You are here: silicon.com > Software > Security Strategy

Security Strategy

Ubuntu security concerns sparked

Rogue servers go on the attack...

Tags: servers, security, linux, ubuntu

By Colin Barker

Published: 17 August 2007 08:37 BST

Concerns over the security of the Ubuntu Linux distribution arose when five out of eight community-run servers sponsored by Canonical had to shut down.

The servers had "started attacking other systems", according to an Ubuntu newsletter. The issue first came to light at the weekend, when Ubuntu users voiced concern over a problem with local community (loco) hosted servers.

Canonical moved quickly to minimise the issue and reassure users that the operating system is secure.

Gerry Carr, marketing manager of Canonical, said: "This is not a problem with our production servers." The issue was with "loco servers that we pay for but that do not sit in our data centre", he said. As a result, the security in Canonical's data centre was "in no way compromised by these attacks".

While the company "held its hand up" in regard to the problem, it completely rejects any implication that user security was compromised, Carr said.

He said: "Any [implication], and there has been some, that this episode has, or had, any bearing on our enterprise readiness or the Ubuntu downloads is so completely wide of the mark as to miss the point entirely. It has nothing to do with downloaded copies of Ubuntu; it is separate servers on a separate network in a separate location."

But the company did accept that the servers had been poorly managed. The problem arose because the responsibility for security lay "between Canonical and the community", Carr said.

Most of the time this was just as it should be, Carr said, but "server management is maybe not one of those times".

The issue is one for the community to decide, he added: "Either the loco servers come into our data centre and are subject to our standard, rigorous security and management, or they sit completely outside of it and are run by the community."

Colin Barker writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Certified Data Centre Project Engineer

Certified Data Centre Project Engineer Experience: Relevant/Related industry experience Annual Salary: circa 25000-28000 Depending on experience ...

Hardware Engineer -Data Center

Must be flexible to work on-call & occasional second and weekend shifts.Other:1. Job Title:Hardware Engineer (Data Centre) Location:Dublin, Ireland ...

Operations Technician Weekend role

Weekend role LOCATIONDublin 15SALARY? Ability to teach, learn from and communicate with others.Supervisory Requirements: This position has no direct ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: