View Single Post
Old 12-17-2011, 12:24 AM  
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
It's a very delicate balance, how much cooperation there should be between NSA security experts and the businesses you trust with your data. When the NSA was looking for the most secure OS for their own systems, they chose Linux. They then released certain security improvements they made for their own use, so that companies, including yours, could have this advanced security.

Only after the improvements were fully vetted so that we in the private sector know that the NSA didn't include anything sneaky, we are now able to include this NSA level security in our own systems. That's great - your Linux web server can now have the same security that the NSA has. We at RMEE were contracted to develop a similar security layer and I'm glad we didn't have to take it quite to that level because NSA did it for us all. Ours could just be a comparatively simple preload based system to control file access by different programs.

On the other hand, when working with security groups which include government employees, how much information to give is always a question. I tend not to worry too much about the NSA because they are so focused on the really big fish. They are watching Ahmadinejad and don't give a crap what's on your web site, so long as you're not selling nuclear weapons.
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote