Why is Debian not secure by default?



Hi.

After having brushed up on some technical aspects of security I would
like to understand why Debian isn't secure be default.

As we all know a lot of security breaches occur because of overflow
errors. Difference protective measurements has been developed for
example such as "executable space protection".

As seen in this list of comparison both Fedora and SUSE are running
with some method of protection enabled by default whereas Debian isn't.

http://en.wikipedia.org/wiki/Comparison_of_Linux_distributions#Security_features

Another example is "stack checking" in GCC where for example OpenBSD
ships with this setting as "enabled-by-default" whereas it is
"off-by-default" on Debian.

I would like to understand why Debian is running with this policy of
"security is off by default"?

Kind regards

RS


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx
Archive: http://lists.debian.org/20110123072917.6f210f96.coolzone@xxxxx



Relevant Pages

  • RE: Scary article in Wall Street Journal today
    ... Debian systems unless the user logs in as root to allow installation? ... I'm the OP on this thread, so by no means an authority of Debian ... I'm aware of various security measures that *are* realistic defense ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Fwd: Configure wifi access / Free.Fr / WPA (TKIP/AES)
    ...  I am trying a very simple task: connect to my wifi using a my debian box. ... network-manager and select 'Connect to Hidden Network', set security ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Why is Debian not secure by default?
    ... As we all know a lot of security breaches occur because of overflow ... with some method of protection enabled by default whereas Debian isn't. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Why is Debian not secure by default?
    ... As we all know a lot of security breaches occur because of overflow ... with some method of protection enabled by default whereas Debian isn't. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Iceweasels UserAgent
    ... conditions like using the lastest versions of Firefox to address security ... Debian did not agree to all the conditions and thus Iceweasel ... but putting "Firefox" in the user-agent string could not possibly ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)