Interview with Scott Mann, co-author of Linux System Security: The Administrator’s Guide to Open Source Security Tools, 2/e

Who is Scott Mann?

I am a computer jockey by profession. I’ve been working with UNIX and TCP/IP for nearly 25 years. Windows for 8 years. I’m also a sometime auto mechanic. Basically, I just like getting things to work.

How long have you been working with Linux, and how did you get interested in it?

I started fooling with Linux in 1995. I was intrigued by an open source UNIX-like operating system – having source code made figuring things out so much easier! By 1996, I was using Linux for a variety of purposes, it is such an inexpensive way to get a UNIX-like box. Beginning in 1997, I was using it for firewalling, routing, education, and a variety of similar uses.

How did you gain interest in computer security?

In the mid-80’s, I was a programmer who had an interest in how operating systems worked. At that time, the UNIX administrators I worked with also had the responsibility for either mainframes or VMS systems or both. Often, I needed to get things done and couldn’t get the administrator to do what I needed (either because he didn’t know how or didn’t have time). So, I’d figure out ways to gain root access and do it myself. Of course, today, such behavior is unacceptable. But then, the admin didn’t even know what I had done. In 1987, I officially became a UNIX administrator in a University environment. I became “interested” in security because I got tired of all the tricks students were playing on me! I had to figure things out and put things in place to stop their activities. At the time, I really didn’t think of it as “security”. By 1993, I was involved with all sorts of activities specific to limiting access, hardening systems, and monitoring networks.

How long did it take you to co-write “Linux System Security: The Administrator’s Guide to Open Source Security Tools, 2/e” and what was it like?

It took about 6 months. I find writing about technology to be interesting, challenging, fun, and tedious. It is interesting because I always learn something new. It is challenging because I really want to write in a “how-to” style and it takes a lot of work to get it to a point where people can both use a “how-to” and learn from it. It is fun when people read it and figure things out from it. The tedium comes from the copyediting, the re-reading, the re-writing…

In your opinion, where does Linux need the most development at the moment?

I still think that there are two major areas. The first is application support. Application developers (everything from word processing to databases to games) have been slow to adopt Linux as a platform. A lot of this can be attributed to the economic climate over the last three years, but at least some of it is attributable to the second area of development need.

The second is ease-of-use/ease-of-administration. Although the desktop environment (either gnome or CDE) has gotten much better, there are still major issues with configuration and administration. Simple things like configuring X-Windows still requires considerable knowledge under certain circumstances. Adding devices and device drivers can still challenge the most adept administrators. Configuring a Linux firewall, for example, is quite a challenge.

Better documentation and better GUI interfaces will make a huge difference, but these things take a lot of time and effort. It is getting there, it just has a way to go.

What is, in your opinion, the biggest challenge in protecting sensitive information at the enterprise level?

Unquestionably, the biggest challenge is with the people within the enterprise. All the technology in the world won’t prevent someone from giving out their password or doing damage to a compute environment.

What’s your take on the adoption of Linux in the enterprise? Do you think it will give a boost to security?

I think that it has been slowed by the dot com bomb, but the evidence that it is moving into the enterprise is everywhere. Even IBM offers Linux on an LPAR and they’ve got customers using it. The biggest limiting factor with its adoption in the enterprise, I believe, is the knowledge required to provide various higher end functionality. It is one thing to set up a Linux desktop or server, another to configure a Beowulf cluster. Because there is limited support for Linux, administrators have to become much more knowledgeable. Although this is also true with commercial UNIX systems (Solaris, AIX, HP-UX, etc.), those commercial companies offer a variety of support services including customization and consulting. Often, with Linux, the best support available is a newsgroup or email alias. Having said that, though, there are many companies that are offering customized Linux solutions – it’s a very different business model and not as prevalent as commercial UNIX offerings.

I believe that it definitely provides a boost to security, generally. Anything that can be done for security can be done on a Linux box more cost effectively and, because of the open source nature of Linux, more customizably.

What do you think about the full disclosure of vulnerabilities?

I’ve always felt that full disclosure of vulnerabilities is critical. The bad guys are going to find out about them whether they’re disclosed or not. By disclosing them fully, administrators minimally have an opportunity to do something about them.

What are your future plans? Any exciting new projects?

Right now, I’m enjoying C++ and Java coding and fixing old cars in my spare time. I’m doing a lot with networking these days, so I’ll probably end up doing some work on the network administration book.