D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Linux - and security

 

On Fri, 2 Nov 2012, Simon Waters wrote:

Sure Debian have procedures, but we know DDs have inadvertently done stupid things which made testing, and most distros have released horrendous upstream messes (Xorg screenlock bypass springs first to mind).

Sometimes it's hard to know what the impact of some changes you might make might have on something you think is completely unrelated - especially in a very large system - e.g. MS Windows, and now, as it bloats and stretches at the seams, Linux - or more correctly a Linux distribution ...

Here's a wee story...

20 years ago I wrote a MUD. (Multi user Dungeon) In the MUD there was a "safe town" - a place where newbies could wander without fear of being killed - at least not by another player. There was one way you could be killed and that was by dropping mouldy bread in the duck pond - where you'd kill the ducks and an angry god would them smite you for killing his ducks.. (There is a puzzle that involves dropping something else to feed the ducks to gain gold)

And all was well...

Until some time later (over a year or 2!) a new magic system was implemented, and a "fumble" spell was created. You could cast the fumble spell on a player and they would drop something... Usually the last thing they picked up, or was given...

So a wily player worked out that they could summon a player to the duck pond, give them the bread, then cast the fumble spell, causing them to drop the bread, thus killing them - the player killed would lose some score (and as it was a percentage, if you were a high level it was worse).

So that's just a game, and I never bothered coding round it - left it in as a "feature", but while it's just a game, it's also a demo of how one seemingly un-connected change can be used/abused by others...

That's the sort of thing that's now (or always was?) happening in big systems - it's these sort of seemingly unconnected things causing undesired actions - and they're hard to track down!

Constant vigilance, etc.

Gordon

(and the MUD's still running FWIW)

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq