bad? You're too young to remember Morris and his worm... > > > You know... There is a thing called Internet that helps us youngsters to learn a bit about the past. But what you always deny each time we discuss this is to recognize that his famous worm took advantage of the widely spread usage of the infamous r* services. And what I keep asking and you never answer is why the hell are you running them, or if that is not the case, how is the /etc/hosts.equiv and .rhosts so insecure? And yes, since 11.70.FC2 you don't need to use those files. > > This isn't really off topic because Red raised a security question based on something in IBM's documentation and choice in tools... > > It's already clear that his concerns are based on incorrect assumptions. > > Regards > > -- > Fernando Nunes > Portugal > > http://informix-technology.blogspot.com > My email works... but I don't check it frequently...