Slashdot Mirror


Aussie Uni Dumps Dual-Boot In Favor of Linux

kNIGits writes "News.com.au is reporting that the University of Wollongong have dumped their previously dual-boot installations in favour of booting Linux only. Among other reasons, staff enjoy the ease with which they can 'lock down' first year students, stopping them messing with the systems prior to learning anything about them."

344 comments

  1. Hehehehe... by Pig+Hogger · · Score: 5, Interesting
    Linux to lock down... Who'd have thought...

    I've met a tech who was working for a high-school, and 90% of his time was used in fixing Windoze computers after students messed-up with them. That changed when they installed some cards (don't remember the name of the cards) with RAM on them that effectively made the hard disks read-only, and stored in RAM whatever was written on the hard-disks.

    So, whenever a PC was screwed-up, all you did was power-cycle it once!

    1. Re:Hehehehe... by Jester998 · · Score: 5, Informative

      The cards you're thinking of are often called "Sheriff Cards".

      Apparently they have them in my old high school now. Poor kids... hacking the network was one of the more fun things about high school. :)

    2. Re:Hehehehe... by ChrisBennett · · Score: 5, Informative

      There is a software solution for Windows called DeepFreeze. It works very well. I love seeing the look on faces when they delete random .dlls or change wallpaper only to find that they magically re-appear when the system reboots.

    3. Re:Hehehehe... by Anonymous Coward · · Score: 0

      ya. then there's that software you can get/use for free called POLICY EDITOR. Ohhhh what a concept.

    4. Re:Hehehehe... by pVoid · · Score: 2
      I've met a tech, who works at a university called University of Toronto. They have public internet access stations at their library. And they have dozens if not hundreds of PCs running 'windoze' that students use to do their projects. They're all running 'windoze'.

      What's your point? An improperly administered box is an improperly administered box.

    5. Re:Hehehehe... by Anonymous Coward · · Score: 3, Interesting

      A undergrad lab at my alma mater (Stony Brook) had an ingenious solution: a pile of network-booting machines that automatically mirrored the "official" disk image upon detecting changes. This way, students could come in, install some other operating system for a while (other than the default FreeBSD install), and then just reboot the machine to return it to its original state. No reliance on any special software like that Windows deepfreeze thing, or assumptions about not having physical access to machines. Very elegant.

    6. Re:Hehehehe... by systemaster · · Score: 1

      Wow your school must have had money to burn...there are software versions that do exactly what you describe in a piece of hardware. The software version works as long as the "sheriff" software is not damaged. We fixed that by installing the app really deep in the windoews directories, in a folder in a folder, and so on. But the software rocked, screw up the C: drive all ya want and all ya have to do is reboot and presto all back to normal.

      --
      LinuxWorx
      Spelling errors are intentional as are gramatical error
    7. Re:Hehehehe... by MechCow · · Score: 2, Interesting
      At my highschool we used Novell computers, and they were as locked down as the poor computer studies teacher could make them. You couldn't use the floppy drive. You could only execute the 8 or so programs assigned to you. The internet was so protected that I was unable to look stuff about Homer's Odyssey (luckily I was protected from the word virgin I presume).

      Now at uni things are so much more free yet the systems so much more secure. We can use the floppy drives, have our own email addresses and websites, and even the /sbin/ is a+x (I don't know how bright this is on there part). All is well...

      Unless you go into one of the windows labs in which case you are assaulted with kazaa, icq, msn straight after logging on. You will find the harddrive to be full of crap. Also many people do 'confirm' their password after logging on thus I assume there are password files on those computers with hundreds of students passwords, all with measily encryption.

      At least until XP, or the next windows after that makes into the labs it seems windows will always be a hassle for maintainers.

      --

      --
      On Slashdot I'm a lawyer.
    8. Re:Hehehehe... by kraksmoka · · Score: 1
      Linux to lock down... Who'd have thought...

      oh, sure, like all those 18 year old future programmers aren't gonna figure something out :) that sounds like some real arrogance to me.

      as for the win solution. at FSU they used something called Centurion, that did the same thing, reboot all of our changes away.

      fortunately for us, we had already hacked their novell server, and had all of our stuff in a nice hidden directory, so when it came time to Quake, we had a 5 minute setup :)

      sad as it is, most of the college admin staffs i've come across are way undertrained. ironically, it was because once someone graduated (MCSE or CompSci, whatever) their starting salary was more than the Uni wanted to pay. . . ...

      --
      "You never want a serious crisis to go to waste." - Rahm Emanuel
    9. Re:Hehehehe... by SweetAndSourJesus · · Score: 1

      "We fixed that by installing the app really deep in the windoews directories, in a folder in a folder, and so on."

      Now that's security.

      Of course, it does little to protect you from leet haxoring tools like deltree.

      If your security depends on a readily accessible file not being tampered with, it's going to fail. The hardware solution is elegant because it's much harder to tamper with.

      If you think no kid will ever run into deltree, you obviously weren't in my seventh grade math class.

      --

      --
      the strongest word is still the word "free"
    10. Re:Hehehehe... by Anonymous Coward · · Score: 0

      How ironic...my high school recently used that in my computer programing class to try and keep us from installing and play games. It took me about 5 minutes to get around it, and most of the other members of the class about 5 more minutes past that. By the middle of the period we were playing GTA 2 (after finishing our work of course...)

    11. Re:Hehehehe... by Anonymous Coward · · Score: 0

      Here's a concept smartass. Idiotic person that configured policy editor did it WRONG!

      Either way, PE is a lot easier, as well as the numerous other packages avail., than re-OSing the campus, or installing hardware into every machine.

    12. Re:Hehehehe... by Anonymous Coward · · Score: 0

      Hmm, deltree, wow. And NOBODY would be able to see who was logged in when everything got deleted. Then we just go nail them for destruction of property/hacking/whatever. Pretty simple. oh ya, on our way to visit the person we drop a ghost boot cd in the pc and before we even get back the machine is done. It's soooo hard.

    13. Re:Hehehehe... by shepd · · Score: 2, Insightful

      >ya. then there's that software you can get/use for free called POLICY EDITOR

      You clearly don't have even the very slightest clue about what you are talking about.

      Do you even know the difference between a piece of software that keeps an image of the HDD clean, clear and free of crap while emulating a small write-only partition and a policy editor that (pathetically) attempts to stop users from doing things?

      The number once difference would be that deepfreeze is pretty much immune to virii. Is policy editor? No, because it doesn't work at all like deepfreeze.

      This is like comparing ghost and xcopy. Sure, I could keep a backup copy of my hard drive with xcopy, but only ghost offers the bulletproof solution.

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    14. Re:Hehehehe... by Arker · · Score: 2

      I installed that Centurion on nearly a hundred machines in a past job. It's not nearly as good as you're making it out to be. It's pathetically easy to defeat.

      --
      =-=-=-=-=-=-=-=-=-=-=-=-=-=-
      Friends don't let friends enable ecmascript.
    15. Re:Hehehehe... by shepd · · Score: 2, Interesting

      >Of course, it does little to protect you from leet haxoring tools like deltree.

      Overall, deepfreeze (and other such software) tends to protect its own files from deletion (windows does too, since deepfreeze is running the deepfreeze DLL will cause windows to throw an access violation upon deleting it). Although, if you can get the machine to boot to DOS, you can bypass it. However, it isn't very difficult to stop anyone from doing that...

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    16. Re:Hehehehe... by gmack · · Score: 1, Offtopic

      Ahh yes Novell.. lots of posibillites to screw that up :)

      Apperently my teacher defined his backup admin account by not giving it permissions anywhere.

      I screwed that completly by accident when I added him with read only access to my home dir and then removed the global classrom account("room12"). I don't think he figgured out what I did until I told him what I did without actually admitting that did something with a side affect of disruting classes for the entire afternoon.

      I spend the entire year poking holes in his security. I'm sure he was glad when I left but the upside was that his system was actually secure.

      And he was one of the better ones.

      2 years later I found an apple printer while portscanning the school's ip block. It belonged to the mac lab teacher who also ran the school's dialup service and telnetted to it .. first thing it did was demand I set an admin password...

      I think school's problems are usually that they stick whatever teacher has free time and a passable knowlege as the admin.

    17. Re:Hehehehe... by Anonymous Coward · · Score: 0

      I know the difference quite well. The point you are missing is that we are discussing lock down ways and also time/costs associated. And ghost is not a BP solution either dumbass. Ghost will "ghost" errors on the drive along with everything else.

    18. Re:Hehehehe... by Anonymous Coward · · Score: 2, Insightful
      fortunately for us, we had already hacked their novell server, and had all of our stuff in a nice hidden directory, so when it came time to Quake, we had a 5 minute setup :)


      In the process you made some underpayed lab technician's day a little longer. And students wonder why the lab machines crash when they go to do real work, (or they b1tch because the machines are locked down tight). e_e

      Folks, the computer labs at (insert your favorite college here) aren't necessarily the best-funded part of the school, despite what you might want to believe. Depending on the administration, the college might not even have a proper IT division. The people who maintain the labs may also have to maintain the faculty and classroom computers, in addition to tutoring students and teaching classes.

      Please, mentally masturbate somewhere else. No tech with a day's worth of trouble tickets needs to see how 'l33t you aren't. They've got better things to do.

    19. Re:Hehehehe... by Anonymous Coward · · Score: 0

      That was a facinating and enlightening post. (+5 Insightful, Informative, Heterosexual).

      (Not.)

    20. Re:Hehehehe... by shepd · · Score: 1

      >I know the difference quite well.

      Good. Then why did you even bother mentioning policy editor in this thread?

      >The point you are missing is that we are discussing lock down ways and also time/costs associated

      No, in _this_ subthread we are discussing how deepfreeze is an excellent solution to the lockdown problem. Perhaps you screwed up and posted in the wrong thread? I think you wanted to post here then, and not here. If you made a mistake, no problem, but it's silly to get your panties in a knot over it.

      >And ghost is not a BP solution either dumbass. Ghost will "ghost" errors on the drive along with everything else.

      And why are you using a used workstation to update your ghost image from?

      What you should do: You download the ghost image from a CD or server onto a box. Make your changes. Upload changes. As long as you trust your IT staff, there'll never be any foreign stuff on the disk the first bootup after ghosting.

      As far as ghost ghosting errors along, well, for me for the past 3 or 4 versions it also tells me there's an error. I assume you are still working with the old shareware version, perhaps, to be noticing that sort of behaviour?

      Actually, the latest versions of ghost are so nice they even include a CRC with the ghost data, ensuring that even if one bit in your ghost image file itself changes you notice it. It's very difficult to not notice an error this way.

      Now, explain to me how foreign software, virii, or other nasties are introduced into an image when using ghost in the above manner, and I'll show you a set of admins that should be on helpdesk.

      A combination of deepfreeze and ghost has cut down on repair problems for us by so much we can sit around and post to slashdot all day now (well, maybe not). We've gone from having labs where 5 or 6 machines (win98) per lab would be out of commission daily due to software vandalism to never having any software vandalism. It has to be the best investment we've made in a long time (although, ghost was pretty damn good a long time ago too).

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    21. Re:Hehehehe... by dswan69 · · Score: 1

      Or they could just have used the security in windows NT/2k/XP to prevent the users from messing with the system. So either they were using the 9x range which makes the systems getting messed up their fault or they just don't know how to configure NT et al, which again is their deficiency.

    22. Re:Hehehehe... by Anonymous Coward · · Score: 1, Funny

      Like what, dumb kids cutting the rj45 cable? You are so clever!

    23. Re:Hehehehe... by Anonymous Coward · · Score: 0

      Please, it's VIRUSES!

    24. Re:Hehehehe... by Feztaa · · Score: 5, Informative

      Older versions of DeepFreeze were pretty funny. Set the system clock sufficiently far into the future, and it magically crashed. The first thing you do after that is delete DeepFreeze, and you have no more DeepFreeze problem ;)

    25. Re:Hehehehe... by kraksmoka · · Score: 1
      it wasn't that good, but then again, we Were that good.

      ok, soupy was that good. we just knew all the fun win95 hacks, like telling IE that it's telnet app was command.com and how to use his stuff. this guy didn't have a novell certifacation, but he took over. we were just lucky fuckers, and fragging away!

      --
      "You never want a serious crisis to go to waste." - Rahm Emanuel
    26. Re:Hehehehe... by watzinaneihm · · Score: 1

      To believe that a machine can be secured when everyone has physical access to it is .... What happens if somebody pulls out the card ? Or does it work like netware (Install the OS lock up the server and everyone is a client?) ?

      --
      .ACMD setaloiv siht gnidaeR
    27. Re:Hehehehe... by doofusclam · · Score: 1

      Reminds me of when I was at college - we had a load of BBC Micros as terminals to our Prime minicomputer and they had their disk drives removed so we couldn't play games on them... so we hacked the Prime, FTPd every BBC game we could find onto there and fitted every BBC with roms that used the Prime as a virtual hard drive. The tutor could never work out how we managed to play games on them without any obvious means of getting the game there...

    28. Re:Hehehehe... by Anonymous Coward · · Score: 0

      No, it's viruxen!

    29. Re:Hehehehe... by Quantuminium · · Score: 1

      No, it's virupodes!.... Well, maybe not but the plural of octopus is octopodes. http://www.aquarium.org/upwelling/upwelling32.htm Offtopic? You betcha!

    30. Re:Hehehehe... by jaavaaguru · · Score: 2

      If you had choses Linux in the first place over Windows, you'd never have known that problems like that exist ;-)

      To be fair though, Linux wasn't as useable to the average person back then as it is now. Lets just hope people starting this process from the beginning don't make these mistakes.

    31. Re:Hehehehe... by ningcat · · Score: 1

      I work for a tertiary college where IT/computing is taught.

      We evaluated something like this a couple of years ago. The product we looked at was called a Reborn Card. It's a small card with a ROM on it that sits in a PCI slot.

      Didn't use them in the end, we felt it was cheaper and easier to reimage classrooms of machines. Also has the benefit of being less restrictive for the students that are trying to learn about computers.

      All our linux classes are run 'offline' from the rest of our network. This gives students an environment where they can play around and experiment without impacting on the campus network.

      I don't see "Linux taking over at uni". Although it is certainly a threat to traditional Unix operating systems. We won't be leaving the Windows platform anytime soon unless business/industry suddenly decide to do so.

      The main benefit to increase in educational linux use is that students will get more exposure to alternative operating systems. This will make them a more realistic option for the IT decision makers of tomorrow.

      </rambling>

    32. Re:Hehehehe... by shepd · · Score: 1

      Not on slashdot, it isn't.

      If anyone cares to continue this sort of boring debate, read here for some debate on both sides of the fence.

      Since we want to be correct, the plural of virus is, in fact, virus. Therefore, one would say "The problem on your computer is that there are 2 computer virus on it." To which one would reply, "You idiot sound like brain-my-damage!"

      So it is your choice. The plual is in fact virus, the dictionary english plural being viruses, or the slashdot plural being virii.

      I stick with a different plural noun for computer virus than living virus, because they are different enough to warrant it, IMHO.

      I truly HTH with this debate on how to say the plural form of virus. And, as long as I post to slashdot, I will use the preferred spelling of the maintainers of slashdot.

      Thank you.

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    33. Re:Hehehehe... by Anonymous Coward · · Score: 0

      - Linux to lock down... Who'd have thought...

      My company's business relies entirely on the ease of use and low price of simple Linux systems. I administer remotely dozens of these, used by non technical users (some of them never touched a computer before). It started months ago, and all we got were a couple calls about the network going down due to the isp fault.
      No viruses, no trojans, no crashes and no system files deleted. I can spend almost all my administration time listening to music, reding /. and coding for fun. Linux Wohoooo!

    34. Re:Hehehehe... by Black+Copter+Control · · Score: 5, Informative
      Either way, PE is a lot easier, as well as the numerous other packages avail., than re-OSing the campus, or installing hardware into every machine.

      Windows was originally designed around the presumption that there was really only one user on the system, and that user could/should do whatver (s)he wanted. To that was added the eventual realization that Oops! That's not always the case.

      This has resulted in the back-ending of all sorts of security hacks onto what is still, essentially, a single-user system. A side effect of this is all sorts of special cases and wierd holes in the design of Windows that results in the need for things like PE.

      Unix, on the other hand was designed as a multi-user system almost from day one. In this context, a single user system is simply the special case of N==1. Locking down a Linux system requires little more than putting passwords on GRUB and the CMOS editor, and possibly pulling the setuid bit from some questionable binaries. Once that's done, there's little that a non-root user can do beyond trashing their own account, or various DOS type stupidities (which can often be responded to by a good sysadmin).

      Beyond that, the ability to prevent first-year stupidity is only one of the reasons why Linux was chosen as the standard for first-year students. Not having to worry about being sued when the students post the source code that you gave them (under some sort of non-disclosure agreement) on the net when asking for an answer to a question is another. Multiple GUI desktops, extensibility and totally free access to the source code are some of the others.

      --
      OS Software is like love: The best way to make it grow is to give it away.
    35. Re:Hehehehe... by Agent_Basilisk · · Score: 1

      Ever heard of Deepfreeze? In the library in the high school I went to we use it, it dowes the same thing and the standard version is FREE to institutions and schools. The Pro version is much more customizable and allows you to change what changes to the system/ what writes to the hard drive can be kept. it's fairly inexpensive (as far as i know) to places like institutions and school. The standard version locks out everything. You can make changes while the computer is running and swap and stuff aren't affected and it just seems like a normal computer until you restart. When you restart it has NONE of the changes that were made that were on before a restart. Our school told people to save work on floppy because once the system was restarted everything they had saved to HD was gone. I just think this is a less expensive alternative to a physical piece of hardware. What do you have to do? Remove the card when you want to update the system and re-insert it later?? This sounds like a hassle.

    36. Re:Hehehehe... by jez9999 · · Score: 2

      >And ghost is not a BP solution either dumbass. Ghost will "ghost" errors on the drive along with everything else.

      And why are you using a used workstation to update your ghost image from?


      Any why are YOU using a used workstation to update your xcopy image from??

    37. Re:Hehehehe... by jez9999 · · Score: 2

      Sounds like you could have built your own BBC with less effort.

    38. Re:Hehehehe... by shepd · · Score: 1

      >Any why are YOU using a used workstation to update your xcopy image from??

      Uhh, I think you've got me confused with the AC. ;-) Either that or I'm missing something.

      "This is like comparing ghost and xcopy. Sure, I could keep a backup copy of my hard drive with xcopy, but only ghost offers the bulletproof solution."

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    39. Re:Hehehehe... by AvitarX · · Score: 2

      I think the problem is the hords of semi geek 18 year old drop outs and haxor wanna bes.

      if you are serious into programming you are more likly to have some respect.

      Your quaking was not malicious, and probably did not cause support headaches. So how was your bypassing the system so bad?

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    40. Re:Hehehehe... by Anonymous Coward · · Score: 0

      haha... When I was in high-school we didn't even have networks.

    41. Re:Hehehehe... by jgerman · · Score: 2

      Though it would have taught the kids a heck of a lot more about computers is their teacher was knowledgable enough to install it. I didn't find Linux until my senior year (the end of it actually), but I had some Unix experience at that point. I'm pretty confident in my coding skills, but I can only imagine how much I would have known if for the previous 6-7 years of coding and learning about computers I had had Linux to work with... it's infinitely more conducive to not only programming, but exploring computers in general.

      --
      I'm the big fish in the big pond bitch.
    42. Re:Hehehehe... by jaavaaguru · · Score: 2

      Yeah, I'd say that learning Windows (aside from administration) is really just learning an application: explorer. Learning Linux is a bit more like in learning about operating systems in general. Sure, you could stick to learning KDE, which would be really similar to learning Windows, but there is a whole wealth of knowledge waiting to be found below that.

    43. Re:Hehehehe... by Muddle · · Score: 1

      I use Windows Configurator http://freeware.prv.pl/ to Lock down my other computer. My Son can change screen attributes, Log Off and run only the programs I place in his user folder. Everything else is off limits to him. My wife's Loggon on the same machine has unlimited access to all functions.
      My son who has Autism was constantly messing up the system. It would take me countless hours trying to figure out what he did and correct the problems. It sure cut down on a lot of insanity at our home. No more cussing, muttering, hair pulling and complete system reinstalls due to his computer usage as he could turn a Windows installation into useless garbage in the blink of an eye.
      Using the Configurator is easy and one does not have to enter the registry or system settings to make the changes just put a check mark's in the boxes.
      Best of all it's free

    44. Re:Hehehehe... by SignoffTheSourcerer · · Score: 1

      What good is a write-only partition? Reminds me of Signetics write-only-memory in `72.

      --
      Ordo Militum Unix.
    45. Re:Hehehehe... by Anonymous Coward · · Score: 0

      I think school's problems are usually that they stick whatever teacher has free time and a passable knowlege as the admin.


      For a small school that is true, for larger districts they actually pay people to be nothing but incompetent admins. Actually, most of the admins in the school district where I live are not to bad, they are just in way over there heads. They have put Linux boxes up that have been hacked by the students in hours, they run Windows NT networks and have botched there PDC's (and BDC's) so badly that they had an unusable network for a week. Exchange and Melisa was fun, but not fun enough to learn from, etc. Part of the problem is that the want to stick with Microsoft at all costs, and are unwilling to look for better solutions.

      The local college, with a bigger student/teacher/administrative population was running a much more reliable network with Primaraly Netware for file services, web serving (via Apache), email (Groupwise for Staff/Faculty and NIMS for students) and computer policy enforcement (ZENWorks) various Unix boxes for financial, firewall, primary email scanning, Network traffic monitoring, Oracle Database, web serving, and NT (Citrix for 2 remote users, Coldfusion before it became available for Linux, and a couple of misc pet projects for professors). Downtime: Very rarely, but more often then I liked (Probably 1 work day throughout the year), but definatly better then most. Simply because we looked at the tech that was available and chose the solution that worked best for us, rather then blindly following the pack.

    46. Re:Hehehehe... by Anonymous Coward · · Score: 0

      >What good is a write-only partition? Reminds me of Signetics write-only-memory in `72.

      A lot of misdesigned apps require a writable space on the hard drive, so deepfreeze provides them with one.

      I call it write only because it only stores the changes for the current session. After that, the changes are lost.

      However, technically it is readable.

      Hey, semantics wins again. Unfortunately for me, that is.

    47. Re:Hehehehe... by jonadab · · Score: 2

      As long as they have unsupervised physical access to the system, they
      can always circumvent it. Ultimately, if there is no other way, they
      can set the BIOS-forget jumper to wipe any CMOS password, set it to
      boot from a removable drive, and then have their way with the MBR and
      the boot sector of the boot partition. In almost all cases, there's
      a much easier way that doesn't involve opening the case. DeepFreeze
      is, from what I'm told, good enough that if you have no bootable
      removable drives, set the BIOS password, and can keep them from
      opening the case you won't have much trouble -- but you are always
      taking the risk that the teacher or lab assistant will step out of
      the room for too long and some clown will set the BIOS jumper and
      have his little fun. (Having no removable drives goes a long way
      toward making this harder, but that isn't always practical.)

      The better solution is to go with thin clients. Then all they can
      do is steal the thin clients, but without getting into the server
      room, that's the limit. You hook up a new thin client, and it's as
      if nothing happened. (This assumes the thin-client server is secure
      from network-based attacks; I suggest not using a Microsoft solution
      on the server end, and don't use your thin client server for serving
      other things like mail, either; spend the $50 on ebay and get
      yourself an old system you can make into a separate mail server, if
      it comes to that.)

      Seriously: a thin-client solution takes more setup, but once you
      have it in place, your headaches are greatly reduced. The only
      downside is a Single Point Of Failure, which is another reason
      you don't use a Microsoft solution on the server end.

      --
      Cut that out, or I will ship you to Norilsk in a box.
    48. Re:Hehehehe... by jonadab · · Score: 3, Interesting

      > Yeah, I'd say that learning Windows (aside from administration)
      > is really just learning an application: explorer.

      Um, have you ever tried to administer a Windows box? Knowing
      Explorer is what you take for granted; it's the undocumented stuff
      that you have to know to survive. You're dead in the water if you
      aren't comfortable with the registry, for example. First time any
      problem crops up, you'd best know how to work with cabinets, and
      which undocumented batch files that get created by install processes
      are run on startup and, if broken, have to be deleted in order to
      restore the system to a bootable state. (And no, I'm not talking
      about AUTOEXEC.BAT; if you thought that was what I meant, you'll
      end up formatting the drive the first time anything goes wrong, but
      not until after you pull out your hair first.)

      The difference between Windows and Linux is not one of complexity;
      Windows and Linux have roughly the same amount of complexity. The
      difference is one of documentation: Linux has some. (The other
      difference is consistency in terms of the visual appearance of UI
      widgets; almost all Windows apps use the same widget set. (That's
      a good thing.) RedHat is working on this problem, but their
      solution is incomplete at this time.)

      --
      Cut that out, or I will ship you to Norilsk in a box.
    49. Re:Hehehehe... by jgerman · · Score: 2

      The difference is that Linux has accessible complexity, plain and simple.

      --
      I'm the big fish in the big pond bitch.
    50. Re:Hehehehe... by Jeffrey+Baker · · Score: 3, Insightful

      If the program was any good in the first place, it wouldn't let you set the clock. There is no legitimate multiuser system where a normal user can diddle the clock.

    51. Re:Hehehehe... by jaavaaguru · · Score: 2


      Um, have you ever tried to administer a Windows box? Knowing
      Explorer is what you take for granted


      I said aside from administration, meaning that I was talking about using windows but not administering it.

      I do believe that administering it could be very complex.

    52. Re:Hehehehe... by SavingPrivateNawak · · Score: 2, Interesting

      I tend to agree with the previous poster: you can easily lock down any NT.

      They did that at my universities and their NT-domain was the most well built I have ever encountered... far more robust than the one we have at work...

      Anyway the only way we found to get around the policies was to open the case and boot from another OS to make our 'modifications'... So we succeeded but since ANY computer is vulnerable when you have physical access to it, you can't bash NT on that.

      I also think that playing GTA2 on a university computer is no l33t hax0ring at all, so the other poster that bragged about that really proves nothing. On any computer, if you want to get some work done, you have to have write access somewhere and the ability to run binaries... once you have that, there's no reason why you couldn't play games, they are programs after all... and you are in CS-course to make programs...
      (Well of course there are many games that need to be installed but really I can't understand that! I mean, there's no fscking DLL to share with another prog, no need for special 'machine-wide' registry settings, so why require it to be 'installed'... Quake 3 r0x0rs! :) )

      To be more specific about your post, I think it could refer to some lame special Win9x versions that were extended for multiuser and access restrictions but not to NT. I think that NT was multiuser from day-1. (With the special requirement to look like the 'lame, single user one'...)

    53. Re:Hehehehe... by Black+Copter+Control · · Score: 2
      They did that at my universities and their NT-domain was the most well built I have ever encountered... far more robust than the one we have at work...

      I'd say that that backs up the theory that it takes a god-level sysadmin with attention to detail to lock down an NT network. It's not impossible, but it's far from a normal state of being.

      --
      OS Software is like love: The best way to make it grow is to give it away.
    54. Re:Hehehehe... by SavingPrivateNawak · · Score: 1

      I'd tend to agree. However, one also has to have skill to secure a Unix network. The details you look after are not the same, though.

      To make things clear, I am not a fan of NT. I prefer linux/unix for servers. I think workstations are easier to work on when they have NT though.
      It has something to do with the UI, but linux is making progress in that domain, although I would prefer that it wouldn't be on eye-candy (l33t round & transparent windows) but more on old things that hurt me (clipboard, integrated file-explorer (with all the options!) in an 'Open file' dialog, etc)

    55. Re:Hehehehe... by kraksmoka · · Score: 2
      figures, one of the lab fsckers would bitch about quake today, still. they whined and whined, its causing instability thoughout the network!

      they were always full of shit, and would walk around and shut down our boxes as we played.

      since you're one of them, that makes you highly qualified as a moron.

      if jerks like u spent the time studying your manuals instead of hunting down gamers, you might know how to find your ass in a paper bag, let alone manage a network.

      i leave you with the greatest curse i can levy upon anyone: your own stupidity is your highest reward.

      --
      "You never want a serious crisis to go to waste." - Rahm Emanuel
    56. Re:Hehehehe... by SectoidRandom · · Score: 2

      Typical school thinking, ie spend the smallest amount possible. I'm guess you used Win9x?

      I setup a bunch of locked down libary pc's at a private school here, first they chose the cheap path of Windows98, I locked them down as best as I could, of course that's only so much, after recieving frequent calls i proposed Windows2000. Since installing and locking that down six months ago NOT ONE CALL. The best a kid could hope for would be to either crash or corrupt the install, that's why the Libarian has the Ghost image cd that autoboots and images back to square one. Apparently she hasn't needed to even use that yet!

    57. Re:Hehehehe... by Anonymous Coward · · Score: 0

      Then again...

      It depends on the system administrator, its sure as shit easy to lock down a windows environment, using nothing more than your brains and group policy on a 2000 domain.

      Maybe they should all learn how to administer systems, and stop blaming the Operating system.

      Just my two cents

  2. Re:IN SOVIET RUSSIA... by Anonymous Coward · · Score: 0

    As Tired as I SOVIET RUSSIA..... Linux Dumps universities!

  3. UNSW by Slurpee · · Score: 5, Interesting

    The Uni of New South Wales Computer Science and Engineering department has been running unix/linux for years, no duel boot.

    8 years ago it was Sun Solaris.

    5 Years ago they moved to Intel Solaris

    Now they have (or are) moving to Intel Linux.

    anyway, good stuff at Uni of Wollongong.

    1. Re:UNSW by x1048576 · · Score: 1

      Unix at UNSW goes back much much further than 8 year. See the Lions Book.

    2. Re:UNSW by Slurpee · · Score: 1

      You are totally right...it goes way way way back...especially in CSE. But I only have first hand knowledge since about '93/4.

      The coolest thing about CSE (Computer Science and Engineering) @ UNSW, is that they have not ever sold out to Microsoft, unlike those losers in Information Technology, who when MS came knocking with a big fat cheque, bent over and let them take whatever they wanted. The IT department now basically only teach people how to use MS products.

      MS have come to CSE with *very* large checks...but CSE has constantly refused to take them.

  4. The article. by Anonymous Coward · · Score: 3, Informative

    Linux taking over at uni
    Chris Jenkins
    17Dec02

    LINUX is making inroads into the nation's universities, pushing Windows, Unix and Apple operating systems off the desktops of first-year IT students.

    It is making ground in IT courses because Linux is both easy to lock-down, easy to pull apart and offers simple licensing for distribution to students.

    At the University of Wollongong, which has about 1700 computer science students, machines in first-year labs that used to boot from either Windows or Linux have been changed to Linux only.

    "We get large number of inexperienced people in first-year and we are really trying to keep down our overheads and concentrate our professional support more in the later years," said Les Ohlbach, operations manager for the university's Department of Informatics."

    "The best way to control the first-years was to put them in a Linux-only environment where you can lock it down pretty well."

    Students moved to Unix and Windows in second- and third- year, he said, with Macs used for multimedia training.

    At the University of Western Australia, which has around 1650 students in its computer science courses, Linux has totally supplanted more traditional Unix distributions, such as Sun's Solaris in the school of computer science and software engineering.

    UWA's senior lecturer in computer science and software engineering Chris McDonald said Unix was dropped from teaching around 1995, and was no longer specifically required for any research projects.

    UWA recently dropped Apple from its IT education programs in the school, for the same reason that Unix was abandoned -- expensive proprietary hardware.

    "It wasn't so much the [Unix] operating system costs, because it usually came with the machine or we could get pretty good prices as an educational institution," he said.

    Linux was easier to give to students for home use, Dr McDonald said.

    "If we were using Solaris or HP-UX or something like that, I'm sure there would be very different and costly licensing issues involved," he said.

    "We are trying to move to an environment where what we provide in the laboratories can be mirrored in the students' home."

    Mr Ohlbach said the University of Wollongong favours Linux for first-years for a similar reason.

    "We are teaching programming, so they [students] need to run all sorts of IDEs and development environments. On Linux they can quite easily do most of their code at home at fairly low cost," he said.

    Dr McDonald said in teaching open-source platforms to students it is important not to "just ram open-source issues down their throats. It's important to explain why there is a difference in philosophy, why it's reasonable to not to totally tread the path of one particular vendor, one particular monopoly."

    However, Dr McDonald said UWA's school of computer science and software engineering was part of Microsoft's academic alliance program, which allowed the free distribution of Microsoft operating systems to enrolled students.

    The school used Linux and Windows to teach operating systems.

    "It's good to show not just the similarities, but more importantly the differences."

    Linux allowed better teaching of the principles behind software development, he said.

    "We'd rather explain how things work. We do that by taking things apart and putting them back together again, rather than just showing people how to use particular GUIs that other people have designed. It's our belief that open-source software better explains those concepts," he said.

    "Personally, I think that just showing students how to use operating systems tools and networking tools, is more training than education.

    "From 2003 UWA's school of computer science and software engineering will be using Linux, in preference to Windows, for our first-year Foundations of IT unit."

    Mr Ohlbach said it was important for students to have exposure to multiple operating systems and development environments.

    "Anybody wanting to be a professional computer science person, or an IT person, generally doesn't want to be seen as just a Mac or a PC party, " he said.

    This report appears on news.com.au.

    1. Re:The article. by CmdrFaco · · Score: 0

      You damn whore. Looking for some easy karma ? He ?
      I see more and more "first article post" competition on /. recently.
      Anyway, it's my first beer and I already bumbling. Oh well let's wait for the second. ... and I'm pissed off 'cause can't find any bitch

    2. Re:The article. by Anonymous Coward · · Score: 0
      You damn whore. Looking for some easy karma ?

      Yup, that would be why he posted as an AC, dickflop! Heaven forbid that anyone post anything informative on /. -- such an act could only be whoring!

    3. Re:The article. by Anonymous Coward · · Score: 0

      hey! Are dickflops like terraflops?!

    4. Re:The article. by WaKall · · Score: 5, Interesting

      "Dr McDonald said in teaching open-source platforms to students it is important not to "just ram open-source issues down their throats. It's important to explain why there is a difference in philosophy, why it's reasonable to not to totally tread the path of one particular vendor, one particular monopoly."

      I wonder WHICH monopoly he refers to?

      I think it's important to teach skills and not languages. The platform shouldn't really matter. But what I read there is "we're gonna teach non-proprietary solutions". I don't think the OS matters for the undergrads.

      I learned programming on Solaris and later Linux, and honestly there's no real difference between them for 95% of what you do in school, since you are NOT administering the box, and the interesting tools are opensource, portable, and provided by the school - you just have to USE them. This probably holds true for BSD as well.

      I do believe that we shouldn't be teaching kids to develop in MSVC++ and MFC. I think that's god-awful - we should learn to use makefiles and know the dependencies in our code, and not waste time on things that aren't portable to our jobs, on a yet-to-be-determined platform.

    5. Re:The article. by Anonymous Coward · · Score: 0

      The article? Why would anyone want to read that?

    6. Re:The article. by Anonymous Coward · · Score: 0

      More interestingly and relevant, are they like tera-FLOPS?

    7. Re:The article. by Anonymous Coward · · Score: 0

      I don't mean to troll but...

      ...I wish the mods would stop modding up these cut'n'paste instant karma trolls

    8. Re:The article. by Anonymous Coward · · Score: 0

      Let me start off by saying I get paid to develop on UNIX-like systems such as Linux, Solaris, and OS X, however...

      You _CAN_ use makefiles and do everything from the command line in Windows too. Using gcc or MSVC++.

      Doing _something_ in MFC might not be a bad idea just for the learning experience since that is what you are most likely to run into in the real world (even if you're only porting to X or something). And just because you use MSVC++ doesn't force you to use MFC/ATL/COM or whatever, it compiles normal C++ code (like all the algorithms you learn in school). Plus the MSVC++ compiler is a hell of a lot faster than GCC.

    9. Re:The article. by Anonymous Coward · · Score: 0

      On the contrary, we should definitely be learning to program for Windows. If you want to be a programmer for a profession (why on earth anyone would WANT to be a programmer is beyond me) then you better learn Windows programming or you're going to be eating Ramen noodles for breakfast, lunch, and dinner for the rest of your life. As for the programmer as a profession thing... do you guys actually go through the CIS programs and WANT to program? I can't be the only one that is severely bored with university CIS programs covering nothing but how to code in three or four obscure obsolete languages. How do you get a CIS degree when you find no interest in programming? I prefer network engineering and systems administration to sitting at a desk all day staring at an IDE banging out some program. Programming is beneat an admin. Programmers are the scum that write the shitty code in the first place, but the admins are the one that can make it sing even with the bugs.

    10. Re:The article. by Lumpy · · Score: 3, Interesting

      I do believe that we shouldn't be teaching kids to develop in MSVC++ and MFC.

      we shouldn't teach ANYONE to program in any of the Microsoft visual environments. it promotes sloppy coding, bloat and tons of other things that make just plain old BAD programmers.

      you want to teach windows programming? then use the free solutions out there teaching the API interfacing and other parts of fighting with a windows environment is so much more important than the drivel the MS visual dev.

      Give the studen MORE understanding and a tool they can freely take home legally. you get a better programmer.

      and as a side note. every teacher should at the end of every semester force all the student to program in an embedded environment or put tight size cap's on the compiled program.

      Anyone can make gigantic bloatware, a good programmer makes fast tight code.

      --
      Do not look at laser with remaining good eye.
    11. Re:The article. by fitten · · Score: 1

      a good programmer makes fast tight code

      I'd agree with this as long as you add 'maintainable'. If tight/fast was your only goal, you wouldn't use GUIs... which are typically much better for end-user interaction and efficiency, for example. If tight/fast was your main goal, you wouldn't use a multi-tasking OS... you'd only make single-purpose devices programmed to the bare silicon.

      One of my theories that Un*x and Un*x-like programmers are typically stronger (although, there are plenty who are not very strong) is that they have to do so much more work to get things to 'go'. For instance, it isn't enough that I know C. I have to also know make... and probably either vi and/or emacs.... and dbg or some other debugger... and man... and possibly autoconf... and the list goes on.

      On Windows, the environment is pretty easy to use, especially for less skilled people. It makes programming less '3l337' /shrug.

      I agree somewhat though... a good hardware class and some assembly would do many programmers good though. If nothing else, it lets them know what goes on behind the languages they use. Once you write a bit in assembly, pretty much any other computer language isn't that big of a deal.

    12. Re:The article. by GuruJ · · Score: 1

      Notice the key reason given for the switch:

      "We are trying to move to an environment where what we provide in the laboratories can be mirrored in the students' home."

      You can't give people a free copy of Solaris or Windows. Linux is lovely for a set of cash-strapped students.

      --
      -- Askari: Give JavaScript the bird.
  5. Re:Early Post by Anonymous Coward · · Score: 0

    Funny to think that if you had back all the time you spent tweaking and patching (for no good reason other than to say you have the latest version)... ... then the Linux-Losers could actually make "real" friends.

    Ba-dum-dum!

  6. Another Solution - Windows Policy Editor by RaboKrabekian · · Score: 5, Informative

    I'm not fully versed in all its wonders, but the Windows Policy Editor (or whatever its called now) can completely lock down a machine. It's a vastly underutilized tool for environments where you don't want users messing with the machines. I remember getting annoyed the first time I sat down at a box which wouldn't let me even look at the start menu. Any and all Windows admins should look in to its proper use in their environment.

    --
    "Moderate drinking can help prevent amputated limbs" -- Abigail Zuger, NYTimes, 12/31/02
    1. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 1, Informative

      Except it's not fool proof.
      Anyone with half a clue will realize that this only restricts the Windows shell.

    2. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      ya but then Nothing is fool proof.

    3. Re:Another Solution - Windows Policy Editor by tconnors · · Score: 3, Interesting

      t's a vastly underutilized tool for environments where you don't want users messing with the machines. I remember getting annoyed the first time I sat down at a box which wouldn't let me even look at the start menu.

      In our undergrad labs at cs.usyd.edu.au, there was a low-end pentium for the sole purposes of ftping files from your floppy to your 3meg quota'd ugrad account on the nix machines. It was win3.1 (even though this was in 1998-2000), and all it _appeared_ to have was a crappy ftp client and 2 other semi-useless programs. You were given a 3 minute time-limit to use this machine. But one day, I recursively transferred the wrong files, and the ftp client was crap, and couldn't recursively remove directories, so I went to the c:\windows directory (or whatever), in the ftp client, selected command.com, and clicked the "run" button. I then was in a dos shell where I could deltree.

      Moral of the story: There is no security in removing the start button :)

    4. Re:Another Solution - Windows Policy Editor by mferrare · · Score: 4, Interesting
      But consider how much you have to piss-fart aoround with WPE to get a good config - partially because no-one uses it - and compare that with 'locking down' a linux box ie:
      • secure it - and most linuxes are reasonably secure out-the-box these days
      • set a strong root password. Give the students limited sudo access if necessary
      • Probably a little bit of hardware stuff (disable floppy booting etc)
      • Maybe setting up a restricted shell or GUI environment
      But basically, students would be pretty safe on a linux box without root access. And it's simple and well-known to set up. Compare that with Windows Policy Editor. Does anyone really use it? Maybe a few but I'm sure it's not as well documented or as well tested and probably not as robust as simply locking out root access to a linux box.
      --
      Why would anyone want to use a text editor that is not vi?
    5. Re:Another Solution - Windows Policy Editor by indiigo · · Score: 2

      we use it, and like linux, it requires a lot of compatibility testing with your apps. You can easily break something bad enough irreversibly, so it's not a toy that one uses on their users.

      follow the guides and the people (beta) before you

      --
      fslg503-985-8686503-985-8686503-985-8686503-985-86 8650 3-985-fdsg8686503-985-8686503-985-8686503-9
    6. Re:Another Solution - Windows Policy Editor by foo+fighter · · Score: 4, Informative

      Windows Policy Editor was used for the 9x/Me series.

      Starting with Windows 2000, admins have access to "Group Policy". Essentially, any user interface setting -- and most system settings -- can be controlled via this either on the local machine or remotely.

      Group Policy kicks ass. You can completely lock down a machine so that cmd.exe doesn't work no matter what and the only .exe's that do work are the ones you specify. You can let the user specify their Display preferences, but nothing else. Or everything except the Display preferences. The point is, Linux has nothing to compare with this.

      The fact is, under Windows 2000 (and XP), administrators have never had an easier time setting up, controlling, troubleshooting, and fixing a user's desktop. If Linux had anything to easier to compare to this I'd be using it (admins being essentially lazy).

      At length, I've evaluated Redhat, Suse, Caldera, Debian, FreeBSD, OpenBSD, and Mac OS X. (At length means ~40 hours on each setting up desktops and administrative consoles and testing things out.)

      I have many Redhat machines running on servers at work. I have a Yellow Dog machine running my web site and email and OpenBSD running my router at home.

      The FACT is no one has a better way to administrate and trouble-shoot end-user desktops than Microsoft right now.

      --
      obviously no deficiencies vs. no obvious deficiencies
    7. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      Abstinence is fool proof

    8. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      depends on your definition of foolproof.

      Abstinence sure isn't a foolproof way of procreating :)

    9. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      that sounds good for 1 or two workstations...

    10. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 2, Insightful

      Just because you personally don't know how to do something doesn't mean it can't be done.

      Its quite possible to lock down user's desktops in linux if your familiar with linux. It doesn't sound like you are. It also sounds like your looking for a single point-n-click program to do it with. Well that just doens't exist, but it doesn't mean you can't severely limit what a linux user can do.

      Its also trivial to ssh or vnc in and take over a session of kill the appropriate process if needed. I laugh in your general direction for even joking that its somehow easier to remotely troubleshoot desktops on windows.

      Your also comparing apples and oranges a bit since the linux and microsoft desktop are two very different beasts.

      So not its not a FACT afterall.

      Also and don't take this the wrong way. Spending 40 hrs each on some distros hardly qualifies you to proclaim MS king of all administration.

    11. Re:Another Solution - Windows Policy Editor by popeyethesailor · · Score: 2

      Agreed, but when the administrator password is not in the hands of the user, which so often is the case..

    12. Re:Another Solution - Windows Policy Editor by mystran · · Score: 5, Informative
      There also another view. In windows you have to options: either you allow people to do everything or you allow them to do nothing. The policy editor just stops working once you allow someone to run an .exe from his desktop since he can break the system (with one of the numerous exploit that for example the GUI gives you).

      In Linux (and unix in general) you can allow people to do almost anything with their own account. If they mess their homedir (and it's quite unlikely to get your personal stuff to the point you can't login at all by accident), just clean it by resetting the configfile that breaks the thing.

      You can have people run custom window managers, code their own software (even that damn window manager), whatever, if they happen to know how, while at the same time making sure they don't mess the system up if they don't.

      Now, imagine that user has to do some task, and they have messed up their configs. Now on Windows you either repair their profile (which can take quite a time if you can't login as them, if possible at all) or take backup of files, create new profile and copy the files over, on linux you just throw the default configs to their homedir and all you lose are few hacks in some files (say .bash_profile/.bashrc or may .Xsession)

      About the config thing.. if you setup linux in ~40 hours (for shared use) you are pretty fast. If you can do the same (in ~40 hours) for Windows you are superman. Start counting from when you get few hundred PCs with blank harddrives, with no images ready, etc..

      And once you get new systems with different hardware you have to do it again :) With linux you dump the same image and switch either kernel or module config.

      Windows has it's strong points, but administration isn't one of them. At least if you are trying to do it well. In a Uni even "we are not mission critical, we don't need the best security" isn't argument, since what would better target for a hacker than a Uni with a lots of computers and students doing all kind of things with irregular patterns.

      Btw, the Windows 9x/ME policy system is a joke :) If you can't get past it whily you can still do something with the system, you probably shouldn't be securing anything ;-)

      --
      Software should be free as in speech, but if we also get some free beer, all the better.
    13. Re:Another Solution - Windows Policy Editor by Burning1 · · Score: 1

      Give netware a try. I understand that it's even better than Windows in most ways.

    14. Re:Another Solution - Windows Policy Editor by Derg · · Score: 1

      About the config thing.. if you setup linux in ~40 hours (for shared use) you are pretty fast. If you can do the same (in ~40 hours) for Windows you are superman. Start counting from when you get few hundred PCs with blank harddrives, with no images ready, etc..


      I can't personally attest to the linux config time, but 40 hrs is fucking rediculous in setting up a homogenous windoze network. Give me 1 copy of ghost and 100 empty pcs and toss in a nice little 100Mbps network and I'll hand you back 100 boxes in 5-7 hrs tops that are harder to crack than leather pants off a fat chicks ass.

      either that or you'll get 100 blank boxes and a nice little network. I need me a current copy of ghost. *cough*

      windoze is not hard at all to secure, and dont give me that poledit or gpo's arent secure at all, because thats just scratching the head of it. pick up a copy of menasi's book on configuring 2kServers and then you will get a taste for what can be done.


      just my $.02

      --
      I'm a little tea pot.
    15. Re:Another Solution - Windows Policy Editor by Spy+Hunter · · Score: 2

      Have you looked at KDE's kiosk mode? I understand Waldo Bastian has done a lot of work locking down KDE to be suitable for use in a public environment. And with Unix, you can have reasonable security without doing silly things like disabling shell access. Unix was made for secure multi-user environments and remote administration.

      --
      main(c,r){for(r=32;r;) printf(++c>31?c=!r--,"\n":c<r?" ":~c&r?" `":" #");}
    16. Re:Another Solution - Windows Policy Editor by aechols · · Score: 1

      Group Policy kicks ass. You can completely lock down a machine so that cmd.exe doesn't work no matter what and the only .exe's that do work are the ones you specify.

      You're exactly right. You can indeed tell it what programs can run. However there's a rather easy and silly way to beat this. Rename a program you want to run to the name of a program that is allowed to run. Then you run it. That easy. Great for busting guest accounts open.

      --
      Are you pondering what I'm pondering?
    17. Re:Another Solution - Windows Policy Editor by dmiller · · Score: 2

      Why don't you write up what you like as a proposal to the KDE and/or GNOME teams - the situation isn't going to change if people sit on their hands.

    18. Re:Another Solution - Windows Policy Editor by aechols · · Score: 1

      Give me 1 copy of ghost and 100 empty pcs and toss in a nice little 100Mbps network and I'll hand you back 100 boxes in 5-7 hrs tops that are harder to crack than leather pants off a fat chicks ass.

      That's irrelevant. Ghost is not windows. Ghost is not unix either. Ghost is a separate program you can buy. You could set up linux, some unix, bsd, or whatever the heck you want and ghost it to a 100 boxes in the same amount of time.
      --
      Are you pondering what I'm pondering?
    19. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      No. You need to use g4u for that.

    20. Re:Another Solution - Windows Policy Editor by m_pll · · Score: 1
      Group Policy kicks ass.

      This is true...

      You can completely lock down a machine so that cmd.exe doesn't work no matter what and the only .exe's that do work are the ones you specify.

      But this is not.

      If you're talking about Software Restriction policies, they only protect users from shooting themselves in the foot. A determined user will still be able to run arbitrary code if he really wants to. Truly secure code restriction would require hardware support (like XBox).

      Software restriction policies are useful but please don't depend on them for security. That's what proper user rights and ACLs are for.

    21. Re:Another Solution - Windows Policy Editor by m_pll · · Score: 1
      In windows you have to options: either you allow people to do everything or you allow them to do nothing. The policy editor just stops working once you allow someone to run an .exe from his desktop since he can break the system (with one of the numerous exploit that for example the GUI gives you).

      What the hell is this supposed to mean? On a properly patched system users can run executables from their desktops all they want, and this won't allow them to bypass security related group policy settings (I'm talking about things like user privileges and group membership, not UI stuff like access to Start menu).

    22. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      Ah. No. You're thinking of 9x. The previous poster was referring to Windows 2000/XP, which has very decent client lockdown tools.

    23. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      Ah. No.

      If you lockdown a machine with NTFS ACLs and Software Restiction Policies, there's no way a normal user can run arbitrary code. Try it on a test domain - Give a user write access to only his MyDocs folder, and do SRP rule that bans any exe's in MyDocs.

    24. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      Um...no. Group Policy works very well with networks with thousands of workstations. Such as the network in my office.

    25. Re:Another Solution - Windows Policy Editor by Plug · · Score: 2

      And there's no way of doing this from Linux. You either get a Win2K server, or you define policy on _EVERY_ local machine, which kinda defies the point.

      If you have a way of pushing policy to Windows clients from a Samba DC on Linux you will make at least one sysadmin very very happy.

    26. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      The original poster was referring to Windows 2000/XP managability software. You seemed to focus on 9x.

      Windows 2000/XP actually has very decent admin tools for configuring workstations. Read up on it at microsoft.com

    27. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      Using Group Policy in XP allows you to ban executables from executing bashed on location, signing certs or hashes...It's a bit different from the options you had on 9x.

    28. Re:Another Solution - Windows Policy Editor by mnbjhguyt · · Score: 1

      You might be right, but you have to consider that in order to use group policy you need the server version of win2k, which costs much more.
      And for schools the budget is usually tight.

      mnbjhguyt

    29. Re:Another Solution - Windows Policy Editor by siliconjunkie02 · · Score: 1

      I think I could help you with your coughing problem. mark*siliconjunkie.net

    30. Re:Another Solution - Windows Policy Editor by siliconjunkie02 · · Score: 1

      Dont give the execute permissions on any folder they have write access too. Simple as that, No more running things from their desktops. Just lock the thing down tight, dont let the execute anything anywhere and try to do whatever it is they need to. Then open it up as needed. With GP you can disable Active X and all that in pages, so no more worries about that.

    31. Re:Another Solution - Windows Policy Editor by siliconjunkie02 · · Score: 1

      Number 1 thing you can do to keep your users from doing anything real stupid. Don't give them write/change AND execute access in the same dir. Then you can be pretty sure that they arent renaming or getting their own .exe's. Even if they do run one, they shouldnt have write/change access to the system dir so they wont hose the box.

    32. Re:Another Solution - Windows Policy Editor by Mongoose · · Score: 3, Interesting

      Listen that's not true at all. You can run anything you want when you rename the EXE to a runnable like 'notepad.exe'. Add to this Word VBA scripting and you'll have admin on the box in seconds. In our lab we have people still installing porn and crap b/c it's so easy to do this.

      On a floppy copy an alternative shell for windows and name it say winword.exe. You most likely can run anything you want off the floppy, so then you just run say the kernel debugger or the MS hole of the week ( ie is weak to loading HTML scripting attacks off disk also. ) -- and then you can use policy editor to start mounting all those hidden windows shares and hijacking other user's computers.

      This is why windows is a joke - suid programs and permissions controls by name of a file.

    33. Re:Another Solution - Windows Policy Editor by siliconjunkie02 · · Score: 1

      You can save them as a template/inf and it just takes moments to apply. And you can do it remotely with the MMC with no domain. Just connect to each machine and do it.

    34. Re:Another Solution - Windows Policy Editor by siliconjunkie02 · · Score: 2, Interesting
      There are alot of assumptions here.

      "You can run anything you want when you rename the EXE to a runnable like 'notepad.exe'"

      This assumes that they have write/change and execute in the same dir.

      "You most likely can run anything you want off the floppy"

      You are admitting that the machine is misconfigured

      "and then you can use policy editor to start mounting all those hidden windows shares and hijacking other user's computers."

      This also assumes that the shares have been modified since by default the $/admin shares are only available to admins. Also I would like to know how to use policy editor to mount a share.

      Don't mistake poor configuration for a poor OS. *nix has its strengths but management at the desktop level isnt one of them. Windows has it beat IF you know how. But that goes for both

    35. Re:Another Solution - Windows Policy Editor by m_pll · · Score: 1
      If you lockdown a machine with NTFS ACLs and Software Restiction Policies, there's no way a normal user can run arbitrary code. Try it on a test domain - Give a user write access to only his MyDocs folder, and do SRP rule that bans any exe's in MyDocs.

      I can immediately see several problems with this setup:

      1. Since the only rule that we have is to block anything from MyDocs, the user can still run any program from system32. So he can use for example ntsd.exe to write arbitrary data into one of his own processes (like his shell). If he can do this, it's game over.

      To prevent this you'd have to carefully examine every system executable and disable the bad ones, or replace the shell so that users can't even try to run them. This setup would be closer to a kiosk than a normal workstation though.

      2. How do you create your path rule? Are you sure there are no path canonicalization issues with it? (most likely there are)

      3. Unless you go out of your way to prevent it, users can change their registry and profile settings, so they can try to manipulate them to cause a crash in the shell or some other process that runs as the user. Most software is not tested very well to protect against this scenario (users trying to crash or corrupt their own processes). It's quite likely that you could find bugs leading to code execution.

      4. How do you make sure MyDocs is the only place where users can create files? It's not trivial. Do you know that by default there are places other than %userprofile% that are writable by normal users?

      Sure, it's possible to lock things down so that it will be very difficult for users to run arbitrary code. But it's not easy and if you also want to allow other programs besides the shell, you're almost guaranteed to get it wrong.

      Note that I'm not saying that SRPs are not useful - they are. But they shouldn't be your only line of defense.

    36. Re:Another Solution - Windows Policy Editor by jez9999 · · Score: 2

      Dont give the execute permissions on any folder they have write access too. Simple as that, No more running things from their desktops. Just lock the thing down tight, dont let the execute anything anywhere and try to do whatever it is they need to.

      But newsflash: that sucks. If a person doesn't have their own computer (I know I know, but some don't), they WANT to be able to download stuff and run it! Why should they only be able to run the crap (read: microsoft office 2000/xp) prescribed to them by the system admin?

    37. Re:Another Solution - Windows Policy Editor by jez9999 · · Score: 2

      Don't give them write/change AND execute access in the same dir. Then you can be pretty sure that they arent renaming or getting their own .exe's.

      OK, and what good is that to a class of students trying to learn C++? I'll just compile the program and ... wha? It says I can't run it!

    38. Re:Another Solution - Windows Policy Editor by m_pll · · Score: 1
      Come on, this is just stupid. To add to what siliconjunkie02 said, you're assuming that there's a rule that allows anything named 'notepad.exe'. Of course nobody in their right mind would do that. That's what hash or certificate rules are for. As I mentioned in my other posts in this thread, it would still be possible to bypass them in some cases, but it wouldn't be so easy.

      Also, no amount of VBA scripting will give you admin access if the box is properly patched. And local elevation of privilege bugs are not that common. IE scripting bugs definitely aren't going to make you an admin, they can only destroy your own files.

      Oh, and to be able to use kernel debugger you have to be an admin already.

      As for permissions control based on the filenames - yes, this is stupid. You should control access to resources, not executables. Normal NT security model is just for that. Software Restriction policies are for administration, not for security.

    39. Re:Another Solution - Windows Policy Editor by siliconjunkie02 · · Score: 1

      In theory, if your permissions are right, they wont be able to hose it running an exe anyhow, but I was speaking more specifically to the concern of people running things they download.

    40. Re:Another Solution - Windows Policy Editor by siliconjunkie02 · · Score: 1

      As I see it I am not here to provide them with and support/fix their own little playground. If part of their assignment/job function is to do this, then you allow it as securely as possible. Give users only as much rights as they need to do their job. If they want to gripe that they can't install the latest spyware, tough. It saves you headaches and the company money.

    41. Re:Another Solution - Windows Policy Editor by mpe · · Score: 2

      In windows you have to options: either you allow people to do everything or you allow them to do nothing. The policy editor just stops working once you allow someone to run an .exe from his desktop since he can break the system (with one of the numerous exploit that for example the GUI gives you.

      Also in older to use the "only run allowed executables" policy option you need to know exactly which files you need to allow to be run. Which can translate into lots of trial and error everytime you install/update an app.

      Now, imagine that user has to do some task, and they have messed up their configs. Now on Windows you either repair their profile (which can take quite a time if you can't login as them, if possible at all) or take backup of files, create new profile and copy the files over,

      You may still have problems, since there might be some critical data in the USER branch of the registry, how do you examine and manipulate this other than trying to login with that .DAT file?

      And once you get new systems with different hardware you have to do it again :) With linux you dump the same image and switch either kernel or module config.

      You don't even need third party tools to copy a Linux workstation, since the regular utilities will do just fine.

      Windows has it's strong points, but administration isn't one of them. At least if you are trying to do it well. In a Uni even "we are not mission critical,

      The students might disagree about the "mission critical" issue :)

    42. Re:Another Solution - Windows Policy Editor by mpe · · Score: 3, Informative

      That's irrelevant. Ghost is not windows. Ghost is not unix either. Ghost is a separate program you can buy. You could set up linux, some unix, bsd, or whatever the heck you want and ghost it to a 100 boxes in the same amount of time.

      Except that you could clone 100 identical unix hardware workstations using basic unix tools. No need for a third party product.

    43. Re:Another Solution - Windows Policy Editor by mpe · · Score: 2

      And with Unix, you can have reasonable security without doing silly things like disabling shell access. Unix was made for secure multi-user environments and remote administration.

      One of these environments was UCB, another was MIT... Are Australian students somehow more destructive than American ones?

    44. Re:Another Solution - Windows Policy Editor by Tony-A · · Score: 2

      Locked down so that cmd.exe doesn't work.
      Problem is, you want it locked down and cmd.exe *does* work.
      You set it all up nice and perty, but some program you have to run requires administrator rights for the user, and poof goes all your security.
      ls -l conviently shows owner and group and permissions. DIR does not.

    45. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      And you are trying to say what? One line says one thing, the next says the opposite. A unix command shows something a windows command doesnt. Whats the insight here?

    46. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      CACLS- write a script once to set permissions and run it as often as you feel necessary.

    47. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 1, Informative

      GNOME 2.0 Desktop System Administration Guide
      http://www.gnome.org/learn/admin-guide/2.0/

      'nough said.

    48. Re:Another Solution - Windows Policy Editor by ink · · Score: 2
      You are admitting that the machine is misconfigured

      OMFG... Being able to run programs off a floppy is considered a "misconfiguration" in the Windows Wild World of Security now? And you people wonder why we laugh so hard.

      --
      The wheel is turning, but the hamster is dead.
    49. Re:Another Solution - Windows Policy Editor by FoxMcCloud · · Score: 1

      This is so wrong. Linux has by FAR the easiest way to let users do anything they want without them being able to screw the system up. On most distributions, all you have to do is make a default install, and you're set. They can change and run anything they want in their own account. If they totally screw up their system, the next person using the machine won't even notice it.

      How is it any easier to do that in windows? You can probably do it too, but you have to set those things manually whereas it's all set by default when you install Linux.

      What's more, the users can run anything they download, or they code themselves, without compromising the system, instead of kludges that I read in this thread like "not allowing write and execute in the same directory"...

      --
      bool Marketoid::IsGood(){return IsDead();}
    50. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      Changing policy is simply a matter of changing a couple of config files on Unix/Linux. It's dead simple to *automatically* copy config files to 10s or hundreds of thousands of machines. What can't be done with config files can be done with several other standard practise techniques.

      Also, I personally don't know why you need 40 hours to set up a RedHat machine. RedHat gives you the tools to create kickstart disks to automate your installs as much as you want and even install custom programs. I won't even go into mirroring and other tools that come standard with any Unix.

      Face it, Unix practically invented most of the stuff Windows people are just now starting to recieve. Yes, the Linux/Unix approach isn't generally point-and-click (although HP and Sun do have several good interfaces), but they aren't *that* difficult and you get a lot more power from them. You also don't have to relearn everything every time Microsoft decides to revamp their GUI once every 3 years.

    51. Re:Another Solution - Windows Policy Editor by weave · · Score: 2
      GPO has a lot of holes and ways to get around things. Many of the restrictions are only enforced in the windows explorer shell. As for restricting to a specific set of programs, all you need to do to get around that is rename the exe of the program you want to run to be the same as one of the permitted programs and away you go.

      Maybe with Palladin and code signing and only allowing signed code to run, this will finally work! (*ducks*)

      It's all getting better in each release of Windows, but there still is a long way to go. There are so many programs that are not Windows logo compliant and to get them to work you must do inane things like open up that program's program directory to change access or open up large sections of HKLM, all things that would prevent a program from getting the logo. But when you scream at vendors, their usual response is to just give people local admin rights or power user rights.

      Some vendors are really bad. Adobe, for example, only has one program that is logo compliant according to their web site.

      You try to tell an academic department that they can't install program x on lab machines and you don't get much sympathy. A call or two later and some administrator is saying how important this program is and the (academic) program needs it and this could affect accreditation, etc, etc... so just install it anyway.

      An install is only as strong as its weakess link. NT first came out what, almost 10 years ago, and network servers with file ACLs were out long before that. Yet vendors still write their code thinking they have absolute full access to scribble data to anywhere on the file system.

      At least in Unix, I've never seen a user app that won't run unless all users are given root access and or write access to /usr/bin, /etc, and other fun locations!

    52. Re:Another Solution - Windows Policy Editor by botik32 · · Score: 1

      Grsecurity [www.grsecurity.net] - an ACL system on top of Linux security structure.

      You can restrict lots of things, including opening client network ports, secure ports, raw tcp and much more even for root, per userid or gid of process.

      And although I did not try that specifically, installation on multiple machines should not be too complex either: one compiled kernel and an acl file in /etc/grsec/

    53. Re:Another Solution - Windows Policy Editor by JKR · · Score: 2
      The context was "locked-down box". If I walk up to your secured linux system with a statically linked, suid copy of Vi on a floppy and you "misconfigured" your fstab such that I could mount and run it, that's the same problem.

      Please don't be an idiot. Thank you.

      Jon.

    54. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      Windows 2000 Server comes with Remote Installation Services and Riprep, which you can use to clone machines.

    55. Re:Another Solution - Windows Policy Editor by Fulcrum+of+Evil · · Score: 2

      how do you examine and manipulate this other than trying to login with that .DAT file?

      Graft the dat file onto the registry somewhere and examine it there. It isn't hard, and you can even do it over the network.

      --
      "We returned the General to El Salvador, or maybe Guatemala, it's difficult to tell from 10,000 feet"
    56. Re:Another Solution - Windows Policy Editor by Enigma2175 · · Score: 2
      If you have a way of pushing policy to Windows clients from a Samba DC on Linux you will make at least one sysadmin very very happy.

      It was my understanding that you create the policy then drop the *.pol files in the netlogon share on your PDC and the workstations will download them and apply them upon startup. I am working on implementing a Samba DC myself, but it is like pulling teeth to get anything to work right. So for now it is relegated to the test network.

      --

      Enigma

    57. Re:Another Solution - Windows Policy Editor by Anonymous Coward · · Score: 0

      Don't know how well this might work for your setup, but secedit.exe is a command line tool for managing local security policies on Win2k Professional. You can use it to export/import group policies from the command line, batch files, or scripts.

    58. Re:Another Solution - Windows Policy Editor by yerricde · · Score: 1

      (this comment represents the views of the bean counters)

      Why should they only be able to run the crap (read: microsoft office 2000/xp) prescribed to them by the system admin?

      Because they're using a computer owned or leased by the company.

      Because they're using bandwidth leased by the company.

      Because they're using electricity leased by the company.

      If strangers want to be able to download stuff and run it, they can put a computer on their credit card and pay for electricity and dial-up Internet access with their own money.

      --
      Will I retire or break 10K?
    59. Re:Another Solution - Windows Policy Editor by jez9999 · · Score: 2

      Yeah, except here, we're talking about CS students, and they should not be limited in this fashion.

    60. Re:Another Solution - Windows Policy Editor by gl4ss · · Score: 2

      .. at this one place, the windows computers were set so that you could only run executables named something(for example telnet.exe and such), and those executables could then launch anything they wanted.

      needless to say there were lots of funny shit on all desktops, ftp.exe with winamp icon, telnet with a very funky icon & etc.

      --
      world was created 5 seconds before this post as it is.
    61. Re:Another Solution - Windows Policy Editor by Arandir · · Score: 2

      I'll second your comment. I've never tried to lock down a Windows machine, but from what I've heard, it takes considerably more knowledge then what you learned in "Be An MCSE in 24 Hours".

      On the other hand, install a BSD or reasonable Linux distro, and you're done. For the paranoid (and you can never be paranoid enough), disable CDROM and floppy booting in the BIOS, password the BIOS, make everything but /var, /tmp and /home read only, and keep up to date on the security issues.

      --
      A Government Is a Body of People, Usually Notably Ungoverned
    62. Re:Another Solution - Windows Policy Editor by Arandir · · Score: 2

      if you setup linux in ~40 hours (for shared use) you are pretty fast.

      I sure hope Linux isn't that horrible. I spent 20 hours setting up a FreeBSD box securely for shared use. 15 of those hours had nothing to do with configuration or security, but were peripheral tasks like writing site-specific admin and user manuals, testing, etc.

      --
      A Government Is a Body of People, Usually Notably Ungoverned
    63. Re:Another Solution - Windows Policy Editor by Rutulian · · Score: 1

      This assumes that they have write/change and execute in the same dir.

      But you see that is just it. In order to lock down a Windows box you have to cripple your users. Why shouldn't I be able to write files and execute programs in my home directory?

      Using a locked down Windows box is a pain in the ass because you can't do anything with them. Need to install a secure ftp client, too bad. Want to compile something, sorry you can only use Word here.

      My linux box is effectively locked down. I can't change anything on the system without the root password. But I can do anything I want in my home directory.

    64. Re:Another Solution - Windows Policy Editor by dvdeug · · Score: 2

      The context was "locked-down box". If I walk up to your secured linux system with a statically linked, suid copy of Vi on a floppy and you "misconfigured" your fstab such that I could mount and run it, that's the same problem.

      There would be no problem running it. But the floppy drive is usually set nosuid, so it would just ignore the suidness of the file. Nonprivliged users can't preserve the suidness of a file while copying, either.

    65. Re:Another Solution - Windows Policy Editor by SectoidRandom · · Score: 2

      I enjoy dealing with users with your attitude. As someone else pointed out since the use of Company/School resources is strictly controlled (and always should be), the first thing I do when a user complains about not being able to change the desktop walpaper is add that GPO (Group Policy Object) to the now heavily restricted user!

      hehe

    66. Re:Another Solution - Windows Policy Editor by jez9999 · · Score: 2

      I didn't know the BOFH perused the Slashdot discussions! :-)

    67. Re:Another Solution - Windows Policy Editor by aechols · · Score: 1

      I did this on a windows 2k pro machine day before yesterday. It works.

      --
      Are you pondering what I'm pondering?
    68. Re:Another Solution - Windows Policy Editor by deblau · · Score: 2
      Group Policy kicks ass. You can completely lock down a machine so that cmd.exe doesn't work no matter what and the only .exe's that do work are the ones you specify. You can let the user specify their Display preferences, but nothing else. Or everything except the Display preferences. The point is, Linux has nothing to compare with this.

      Sorry to burst your bubble, but it's called /etc/group, and it was invented long before Windows.

      If Linux had anything to easier to compare to this I'd be using it (admins being essentially lazy).

      Uh, no, that's users who are lazy. Just because you know how to admin, don't mean you're an admin. I run Windoze at home. Why? Because at home, I'm a lazy user. Says nothing about my day job...

      The FACT is no one has a better way to administrate and trouble-shoot end-user desktops than Microsoft right now.

      Uh, sorry to burst your bubble again, but that's an OPINION. Another opinion is that you're a troll.

      --
      This post expresses my opinion, not that of my employer. And yes, IAAL.
    69. Re:Another Solution - Windows Policy Editor by jtev · · Score: 1

      Ok, here's the difference between those. win2k, use remote administration tool do one box at a time, Unix, Install unix you want on one drive, install any Unix OS on another, put both and one blank drive in third box, copy the ENTIRE instalation from source disk to blank disk, no fuss no muss no hassle. with a few command line switches it's even easier, no need for the third disk, but this is the easiest way. windows won't allow you this sort of flexability. if you use identical drives for all your machines you can just do "dd if= of= and it does a bit copy of the disk, JUST LIKE GHOST. You don't even have to partion the blank drive first because the partion table is also copied, (hence my comment about this being the easier way)

      --
      That which is done from love exists beyond good and evil
  7. LAME POST ALERT!! by Anonymous Coward · · Score: 0

    -- Campaign Against Lame Slashdot Posts

  8. Re:Early Post by skinnydskitzo · · Score: 1

    "Kinda sounds like the Linux crowd, huh? "I'm so ALTERNATIVE by patching my kernel every day while you brainwashed Windows sheep meander in unenlightened tedium." Funny to think that if you had back all the time you spent tweaking and patching (for no good reason other than to say you have the latest version), you wouldn't know what to do with the workstation on your desk." i probably would of spent that time trying to be different

  9. the original quote by SHEENmaster · · Score: 2, Funny

    And 1.1.81 is officially BugFree(tm), so if you receive any bug-reports
    on it, you know they are just evil lies."
    (By Linus Torvalds, Linus.Torvalds@cs.helsinki.fi)

    --
    You can't judge a book by the way it wears its hair.
  10. Re:IN SOVIET RUSSIA by Anonymous Coward · · Score: 0

    HA! Mod this baby up!

  11. PH34R 7H3 VL@DEQU@CY! by Anonymous Coward · · Score: 0

    0wn3d!

  12. People read the article! by Mustang+Matt · · Score: 5, Interesting

    By locking down, I think they mean students can go in and randomly format the drive like they could in a stock Win9x setup.

    They also mention that they like linux because it's easy to give to students. They don't have to worry about costs or licensing, they just hand the students a CD and they're on their way.

    "We'd rather explain how things work. We do that by taking things apart and putting them back together again, rather than just showing people how to use particular GUIs that other people have designed. It's our belief that open-source software better explains those concepts," he said.

    That seems pretty logical to me. The article really wasn't about taking away freedom at all.

    --
    The man who trades freedom for security does not deserve nor will he ever receive either. - Benjamin Franklin
  13. Re:Early Post by Anonymous Coward · · Score: 0

    I guess the BSOD that you receive while running windows takes away from your time to be truly creative with that workstation on your desk to actually come up with a new troll.

    This one is tired and used up.

  14. Learning Experience by Amigori · · Score: 2
    This will be an experience for all parties involved, students, teachers, and admins. The admins learn how to properly lock down a system, the teachers learn more of the nuances of the system as..., the students learn how to overcome the limits set by the admins. Good show, I say... I just wish more schools, specifically my old high school, would look into locking down there systems, even if they keep windows. Windows 2000/XP has a nifty policy editor that helps on preventive maintenance.

    Speaking of switching, and maybe OT, I've been contemplating more and more about switching back to a *nix based system as all the games that I want to play will not run on my system and I am not too keen on building another one that will just be outdated in a year...(Am I growing out of my geekness, or just tiring of spending so much money?)...Its almost as big of waste of money as my car is...No, I think I will just optimize the one that I have and probably load OpenBSD on it.

    Amigori

    --
    "The quality of life is determined by its activites."--Aristotle
  15. easy to lock down by lingqi · · Score: 1

    ... or make heck of a bunch of hackers / crackers and what you have it ...

    my highschool had student admins. (it was the Louisiana School for Math, Science, and the Arts, btw - i know there are others out there in different states. chime in if you know what i am talking about / goes/went to one) These said students knew more about computers, security, and everything so much more than the actual school admins - that eventually when the school decided to "take" these machines from them (changed root password, etc), they got in before you had time to say "blueberry pie."

    so either way, it's good. though I am not sure about the attitude it breeds in people. I know I will get flamed / called a flame-bait - but seriously though - a lot of times stereotypes exist for a reason, and unfortunately unix/linux breeds some of the smartest, but yet sometimes the most anal / strange admins /hackers in existance.

    --

    My life in the land of the rising sun.

    1. Re:easy to lock down by Anonymous Coward · · Score: 0

      "... am not sure about the attitude it breeds in people. I know I will get flamed / called a flame-bait - but seriously though - a lot of times stereotypes exist for a reason, and unfortunately unix/linux breeds some of the smartest, but yet sometimes the most anal / strange admins /hackers in existance."

      It's called "motivation".

      Geeks aren't the only people who get it. Also, put away those scanning tools and root kits. The best technique for getting into any computer is the application of a little social engineering.

      I mean, why go about it the hard way?

    2. Re:easy to lock down by Nynaeve · · Score: 1

      Admins for these kinds of high schools really do have a challenge -- as well as the colleges around them. :)

      At OSSM (Oklahoma School of Science and Math), we didn't have much of a problem with hacking. The exception being the first year of operation (1990-91) when we ran a MIPS-based Unix terminal setup. A certain individual of this class (CO'92) boasted of rooting the server 50+ times, but the rest of us never really cared much for hacking the system (which was changed over to Novell 3.11 when I was there - CO'93). We cracked a few shareware games, maybe, but not the server.

      I must relate one story, however: During the two years I was there, we lived in dorms on the Norman OU campus. At the time, OU had a BBS that you could dial into and download files, drivers, games, etc. The usual BBS stuff. Well, a friend and I had tired of the long download times and figured since the BBS was on campus we might as well take some floppies to a computer lab and copy them onto disk instead of downloading them. We didn't know if it was possible or not, but we trudged over to the nearest lab (also a Novell 3.11 network) and logged onto the file server as the username the BBS ran under. We discovered there was no password. Additionally, we discovered the account was also ADMINISTRATOR EQUIVALENT. It wasn't just a file server, either. There were user accounts and everything. No hacking needed - OU had left the door wide open. We laughed a bit, copied the drivers we needed, and left. I always wondered if anyone else ever discovered it...I went to OSU after high school.

      <shameless-plug>OSU: 38, OU: 28</shameless-plug>

  16. Windows Policy Editor - could it be any worse?? by dan_barrett · · Score: 5, Informative

    Yes, you *could* use windows policy editor, but there are some major issues with it (having just locked down a standalone windows box for kiosk use I'm well versed in the pain of poledit for Win 2000..)

    Note that policy editor is now primarily designed for a computer in a Active directory tree - without active directory you have to edit a "local" policy, ie edit the registry directly.

    A disclaimer: maybe an active directory policy is nicer to play with, I don't know - local policies were enought of a pain for me as it was..

    here's the fun with local policies..
    firstly - the policies affect ALL users, INCLUDING the administrator. (WTF?!?!? you say?) so.. lock out all registry tools, disable "command prompt" and run on the start menu - and you're screwed - no more windows administration. time to reformat the box. (or at least attempt to "rescue disk" it..

    second - policies quite often are applied in REAL TIME. hmm.. disable registry editing.. (screen flashes) - oh bugger, policy editor has stopped working..

    The way to get around this is to remove access to the %winnt%/system32/GroupPolicy dir for the administrator (that's right, you remove access to the root user to prevent the policy applying to that user.) of course, this dir has to be accessible to make any changes. And the changes apply immediately. Forget to reapply the restictions to the admin user and it's reformat time, again.

    if you want to use policy editor I suggest having a recovery cd lying around, as I guarantee you *will* be locked out of your system, unless you're extremely careful.

    I love windows security, it rocks.

  17. Finally.... by ExEleven · · Score: 1

    Its good to see everybody switching to Linux, but its even better to see it in Austrlaia, but lots of schools down under use Linux as well. But they tend to use it for Terminal Servers and the like, with tarantella.

  18. please explain this by atari2600 · · Score: 1

    From the article...

    ...UWA recently dropped Apple from its IT education programs in the school, for the same reason that Unix was abandoned -- expensive proprietary hardware. Doh!. Furthermore they are not using HP-UX or Solaris. Someone tell them about SCO Open Server? or tell them that Unix was ported to the PC long back.

    1. Re:please explain this by vlchung · · Score: 1

      Which variant of UNIX are you referring to? Being a postgrad at this School, we've been dual boot Linux / (NT/2K) since PCs replaced our old X-terms (circa 1995 or so); indeed almost all of our infrastructure is Linux based.

      Perhaps reading the entire article is called for; clearly the implication from your comment was that we are a non-Unix shop, where I think most people would say that running Linux certainly entitles us to say that we are.

  19. And your point is what? by dschl · · Score: 1

    While I am far from being a big fan of Windows, all your comment tells me is that Win 3.1 (which is what, a 12 year old DOS-based OS) could not be locked down.

    Your comment would be a bit more relevant if you had a similar example for Win2k or XP.

    --
    Slashdot - the place where you can look like a genius by restating the obvious
    1. Re:And your point is what? by Anonymous Coward · · Score: 0

      His point was that there is no security in locking down the Start Menu. If a user can run command.com or other potent utilities, they will find a way to do it.

    2. Re:And your point is what? by Anonymous Coward · · Score: 0

      We have a security camera system installed on a windows machine, we had no way to share out the C drive (Win98) and this program replaced the explorer shell.

      Goto save video, go back to my computer, right click C drive, share, done.

      This can be replicated on a Win2k/XP machine.

      Win Xp is nice, right click on a exe, run as, and select current user:)

  20. Re: Windows Policy Editor - could it be any worse? by Anonymous Coward · · Score: 1, Informative

    Jeesum, no wonder this world is coming to an end. There are SO MANY IDIOTS OUT THERE WHO THINK THEY KNOW WHAT THEY ARE DOING.

    You don't use PE on Win2K, you use group policy editor. OMFG-no wonder there are no jobs

  21. GNU/Linux is still usefull after lockdown. by XTerm89D · · Score: 2, Informative

    That's the difference between a secured Unix system and a 'Windows policy editor lockdowned' system.

    In windows you just have to close down all ways to do nasty things. End result : undestroyable but also completely useless pc. Nobody can do anything on it.

    With a Unix system, students can't mess around anything BUT they can do whatever they want in their personal enviroment and a Unix box is still a usefull tool without root access.

    1. Re:GNU/Linux is still usefull after lockdown. by mpe · · Score: 2

      In windows you just have to close down all ways to do nasty things. End result : undestroyable but also completely useless pc. Nobody can do anything on it.

      Assuming you don't miss some of the holes and end up with a trashed machine anyway. Maybe because of some piece of malware rather than user vandalism.

      With a Unix system, students can't mess around anything BUT they can do whatever they want in their personal enviroment and a Unix box is still a usefull tool without root access.

      It's even possible that they may mess up their user area so they can't log in, but that dosn't affect every other user. Quite often the attempts to make Windows multi-user don't quite work.

  22. Why use anything other than Linux for comp sci? by Omega · · Score: 5, Insightful
    When you think about it, Linux really is the best operating system for comp. sci students. It offers open source access to the kernel, so you can see the actual code for the operating system and how it interacts with many different types of hardware. Also you have low level access to many devices through the dev. tree so you can teach device programming methods. Not to mention the fact that the primary unix networking protocol (TCP/IP) is the same protocol that runs the internet. What better way to gain an understanding of packet based protocols than by experimenting with BSD sockets? "The Unix Time Sharing System" by Dennis Richie is one of the most elegant descriptions of an operating system that I have ever read. And by working with the text and the operating system together, students can gain a fundamental understanding of many basic low level concepts in modern computers.

    If all you want is to be an MCSE, then why waste you time with college? You can take a weekend course for a few hundred bucks (instead of 4+ years for several thousand dollars). This quote from the article by Dr. Chris McDonald of UWA pretty much sums it up:

    "Personally, I think that just showing students how to use operating systems tools and networking tools, is more training than education.
    Exactly. Showing someone how to point and click isn't teaching them anything. It's only training them how to use someone else's tools (and there are books that can teach you that in 24 hours). Real computer science education, where you gain a fundamental understanding of both high and low level concepts of the computer requires more than just clicking a start button.
    1. Re:Why use anything other than Linux for comp sci? by Anonymous Coward · · Score: 0

      Don't forget the BSDs.

      I personally feel NetBSD is one of the best learning environments. You have all the code for the whole system right there for you. Just 'cd /usr/src' and start reading :)

      NetBSD has clearly written code, clearly written (and up to date) documentation, and in general is designed as a research operating system, making it a great learning environment.

      However, it doesn't have all the hardware/software support of Linux, and is a little slower to get new features implemented. But if learning is what you care about, this isn't a problem.

      That's just my take on things as a comp. sci. student.

    2. Re:Why use anything other than Linux for comp sci? by zoster · · Score: 1

      Agreed that it is the best operating system for comp sci. But that's not where it ends. Our electrical engineering dept. has been on linux for quite a some time now. There are some real good open source tools ( SPICE, MAGIC, IRSIM etc.) out there, which are actively used in the academic arena. We can't afford commercial software, nor can we spend on high-end servers. As a result, PC's running on linux (with open-source tools) is the best solution.

    3. Re:Why use anything other than Linux for comp sci? by dubious9 · · Score: 2

      I can't say how much I agree with you. In interviews know I've been getting the question, "If you could give one piece of advice to an incoming CS student, what would it be?" My answer? Learn linux.(the reasons for this answer usually fly over the head of the HR interview person and I get blank stares)

      If I'm ever in the position to hire new graduates, I'll ask about their linux exposure in school. IMNSHO listing linux always looks better than listing windows. Microsoft is working hard to make sure that any old idiot can half work their computer, but to be functional in linux (now at least, ) require much more insight into the workings of a computer.

      Almost as valuable, would be commandline development familiarity instead of solely GUI IDE.

      --
      Why, o why must the sky fall when I've learned to fly?
    4. Re:Why use anything other than Linux for comp sci? by sheldon · · Score: 2

      "It offers open source access to the kernel, so you can see the actual code for the operating system and how it interacts with many different types of hardware."

      That's great if you are taking the OS track of ComSci... But that's only one small part of the entire CS curriculuum.

      "If all you want is to be an MCSE, then why waste you time with college?"

      The MCSE is a systems administrator certification. Presumably if you are in ComSci you intend to learn more about software development, so this argument appears to be a non-sequitor.

      "Real computer science education, where you gain a fundamental understanding of both high and low level concepts of the computer requires more than just clicking a start button."

      When I was in ComSci the students didn't even know how to load paper in the printer. I'd have to say some fundamentals of computer use are probably important. Disappointing perhaps, but important.

  23. IN YODA RUSSIA... by Anonymous Coward · · Score: 0

    Boring are YOU!

    1. Re:IN YODA RUSSIA... by JavaTHut · · Score: 1

      That would be a question in yoda speak "Boring are you?" for a statment you need to leave the subject uninverted: "Boring YOU are!"

  24. Re:Slashdot Trolling History - Cool by Anonymous Coward · · Score: 0

    Jeez, you're really boring.

  25. Slashdot Social Experiment by kNIGits · · Score: 5, Interesting

    People have been saying for years that Slashdotters don't read the article, so I thought that I'd test the theory. I'd submitted the story and highlighted something insignificant about the article in the submission. Browsing through this page, I see lots of people discussing merely what I wrote at the top - 'locking down' students. If people actually read the article, they'd see that it was more about teaching software development in an open source environment, and also the fact that they can give free Linux cds to the students to replicate their training systems at home.

    What I'd like to know is - how can the Slashdot Effect exist when no-one clicks through to read the article?

    This karma-reducing social experiment was proudly brought to you by kNIGits in Australia.

    1. Re:Slashdot Social Experiment by Anonymous Coward · · Score: 0

      Wow you proved Slashdotters don't read articles.
      No, shit?

    2. Re:Slashdot Social Experiment by jez9999 · · Score: 1

      That's just great. I submit a load of perfectly good stories, and they are immediately rejected. But you submit some crappy Australian Uni Linux-switching story with a self-confessed stupid comment, and it gets posted. What do Slashdot editors do, use Rnd()???

    3. Re:Slashdot Social Experiment by sco08y · · Score: 3, Interesting

      The people who karma-whore try to get their posts in as quickly as possible because, as the FAQ says, if you get in sooner more people will read it and it's more likely to be higher ranked.

      Because of the karma system, you're only seeing people who employ karma-whoring strategies rather than intelligent commentary. That means making politically correct comments about whatever the submitter said. That means mouthing the standard, "freedom-reducing lock down is bad!" kind of remarks.

    4. Re:Slashdot Social Experiment by apol · · Score: 2, Insightful
      how can the Slashdot Effect exist when no-one clicks through to read the article

      Hmmm my bet is that while half of slashdotters are looking for the article and producing the slashdot effect the other half is busy writing "insightful" comments based on their guesses. Since the earlier you write the more likely you are moderated up, the most typical slashdotter is finally the one who does not read...

    5. Re:Slashdot Social Experiment by archen · · Score: 2, Insightful

      Theory A: Article never works because it's always slashdotted.
      Theory B: Some of us avoid reading an article to avoid slashdotting a server.
      Theory C: Some of us don't care about the topic and only want to read what others have to say. Then we randomly reply wherever we want, to stuff that was probably misinformed in the first place. If you want ontopic threads, post an ontopic summary.

    6. Re:Slashdot Social Experiment by Anonymous Coward · · Score: 0

      There are those who read the article, and there are those who comment upon it. And rarely are they one and the same. Welcome to slashdot.

    7. Re:Slashdot Social Experiment by Anonymous Coward · · Score: 0

      What do Slashdot editors do, use Rnd()???

      Well, actually...

    8. Re:Slashdot Social Experiment by Anonymous Coward · · Score: 0

      Shit, they're on to us!

      Moderators meeting! I call Moderators meeting!

      Look, people are starting to figure out the random thing. In a few more stories, they'll understand that this is why the summary barely ever relates to the actual link, and why so many dupes are posted. It won't be long before they realise that we're ALL full of shit, and then we wont make any more money off our banner ads!

      Our "jobs" are on the line! Panic! Panic!

  26. Re: Windows Policy Editor - could it be any worse? by agallagh42 · · Score: 4, Informative

    Just because you don't know how to use a tool, doesn't make that tool bad.

    A properly configured local policy can lock down exactly what you want to lock down, and affect only the users you want it to affect.

    Also, in Active Directory, you use things called "Group Policy Objects" to apply policies to workstations, and it's WAY more powerful than local policies.

    Go here for an overview of GPOs.

    --
    Carpe Cerevisi - Seize the Beer
  27. Don't fixate! Read! Read! by BiOFH · · Score: 4, Interesting

    It is making ground in IT courses because Linux is both easy to lock-down, easy to pull apart and offers simple licensing for distribution to students.

    Please stop fixating on the whole locking down bit!
    Timothy craftily negelected to list anything but the potentially inflammatory and sensational 'lock down' phrase. It's EASIER for them to use Linux (and makes more sense and it's CHEAPER), not "they can't lock down Windows". These are newbies who DO know how to fuck up a Window machine pronto. They'll have to do some learning before they can pull a good cock up of their Linux box. And since this is a Uni, students learning is kind of high on their list of 'things we want to happen'.

    And please take note this is not the whole Uni. My girlfriend works there and she (and her whole department) uses Macs. But it is a step, IMHO, in the right direction for UOW.

    --
    - I am made of meat.
  28. Policies work fine by Anonymous Coward · · Score: 0

    Policy editor in NT4/9x and Policies in a Win2k environment lock down systems about as tight as you want. But no one at slashdot has ever read the Windows documentation, or used W2k. "98 crashed once so windows sucks but I can't afford Win2k or XP and it's not l33t enough anyway". Bah.

    1. Re:Policies work fine by mpe · · Score: 2

      Policy editor in NT4/9x and Policies in a Win2k environment lock down systems about as tight as you want. But no one at slashdot has ever read the Windows documentation,

      Probably because getting decent documentation out of Redmond is difficult and expensive.

  29. Re:Early Post by Anonymous Coward · · Score: 0

    trying to be different Haha. You big sappy fag.

  30. Answer by BiOFH · · Score: 2

    Answer: They only click through to look at pictures of Lego, Linux handhelds and case mods. ;)

    --
    - I am made of meat.
  31. Re: Windows Policy Editor - could it be any worse? by Anonymous Coward · · Score: 0

    Let me just state for the record, that you are a complete fucking tool. Really, you know nothing.

    Carry on.

  32. As someone at an Australian university... by CaptainPotato · · Score: 4, Insightful
    ...who wishes to do convince the IT powers that be to do the same, I am very happy to hear about other institutions that are doing the same. Whilst there remains a need for Windows-based machines, Macs, and whatever else is used, there are many compelling reasons for switching to Linux - these are just a few I have (whilst on University time...).

    1. Control. Whilst I would normally shudder at the thought of restricting IT access, I do appreciate UOW's desire to better manage their machines. We recently had some new machines running Win2k installed in my area, and within a day, one was in poor shape thanks to a particular idiot installing the latest Windows Media Player version on it and somehow stuffing up the OSA installation. He was able to so do thanks to the IT stroke of genius of giving everyone admin access. Whilst this may be an human issue rather than an OS one, every bit helps :)

    2. Cost. We are all aware of the studies that compare the cost of Linux to other OSes. In any case, regardless of the outcome, I do know that my insitution will be spending multiple millions per year (as of next year) for desktop software licences for MS products because of the new licence arrangements. In a country that has mounting financial challenges in university funding, alternatives to MS software need to be found.

    3. Ethics. Maybe this is too strong, but IMO it is not. Why should tapayer money be spent on making a single corporation (even) richer? A centre of teaching and research ought to have academic independence of multinational corporations.

    These are just a few, IMO, valid thoughts about the issue. Regardless, UOW deserves to be applauded for the initiative.

    --
    I heard that your library burnt down and destroyed your only two books - and one was not even coloured in yet.
  33. Just be careful by albino+eatpod · · Score: 2, Interesting

    My University's PC lab ran linux (dual boot with Win 2k), but it also ran telnetd which anyone with a computer science login could telnet to. This led to some interesting fork bomb wars between 'friends', and didn't really help us get on with our (probably late) work. Ironically, although Linux is chosen (amongst other things) its security, it was Windows that was the most secure in this case, simply due to poor administration.

    They've actually removed Linux at the moment, as they attempt to change their linux policies.

    1. Re:Just be careful by Anonymous Coward · · Score: 0

      If the admins don't already know about it (you said poor administration): inform them about PAM.

  34. uow labs by Tristessa · · Score: 4, Interesting

    Being at UoW and knowing the people who did this I can't say it's a surprise. The only things that windows were really used for in those labs were software engineering type programs and Word/Excel for the first years and non-compsci people who used the lab.

    There are other compsci labs around that haven't been dual boot for longer than this. The article also doesn't mention anything about the proportion of CompSci(linux) machines compared the number of mac/wintel machines around the uni which I'd estimate at around 85-90%

    At least the compsci department support staff are always trying new things, actually being taking initiative about things. kudos guys. see you for a drink soon.

    1. Re:uow labs by allrong · · Score: 1

      Forget dual boot, when I did a couple of intro C++ courses at UOW in 95/96 we were supposed to write the programs on Macs. Once submitted they were test compiled under Unix. Not have access to either at the time I used to write them in Borland C++ 4.5 running under Windows 3.1 (very, very painful, but it was a low spec machine).

      --
      What is the inverse of the Matrix?
    2. Re:uow labs by Tristessa · · Score: 1

      When I did first year compsci it was on those same macs. Bad news they were. As well as the tutor who kept calling Eudora email ENdora, like it was made by the mother on bewitched.

  35. Re:Early Post by houseofmore · · Score: 1

    "Funny to think that if you had back all the time you spent tweaking and patching... you wouldn't know what to do with the workstation on your desk."

    `rpm -Uvh kernel-2.4.18-3.i686.rpm`

    Ohh. Shiver me timbers!

    I'd sooner that then spend all day fighting worms, dancing paperclips, spyware and secret coded blue messages.

    If only the networking was reliable, we'd get it the office and boot it up a lunch for a multiplayer game.

  36. This will by katalyst · · Score: 2

    either result in mundane Linux users, or HARDCORE linux hackers :D Both of which, I guess, are better than mundane Windoze clickers.
    Unfortunately,unless we have an industry standard office suit to compete with Microsoft Office, lots of companies are going to hold back. Comments,merging and other aspects of Word which make professional and academic documents exchanging and analyzing easier are still missing in Open/Staroffice. The publishing industry: they would love to shift to linux, but the fonts/word processor aren't up to the mark. But Linux will get there -> soon.

    --
    |/________
    |\A|ALYS|
  37. i study at the UOW by Anonymous Coward · · Score: 0

    they've been using linux for years.. no dual boot that i know of.. there has always been linuix labs and windoze labs... maybe they booted windoze out of somewhere that ive never been in there... but as far as i know.. all computer science labs have been for at least 5 years.. only linux...

  38. Locked down? I doubt it. by Anonymous Coward · · Score: 0

    If you have physical access to a machine, it's not going to be locked down for very long. No floppy? Install one. $6

    *Pssst! Hand me that screwdriver.*

  39. duel boot by Joakim+A · · Score: 5, Funny

    >The Uni of New South Wales Computer Science and
    >Engineering department has been running
    >unix/linux for years, no duel boot.

    Well, duel boot, that is something I would like to run. Just install windows and a few linux/BSD dists, turn on the machine and leave it over night. Then we finally could settle this thing.

    /J

    Ps My bet is on that spiky fish eventhough that little red bastard with the fork might be nasty. I mean, how hard can it be to beat a geek from redmond or a penguin? Hmm, could be a whole army of penguins of course, well that might get tricky.

    1. Re:duel boot by NoOneInParticular · · Score: 5, Funny
      I'm not sure about the geek from redmond, but before you belittle penguins, consider these words from Linus Torvalds:

      "Some people have told me they don't think a fat penguin really embodies the grace of Linux. Which just tells me they have never seen a angry penguin charging at them in excess of 100 mph. They'd be a lot more careful about what they say if they had."
    2. Re:duel boot by xchino · · Score: 2

      Haven't you ever seen the Quake logo of Tux with the rocket launcher? I think the BSD's definately got trouble :)

      --
      Everyone is entitled to their own opinion. It's just that yours is stupid.
    3. Re:duel boot by McGarnacle · · Score: 1

      Ps My bet is on that spiky fish eventhough that little red bastard with the fork might be nasty. I mean, how hard can it be to beat a geek from redmond or a penguin? Hmm, could be a whole army of penguins of course, well that might get tricky.

      ITYM: spiky [blow]fish vs cute cartoon devil with fork vs [army of] penguin[s] vs a butterfly vs an apple :)

      --

      I disagree with what you say, but will defend to the death your right to tell such LIES!

  40. Re:IN SOVIET RUSSIA by Anonymous Coward · · Score: 0

    ROTFL!

    Now watch the mods slap anything but "Funny" on that one.

    Thanks, you made my day!

  41. Just a Thought... by Hasie · · Score: 5, Insightful
    I see their point, and I agree that Linux has a place in any computer-related university curriculum as an introduction to UNIX (even ignoring the other advantagess it has), and I am a major Linux fan (to the point that I actually find Windows difficult to use).


    (You all know what comes next:) BUT, I don't think that Windows should be completely eliminated. Windows is still the de-facto standard in industry and universities owe it to their students to give them skills they can use. It is also essential that universities maintain neutrality in the sense that they do not give the impression that they are promoting one system over another - a university's role is to eductate and do research, not dictate what the world will do or follow current fads.


    Before everyone gets the wrong idea; I use the same argument to motivate the use of Linux at the university where I work (it is a very good way to teach students UNIX rather than only teaching them Windows). So what is needed is a balance.

    1. Re:Just a Thought... by vlchung · · Score: 1

      A fair point - we still have Windows-based units here. In Chris' Operating Systems unit (here at the University of Western Australia), the differences between Unix and Windows-based (i.e. NT / Win2K etc) are explored, and the unit project involves writing a piece of software that interacts with the operating system (as opposed to the user-level libraries) for both Windows and Linux.

    2. Re:Just a Thought... by dubious9 · · Score: 2

      How many computer science people do you know didn't already know windows when they got to school? It's not like they are going to stop using windows. If anything just for the gaming.

      What windows skills would they be missing? Visual C++/Basic/C#? I agree with other posters here that you teach skills, not languages.

      Most of what you learn (or what I learned anyway) in a CS program is OS independant. Linked lists, dynamic memory allocation, objected oriented structure, encryption, sorting etc. etc. will work the same on any operating system.

      In a windows based curriculum, however, you have to simulate more advanced things such as network layer protocol, interprocess communication, file systems, schedulers, i.e. anything implemented in the operating system. In an open source based you can actually do it and not have to use some crappy simulation code.

      In conclusion, what do you get from windows? Learing windows API maybe in one class? The advantages of linux outweigh the advantages of windows. Linux's main weakness is its strength here: it take someone who knows computers well to administer it.

      I assume the only thing holding a lot of universities back is retooling for linux. This will take a lot of infrastructure and writing a lot of new educational software (i.e. half complete, fill in the missing fuction stuff)

      --
      Why, o why must the sky fall when I've learned to fly?
  42. Dual-boot? by Z0mb1eman · · Score: 3, Insightful

    >machines in first-year labs that used to boot from either Windows or Linux have been changed to Linux only.

    That sounds like a LOT of hassle for the admins in the first place... University of Toronto has separate Linux Redhat, Win2000 with Netware, and (still a few) Solaris labs. Separate rooms, separate operating systems, just go where you need based on what you need to do. The Windows machines are even more "locked down" than the Linux ones - you can't even change the wallpaper, for example. Can't move/remove icons, can't change the start menu, can't (really) install programs. I've never seen a trashed Windows machine, whereas I've seen Linux machines that have gone belly-up with a rather pissed off admin trying to fix it. Then again, I spend more time in the Linux labs.

    The dual-boot idea for a public lab makes very little sense to me in the first place - if the university's THAT desperate to save money, maybe it's not the best place to go. More likely though, the admins realized the way they were doing things wasn't really the best way, and changed to something more logical and easier to manage (and not all that new or innovative at that) - how does that constitute news??

    --
    ClutterMe.com - easiest site creation on the Net. Just click and type.
    1. Re:Dual-boot? by g4dget · · Score: 2
      whereas I've seen Linux machines that have gone belly-up with a rather pissed off admin trying to fix it. Then again, I spend more time in the Linux labs.

      Linux machines don't just go "belly-up", and certainly not from normal usage.

      In any case, a common way of dealing with this is to not worry too much about students doing stuff as root at all--you just have the machine reboot on logout and restore the default installation with "rsync".

    2. Re:Dual-boot? by Z0mb1eman · · Score: 1

      >Linux machines don't just go "belly-up", and certainly not from normal usage

      I know, that's probably why the admins always look so annoyed :p

      Almost got into trouble once because they thought I was the one who messed up a machine...

      --
      ClutterMe.com - easiest site creation on the Net. Just click and type.
    3. Re:Dual-boot? by OzPixel · · Score: 1

      You say "if the university's THAT desperate to save money, maybe it's not the best place to go." Unfortunately, this is the way all Australian public universities are heading, thanks to mind-numbingly short-sighted government spending cutbacks on higher education. Linux has a lot of potential for these unis, and it wouldn't surprise me if most of them aren't using it already, at least in CS faculties.

      David.

  43. Taco by Anonymous Coward · · Score: 0

    Nuts!

  44. Shoe's on the other foot. by Spit · · Score: 1

    It's quite refreshing to see windows apologists feeling the need for "me too" posts. It wasn't long ago that Linux admins had to "me too" to be considered for projects. More and more free systems are the default, about time.

    --
    POKE 36879,8
  45. just like USyd by djshiawase · · Score: 2, Informative

    The University of Sydney's got a huge unix tradition - not as much as UNSW but i think Aust has always been unix-inclined, out of the 'pressure spotlight' I suppose, or something. The admins love the linux computers here, they never have do anything to them. Especially the Tektronix dumb terminals, they just sit there and accept input. Slow as hell though, I use them only when I need to get an assignment done and there's no computers left. I think they're retiring them over the Christmas break, that whole lab area is being rebuilt.

    The whole backend runs on linux clusters (went to a little after-lecture talk about it). File servers, CPU servers, connection servers. They have a few sun servers but one of them explode every year and they haven't bothered replacing them. Clusters are so much cheaper!

    The last batch of new systems we got at the beginning of last year for 5 labs, P4s with TFTs, bucks this trend though, as 4 of these labs got Win98 and the other Linux. They don't even bother locking these Windows down either, they just wipe and upload drive images from the server every night.

    Though that kind of sucks, means we have to reinstall Warcraft 3 every day.

    --
    they made me do it
  46. Going towards it here... by imevil · · Score: 5, Insightful

    At my school the math section has linux-only PCs for the students. The CS section has Solaris (SUN) and Windows-only machines, and they justified the no-linux by saying that the companies use Windows so no point in teaching Linux to the students. I think they got it all wrong: more and more companies are migrating to Linux, and in a couple of years there will be a need for Linux experts.

    GNUWin: open your Windows!

    1. Re:Going towards it here... by Peyna · · Score: 4, Insightful

      A CS degress means you know how it all works, but you don't have be an expert in any particular langauge, operating system, or application. Instead you should be able to easily adapt to a quickly changing field.

      For all we know, there may be some new radical ideas in the next few years that void the need to be an expert in Linux or Windows. What a horrible waste of time to work at perfecting a restricted set of skills for a proprietary system.

      --
      What?
    2. Re:Going towards it here... by mpe · · Score: 2

      At my school the math section has linux-only PCs for the students. The CS section has Solaris (SUN) and Windows-only machines, and they justified the no-linux by saying that the companies use Windows so no point in teaching Linux to the students.

      Even if "the companies" do have Windows machines they are unlikely to be the same version of Windows or set up in the same way educational networks are set up.

  47. Re: Windows Policy Editor - could it be any worse? by Anonymous Coward · · Score: 0

    Wow you must wear a helmet or something... you are the very first windows admin that I have seen that has locked themselves out of the computer. Even the most elementary admin will not lock them selves out of the computer. WPE is pretty straightforward on whom the policy is being applied to and what it is for. You are obviously a first time user or you are a complete moron.

    No soup for you... come back one year!

  48. Um, windows isn't any harder to lock down... by autopr0n · · Score: 0, Flamebait

    What, were these guys dual-booting into windows98? Or were they just idiots who didn't know Windows NT (and 2000/XP) has a multi-user system that will allow 'locking down' just as much as anything in Linux. Of course, under Linux more things will be secure by default, but any competent sys-admin should be able to make a windows machine 'bored-student-proof'

    --
    autopr0n is like, down and stuff.
    1. Re:Um, windows isn't any harder to lock down... by mpe · · Score: 2

      What, were these guys dual-booting into windows98? Or were they just idiots who didn't know Windows NT (and 2000/XP) has a multi-user system that will allow 'locking down' just as much as anything in Linux.

      In practice it is considerably more difficult to "lock down" Windows if you actually want to run applications on it. Because the vast majority of Windows applications are written with a single user, who can do anything they like, approach.

    2. Re:Um, windows isn't any harder to lock down... by Anonymous Coward · · Score: 1, Informative

      I have not found this to be true at all. We routinely install all the apps a particular user will need, then lock the machine down for that user so they can't destroy anything other than their own home space. Can't change any of the local settings or install programs. And it takes about 5 minutes to do so from a clean install. It would take seconds if a security policy file were setup in advance and "applied" on a new user account, but we are a small company and we tailor each machine to each users needs/experience.

      The real reason was more likely bias, cost, or just plain stupidity.

  49. Re:Some details? by Anonymous Coward · · Score: 0

    How does DeepFreeze stop users deleting DeepFreeze?

  50. Why not use *BSD? by Anonymous Coward · · Score: 0

    You even mentioned it in your list -- BSD sockets. BSD is a much simpler, yet just as efficient UNIX as Linux. It's not bloated with thousands of drivers for esoteric cards, which makes it easier to code surf and learn Operating System writing from.

  51. IN SOVIET RUSSIA by Anonymous Coward · · Score: 0

    Lame Slashdot Posts Campaign Against Alerts

  52. IN FREE CAPITALIST RUSSIA by Anonymous Coward · · Score: 0

    Nobody Campaigns Against Anything!

  53. Re:Early Post by Anonymous Coward · · Score: 1, Funny

    But you do realize, the whole point is that we don't want real friends. They are far too clumsy and random, much like a blaster.

  54. Looking down anything? please help me with.. by fractaltiger · · Score: 2

    I had just made a journal entry about this issue:
    how can i set a quota on solitaire's use on my box? :)

    dad will now have to find a second hobby or some other box. thanks, slashdot!

    --
    "Wireless : LAN :: Laptop : Desktop"
  55. Support by jaavaaguru · · Score: 1, Flamebait

    Surely the schools have bought support contracts, so that when something screws up or they need help, it's just a phone call away. And surely if they have a support contract, they get the latest version of the OS, and I thought WIndows 2000/XP had pretty good security (relative to older versions of Windows)? I mean, you can change all the permissons just like you'd do on a real OS ;-)

    1. Re:Support by greenrd · · Score: 2
      Yeah, you can change the permissions on NT too, but then you run the risk that nothing will work.

      You have to have an admin who really knows what they're doing (unlike those at my school, who made it so that Explorer wouldn't run on login (!?) on the demonstration machines). And even then you still have lots of software that won't run properly except when run as Admin.

      On Red Hat you already have permissions set up for you, and you don't really have to change much. Yes, users can choose their own wallpaper etc. - but what's wrong with that? They should be allowed to do that if it doesn't affect anyone else or cause system instability.

    2. Re:Support by Crockerboy · · Score: 1

      Yes, users can choose their own wallpaper etc. - but what's wrong with that? Exactly, Kids should be allowed to put goatse.cx as their wallpaper on the school computers in the library.

    3. Re:Support by zootread · · Score: 1

      But it'll only be for THEIR account that'll have the wallpaper. If they leave it logged in someone can just put a "+ +" in their .rhosts and go on a hacking spree.

      --
      Zoot!
    4. Re:Support by Anonymous Coward · · Score: 0
      Yeah, you can change the permissions on NT too, but then you run the risk that nothing will work.
      Not if you do things right. Assuming that you have an NDS based network (And yes, NDS is available for NT, and Linux, and Solaris), you can run Novell's ZENWorks and give all the users normal user privledges. If an app truly needs to have administrator privledges, you can give the privldege for the app. Most apps work fine under a normal user account, but want administrative privldeges to install, and ZENWorks handles that just fine.

      This, along with all the other nifty cool features of ZENWorks definatly are a sanity saver, on any network where there are more then 20 Windows computers.

    5. Re:Support by jonadab · · Score: 1

      > Yes, users can choose their own wallpaper etc. - but what's
      > wrong with that?

      Depends, but if you have an account where you don't want anything
      changed (such as a guest account), that's easy too: set it up
      like you want, make a tarball of the user's home directory, and
      set up a cron job that untars it overtop of whatever is there.

      --
      Cut that out, or I will ship you to Norilsk in a box.
    6. Re:Support by ethereal · · Score: 1

      Big deal - what would you do to a kid who brought in Playboy to read in the library? Do that to the goatse.cx kid too. This is not a computer problem, it's a young-and-bored problem.

      --

      Your right to not believe: Americans United for Separation of Church and

  56. trivia -- wollongong famous for first unix port by Anonymous Coward · · Score: 0


    FWIW, Wollongong Uni was the site of the first
    port of Unix -- from DEC PDP to PerkinElmer.

  57. Yay. by Anonymous Coward · · Score: 0

    At my first college (An evil college(tm)), we had Solaris boxxen, Digital Unix boxxen, Win 2k boxxen, and Mac boxxen.

    They made me use Macs for some of my classes. :( Thankfully, the bulk of my classes were in the Solaris/Unix labs.

    At any rate, I was originally a CS major. Now, I mean no offense to those I took classes with, but the majority of them were about as dumb as a rock when it came to computers. I mean, really, these are people who couldn't tell their asses from a for loop.

    You know something, though? These people had little problems adapting to new operating systems. Oh, it took them a few days to get used to things, but before long, I wasn't the only one in my classes who knew how to use Emacs. (Yes! We used Emacs, too! Bwahahaha!) My fellows were directory diving with great ease from a command line, and it was a bloody great sight to see. It made me kind of proud that I was attending a university that taught something other than pointing and clicking.

    Back then, the GUIs availible for Linux sucked arse. Well, somewhat - you had Enlightenment, which required an uber box, but made Mac users sob with pity over their ugly OS, or you had Windows 3.11 clones. But then, the GUIs we used on Solaris and the Digital Unix boxxen were pretty lackluster, too. I'm willing to bet my fellows would've had little problem adjusting to Linux then.

    Nowadays, well, I finally bit the bullet and installed KDE. Sure, I swore an oath in CowboyNeal's name that I never would - it was bloated without the prettiness of Enlightenment!

    I got tired of my apps being all different colors and looking generally ugly. Sue me. :p

    Right, well, one of my friends sat down at my pretty spartan KDE desktop. (mmm, arts, libs, base, network. No icons everywhere. ;)) I must point out, this wass not a computer-intuitive friend, this is a guy who swears by Windows XP. He installed Kazaa, and doesn't have a clue what spyware is. He believed me when I told him he should empty his bit bucket and swab his ram regularly.

    He had no problems finding his way around. He even went a little nuts over the fact that the panel can fold in and out.

    If people like that can interact with Linux, I see no reason why people in higher education can't. Linux is now damned easy to use, and it'd save a pretty penny in licensing for various Unix-like operating systems.

    Think of what colleges could do with that money. They could lower tuition, or put coffee machines that don't spew colored water in buildings other than the computer science building!

  58. Equally Effective by rinkjustice · · Score: 1

    The way I used to "lock down" Windows so no prying hands could mess it up, would be to open a DOS box and type:

    ren win bill

    which would of course rename the win system file to the name bill, or whatever you wanted. Worked quite well, even in a dual-boot environment, and unwanted users trying to load Windows would get a dire messege about how the win.ini file was missing ;)

  59. You are some kind of moron by bwoodring · · Score: 1

    I've been running Windows NT operating systems for a several years and messing around with policy editing since Win2K, I have never locked myself out of anything accidentally and I am not even a professional sysadmin.

    Perhaps you should look for a new line of work that involves using a much simpler computer that you can wrap your brain around such as a cash register at Burger King.

  60. Linux in Universities? No way... by TheDanish · · Score: 1

    Universities adopting Linux is not news. UCR, where I go, is generally Linux-oriented, but has Win2k boxen situated wherever it's appropriate -- like the library, or the labs below the dorms -- with full restrictions (nothing except IE can be run, and you can't run Internet Options). Either way, dual booting would just be a hassle, I would think. It's far from strapped for cash, and even if it was, Microsoft would be there to the rescue in a heartbeat. It appears that Linux is often a more appropriate choice for some things they do. No, I don't know the specifics or rationale, I just know that a good portion of UCR's labs run Linux. Others have Windows and a good portion of offices have Macs. I have a PC, and soon I want to buy another so I don't have to dual boot (and it's just more convenient). So, yeah, past intro CS, I NEED to write most stuff under Linux -- if the makefile doesn't work on my projects, that's 50% off my grade, usually.

    Oh, please excuse my grammar and spelling, I'm just getting ready to go to sleep.

    --
    Danish != nationality
  61. Re:IN SOVIET RUSSIA by Anonymous Coward · · Score: 0

    duh... mods, rate this one redundant, it's old news. ;)

  62. Re:People read the article! Especially by Anonymous Coward · · Score: 0

    The emphasis on education over training. How many people actually realise that many computer science degrees are just a couple steps away from becoming simply a Microsoft CS degree?

  63. My school just started swithcing to Xandros by Anonymous Coward · · Score: 0
    We are a high school in Southeastern Michigan. Have had problems with Windows licensing for years (oh yeah and the flakiness ;) ). Just converted over most of the computers in our lab to a friendlier alternative.

    It's been a huge blessing. I spend a lot less time having to fix computers while a class is going on and the kids actually seem to be getting a lot more out of the system.

    We tinkered with a few different distros, but even I was annoyed with the problems of some of the others like Red Hat and Lindows, just not really useable for us. I'm having some learning issues with the Debian side of Xandros, but seeing the benefits I don't mind.

    I highly recommend a quick pilot before you convert people even if only for a couple weeks.

  64. The important thing by SLOGEN · · Score: 2, Insightful

    The important thing, is to not provide Free (as in beer) training to one OS vendor, radically unbalancing the competition in the OS market.

    The danish goverment spend millions of dollars each year on "teaching the people to use IT", which basically boils down to giving users a training course on all M$-OS and Office products.

    I suggest having a mix of OS'es, so that the students have different experiences and learn from comparing those.

    I myself is a student at DAIMI where machines with SunOS, HPUX (well not that many anymore) IRIX, GNU/Linux and Windows (Using vmware), and yes it's a pain with the differences between computers but:

    1. You can just select to use the same OS every time
    2. You learn a lot by seeing different solutions to the same problem

    --
    SLOGEN [ http://ungdomshus.nu : Sebastian cover music]
  65. Re:Don't fixate! Read! Read! Lynx by Anonymous Coward · · Score: 0

    And yes I know what year it is.

  66. As a UOW Graduate - I think its a good thing by Onetus · · Score: 1

    YMMV - But My Milage Was Done At UOW.
    While I may be out of date (Finished UOW in '93) ... I can say UOW has had a tradition of doing things to make sure computer usage has been good for all students. It was the first Australia University to make it mandatory that all graduating students were computer literate, so they've had experience in dealing with users of differing levels of experience.

    Basically, this is great. Considering how adept and "destructive" students can be, it's good that they can standardise and protect the computers for all users. Nothing was worse than trying to do your comp sci projects and having some idiot stuff the system up in the lab before you.

    Mind you, i've the sneaking suspicion it's being done so that the comp sci students use their alloted labs, rather than hunting down other under-used computer labs and working in there.

  67. Fools. Here's proof. by BiOFH · · Score: 2

    Tell your CS people they're living in a dream world. Linux has made great leaps and bounds inside corporate IT. If they only want their graduates working for small-time ISPs then carry on. It's nice to see they have Solaris, but that's probably only because of their mis-guided (and out-dated) view that Solaris==The Web.

    I just left Intel where my department (an IT group) supported _thousands upon thousands_ of Linux boxes both in the server room and on the desktop.
    Take a look at the length of this server room:
    http://www.anandtech.com/showdoc.html?i=158 4&p =10
    A good 3/4 is filled with machines running Linux.

    It's sad when consumer mentality leaks into the professional level. But that's what happens with America's backwards management ideas (if something makes sense and works, it probably needs more managers and those managers don't necessarily need to understand the 'product'...). Anyway... good luck to your school's CS curriculum. They need it.

    --
    - I am made of meat.
  68. What's your point? by Anonymous Coward · · Score: 0

    What is your point and what's it got to do with Lynx?

  69. it's a solution--just not a good one by g4dget · · Score: 2
    Group Policy kicks ass. [...] The point is, Linux has nothing to compare with this.

    Sure it does. By default, regular Linux users can perform no system management functions. You give them access to system management functions through setuid and setgid programs. You can control access to those on a per-user or per-group basis using standard UNIX protection mechanisms.

    If you like something more general, you can use the "sudo" program, which allows detailed policies to be specified of who can do what as who and when, and it also logs the actions.

    The FACT is no one has a better way to administrate and trouble-shoot end-user desktops than Microsoft right now.

    As usual, Microsoft has an in-your-face solution that screams at you "I let you edit policies; here is a point-and-click interface--isn't it easy?". Trouble is, in real life, the options it gives you are rarely the options that are needed, and extending and managing those policies is a chore.

    The UNIX/Linux solution is simple, elegant, powerful, and has proven itself for more than 20 years in large, multi-user environments.

    So, the "FACT" is, "Windows Policy Editor" is indeed like a lot of Windows: flashy but not all that useful in practice.

    1. Re:it's a solution--just not a good one by siliconjunkie02 · · Score: 1
      FWIW, you can do all the things you mention with Windows.

      You give them access to system management functions through local and global group memberships. And it can apply to more than one machine!

      You can control access to those on a per-user or per-group basis using standard WINDOWS protection mechanisms.

      If you like something more general, you can use the "run as" function

      By default, regular Windows users can perform no system management functions

      Amazing! It's still true! Before you go bashing something, please be informed about it.
    2. Re:it's a solution--just not a good one by g4dget · · Score: 2
      FWIW, you can do all the things you mention with Windows. [...] Before you go bashing something, please be informed about it.

      Before you go criticizing something, perhaps read it more carefully: nowhere did I claim that you couldn't also use equivalent set-user-id mechanism under Windows; they just happen to be rather cumbersome to deploy and manage compared to the UNIX approach.

      You see, the value of the original UNIX design is in its minimalism: it makes it easy to use a small set of necessary and sufficient mechanisms. The UNIX designers were as busy removing features from the OS as they were adding new features.

      The Windows philosophy is to give you features and more features and more options, and to wrap that up in GUIs. Sorry, but more isn't better, it's usually worse.

    3. Re:it's a solution--just not a good one by siliconjunkie02 · · Score: 1

      The ability to manage all my users and their workstations as well as any future workstations in one central place as opposed to per machine is a HUGE advantage in my book. It may not be as minimalistic, but it is very powerful. I can be certain that every machine within my domain has the latest patches or new applications without even thinking about it. It joins the domain and it gets them. In terms of managing end users this is wonderful. Just set it and go. But, this is just my .02 on it and for you it may not work. Thats what makes the world go round.

    4. Re:it's a solution--just not a good one by g4dget · · Score: 3, Interesting
      as opposed to per machine is a HUGE advantage in my book

      You must be talking about what Windows used to be like a couple of years ago, since networks of UNIX workstations have never been managed like that. Come on, people have run UNIX networks with thousands of machines since the 1980's. Do you think they didn't figure out how to deal with those issues long ago?

      There are several common ways of setting up such networks, and they are generally much simpler to deal with than anything Microsoft offers even today. Adding a new machine to a UNIX network requires no more than just plugging it into the network and possibly adding it to a list of recognized clients. Users, data, and applications are installed centrally. Applications run transparently over the network, or locally, whichever way you prefer. "The latest patches" or "new applications" aren't even issues--things are just automatically consistent.

      Windows has taken some of those ideas and thrown them together into an inconsistent and cumbersome juble. But where networks of UNIX workstations just tick along by themselves, Windows-based networks require constant handholding, fixing, patching, and reinstalling. Microsoft is trying to paper over how messy and dysfunctional their system is with lots of dialog boxes and GUIs, but it just doesn't help: in the end, managing Windows networks is still a lot more work. Oh, of course, you can try and buy lots of expensive third party software to get some of the UNIX-like manageability, but that only makes things even more expensive and complicated.

      I used to manage networks of UNIX workstations with dozens of users on the side. If I had to spend more than an hour or two on it per week, that was the rare exception (and then it was usually due to some hardware failure on the server). And I certainly didn't need any expensive or complicated third party software for doing it either.

  70. that's damning with faint praise by Anonymous Coward · · Score: 0

    I guess...

  71. at length == ~40 hours? by mangu · · Score: 2
    I have used Linux since 1995, let say a few thousand hours total. I have used different versions of MS-windows since 1990. THAT is "at length".


    On the administration issue, that "group policy" you mention and most other resources you find for managing windows machines depend on the GUI. You must sit at the machine in question and click the right boxes in the right windows. Try to do this on a few dozens, a few hundreds, a few thousands of machines without a mistake, without forgetting any step.

    1. Re:at length == ~40 hours? by siliconjunkie02 · · Score: 1

      Hmmmmm, maybe you should read more about applying GPO's to OU's. You can easily do thousands of machines/users at once.

    2. Re:at length == ~40 hours? by mangu · · Score: 2
      maybe you should read more about applying GPO's to OU's.


      Why should I? If it works in Linux, if it has worked for decades in Unix and VMS, why should I read more about some crappy system with huge binary configuration files?


      The kind of configuration my company demands must be simple and reliable. It uses small text files, which can be printed on paper and filed away. The files must be small because one must be able to check them personally. They must be on paper because, when all else fails, when there are suspicions of intrusion, one must have a hard copy which one is absolutely sure is the trusted version.

    3. Re:at length == ~40 hours? by siliconjunkie02 · · Score: 1

      You should because you are making judgements on it based on either false or misinformation. Your system may be exactly what you need, but that doesn't make your incorrect statement about how GP works more correct. And, you can save all that GP info in an inf file and even print it if you like.

    4. Re:at length == ~40 hours? by Anonymous Coward · · Score: 0

      Let's see. You say it is too complicated and cumbersome to administer policies on multiple Windows clients, but when someone points out how you're wrong, you just say you don't care and go off on a different tangent.

      Way to change the argument to suit you, dickcheese. If you can't admit you're wrong, you should learn to STFU.

      To add the original response, you can also use the Group Policy editor to export the settings to a text file, and it is pretty simple and reliable.

    5. Re:at length == ~40 hours? by Anonymous Coward · · Score: 0

      Ya, it seems to me that half the linux people on /. are just too stupid to run windows. I understand the faults it has but I also understand that linux has its own issues.

      The plain fact is that windows is used more. It's used more because when you know what the hell you are doing, it's quite powerful AND simple.

    6. Re:at length == ~40 hours? by mangu · · Score: 2
      someone points out how you're wrong,


      How so? Who pointed out I was wrong? All he said was that I should read more about windoze system adnministration. What this proved is that it's MORE difficult to manage windows, since it takes a lot of study to learn how to do it not-so-badly.


      you can also use the Group Policy editor to export the settings to a text file, and it is pretty simple and reliable.


      No, it's not reliable. The registry is still a huge binary file, no matter how many .inf files you have. Crash that registry, your system config is lost. In Linux I can delete all my system directories; all it takes to recover is to put in the CD, copy the system directories and copy the back-up /etc directory. A couple of minutes at most.

  72. that's easy to deal with by g4dget · · Score: 2
    That's easy to deal with: either you adopt the Windows model and disallow remote logins for users different from the console user, or you set reasonable limits on the number of processes and amount of memory per user.

    Keep in mind that Linux, out of the box, is configured for single-user desktop use. You do have to do a little bit of configuration for a multi-user environment.

  73. Perhaps by Sven182 · · Score: 1

    But being realistic, nobody uses Windows to do much at all. I probably would have done around 6 hours of Windows coding throughout my 4 year degree at UWA, and a lot of that was in VB (not a real language) for Graphics (not a real unit). Even in Chris' OS unit I don't remember doing much at all in Windows. Now that I think about it, I wouldn't have done more than 6 hours of Windows coding in my entire life.

    --
    harshbutfair: you know it makes sense
    www.harshbutfair.org
    1. Re:Perhaps by jez9999 · · Score: 1

      I probably would have done around 6 hours of Windows coding throughout my 4 year degree at UWA, and a lot of that was in VB (not a real language) for Graphics (not a real unit).

      Whereas for the most part you used Linux (not a real OS) on your 486 (not a real CPU). :-)

  74. lol by SHEENmaster · · Score: 1

    If hacking the network wasn't possible, I wouldn't have had my recent three day vacation :)

    It is pathetically simple to reset the BIOS, boot to floppy, replace autoexec.bat and config.sys with clean copies, and reboot to a normal winshit environment.

    As for the school's network, they use SMB PrintSharing; with NO passwords for any of the printers so ANY MORON can print to the principal's printer!

    Maybe these "Sheriff Cards" would help aleviate the boredome; then again, maybe that is too much to ask.

    --
    You can't judge a book by the way it wears its hair.
    1. Re:lol by Anonymous Coward · · Score: 0

      Maybe instead of vandalizing school computers you should try learning something once in awhile. Your kind are the cyber equivalent of street niggers. You probably use script kiddie exploits to hack into IIS webservers and think you are cool too right?

    2. Re:lol by chthon · · Score: 1

      In some schools the BIOS is also locked down. If someone wants to reset the BIOS, he has to open up the case.

    3. Re:lol by 0x0d0a · · Score: 2

      Back when I was in HS, the school bought some (disgustingly pricy) IBM boxes running Surepath that didn't have a hardware password reset (or at least IBM claimed that you couldn't).

  75. Sorry to ask, but ... by Anonymous Coward · · Score: 0

    ... what's a 'Wollongong'?

  76. Also at Auckland Uni in New Zealand by nzAnon · · Score: 2, Interesting

    Auckland Uni is expressin the dis-satisfcatin with Microsoft licenscing policy by moving to Sun Microsystems' Star Office.
    Read here: http://www.nzherald.co.nz/storydisplay.cfm?storyID =3047439&thesection=technology&thesubsection=gener al

  77. Re:I knew it! by mehfu · · Score: 1

    Funny!
    Mod accordingly!

  78. This is significant news by heffrey · · Score: 3, Insightful

    If the prestigious and world famous Department of Informatics at Wollongong University have taken this decision then I'm pretty sure the rest of the world will follow suit in short order.

    This story is typical Slashdot. Small university department moves to Linux (= big story); Multinational Company switches from Sun to Microsoft (=no news).

    Small earthquake in Chile, not many dead.

    Yawn.

  79. Maybe it's easier to lock down... by Kjella · · Score: 2

    ...but I know from experience that a windows box can be equally hard, and that was an all-software solution. I couldn't get *any* non-approved program running at all, even those that need no dlls or registry settings. I've always been able to get around it somehow before (find a temp dir where I have write permission or something) but no. Not at all. Even when I got my own laptop I had to struggle bad with the universitys firewall most ports both in and out, but I did manage to get past that at least. But noone tell me a windows box *has* to be easy.

    Kjella

    --
    Live today, because you never know what tomorrow brings
  80. In other news, the University of Queensland... by little_fluffy_clouds · · Score: 3, Interesting

    ... dumped all of their UNIX machines in computer science and bought new Windows labs about 3 years ago. I know, because I was there starting the undergrad. As of March, they claimed the course was not going to change at all - by November they had dropped such "obselete" subjects like Algorithms and Data Structures and picked up crap to do with web applications nobody will even remember in 2 years (it's been three and I have no clue). I was disgusted by their sellout, and moved to another, UNIX oriented University (University of New England), where each undergrad (I was external) is *required* to install Linux or another UNIX/UNIX like OS in first year, and all assignments from the very first are submitted on a Linux machine, where they must compile properly (I develop on NetBSD, but never had any issues at that level compiling and submitting on the Linux machine).

    Fuck UQ and their sellout for the almighty buck. If that is not what is was, I apologise, but it sure looked just like that from where I was at the time. I feel for the academics caught in the middle of it all.

    --
    What were the skies like when you were young?
    1. Re:In other news, the University of Queensland... by Anonymous Coward · · Score: 1, Informative

      To my knowledge, COMP2501 (Algorithms and Data Structures) is still running.

  81. custom php programming and web development scripts by chrisranjana.com · · Score: 1

    Linux is the best .
    Once you get used to it no o/s even comes near

    --
    Chris ,
    Php Programmers.
  82. Re: The unimportant thing by Anonymous Coward · · Score: 0

    3. ????
    4 PROFIT!!!!

  83. What a Joke by ink · · Score: 2
    Dont give the execute permissions on any folder they have write access too. Simple as that, No more running things from their desktops. Just lock the thing down tight, dont let the execute anything anywhere and try to do whatever it is they need to. Then open it up as needed. With GP you can disable Active X and all that in pages, so no more worries about that.

    So this is what passes for Windows security then?

    A secure UNIX system will allow the user to run ANY binary. Period. They may not have permission to write to some file in /etc, or they may not be able to install shared libraries in the system path... but I can't think of a bigger waste of time than having a default-deny policy on executables and then punching holes in it so that only "safe" programs are allowed to run. What happens after an upgrade? Do you have to do it all over again? What happens when users need a security patch? You have to re-mirror the box? Operating systems have built-in security mechanisms so that these things shouldn't need to be done. That the tools to do them exist under Windows, that they even ship with them and that they are the reccomended manner to secure them is just... laughable.

    --
    The wheel is turning, but the hamster is dead.
    1. Re:What a Joke by SectoidRandom · · Score: 2

      Not that im very keen to stand and defend Windows but you mention "A secure UNIX system" like it's an every day thing. But the fact is local-root exploits even effect OS's like OpenBSD! Sure *ideally* well administered and upto-date systems will be safe from 99.99% of people, but if you think that *any* system can be completly protected from a user with local access then I think that is what is laughable!

      The fact that you can lock down exe's in Windows from my experience was only useful (and necessary) in Windows 9x as since NT4 any good administrator could secure the box for all but that 0.01%.

  84. policy lockout by Erpo · · Score: 2

    firstly - the policies affect ALL users, INCLUDING the administrator.

    I have some experience adminstrating a win2k active directory domain so I can offer some advice in that area: policies only affect all users by default -- you can change this behavior. When you create the new policy, click the "edit" button (I think its this one. If not, it's the other button with a similarly suggestive name.) and you can edit the policy ACLs by hand. See that little check box marked apply in the "Authenticated Users" entry? Uncheck it. If you do this _before_ hitting apply you'll be fine every time.

  85. Oh, that's EASY by ink · · Score: 2
    You just need the Active Solitaire Group Policy Administrator t001 that ships with Windows 2000 SUPER Advanced Server. Microsoft has forseen your need for this problem and provided a complete API for Visual Studio dotInfo which allows IT profeshunals to not only control how many times Solitaire is run by individual users, but it supplies an ACL which allows the per-user limits to change based on how many times others have utilized this program. This means that your boss coule be allowed to play Solitaire only when your vacation requests have been properly filled out (see obscure documentation for the Active LookOut Vacation API Plugin -- and be sure to download the 27 hotfixes we have for this tool that runs with SYSTEM privileges).

    Yes, you can now use the Solitaire Administrata MMC Plugin from any other properly-licenced member of the 2000 SUPER Advanced Server domain (as long as it's using the latest version of Windows, anyway) to manage your company's ability to waste time all day. We plan to rollout future versions of this IT management tool for other titles such as Freecell and Pinball. Look for updates on MSDN.

    Microsoft. We not only make computing EASY, but we make it BLODDY STUPID to boot, by fixing the symptoms of problems INSTEAD of the root cause.

    --
    The wheel is turning, but the hamster is dead.
  86. Lock it down! by Anonymous Coward · · Score: 1, Insightful
    This locking down the system thing is probably the best single example of a feature of Linux that the OSS/FS crowd failed to use to sell Linux to the mainstream. Tell the average head of a household that he or she can set up a system so that no one in the house (read: kids) can munge up the OS, and his or her eyes will light up. Yet mainstreamers think that Linux is just like Win9X in this area.

    Now that the mainstream is moving to XP, which is NT based and has strong multi-ID support, this advantage is quickly evaporating. Just another potential advantage frittered away, thanks to the typical Linuxite myopia...

  87. Did this in 95 by KjetilK · · Score: 2
    Well, actually, I was the student's representative in the computing committee of the physics department of my university. I realized quite early that Linux was a lot better than Windows for most things physics students would want to use it for. Before I got into the committee, the committee held the opinion that Windows was what the students was familiar with, so they would want to use that. First, I persuaded them to start using dual-boot, but eventually we realized that becuase of the sheer time it takes to reboot, most machines would never be rebooted, people would use the OS there was. And for most of the time, that was Linux. So, I argued that it was better to have a small number of Windows-only boxes, and a bigger number of Linux-only boxes. Eventually, people would stop using the Windows boxes, so when I quit the committee, there were only Linux boxes there.

    Nowadays, they have a bigger room that is shared with students from other parts of the campus, so the number of windows machines have gone up. But the physics students stick to Linux.

    --
    Employee of Inrupt, Project Release Manager and Community Manager for Solid
  88. Speaking of Idiots... by ink · · Score: 2
    The context was "locked-down box". If I walk up to your secured linux system with a statically linked, suid copy of Vi on a floppy and you "misconfigured" your fstab such that I could mount and run it, that's the same problem.

    You make my point. A "locked-down" UNIX box wouldn't care if you managed to get a statically linked copy of vi on your system. You could get it over the network, too, so I suppose a "locked down" Windows machine disables the network device?

    Please don't be an idiot. Thank you.

    Eh, yes... good advice in heaps, I see.

    --
    The wheel is turning, but the hamster is dead.
    1. Re:Speaking of Idiots... by JKR · · Score: 2
      ...statically linked, suid copy of Vi...

      A "locked-down" UNIX box wouldn't care if you managed to get a statically linked copy of vi on your system

      Did you READ the word "suid" in that sentence? If I have a user account and can get or copy a suid binary somewhere I can write/copy over it (i.e. my home directory, /tmp...), your box is toast because I can make any program I like run as root...

      Jon.

    2. Re:Speaking of Idiots... by ink · · Score: 2

      Try it out. Once a user mounts a removable device, all the files are owned by that user; in your example vi would be suid to yourself.

      --
      The wheel is turning, but the hamster is dead.
    3. Re:Speaking of Idiots... by RealUlli · · Score: 1
      Did you READ the word "suid" in that sentence? If I have a user account and can get or copy a suid binary somewhere I can write/copy over it (i.e. my home directory, /tmp...), your box is toast because I can make any program I like run as root...

      No, you can't. You can make that executable SUID to *your* UID, but not root unless you are already root, but then where's the point? ;-)

      A SUID executable on a floppy probably wouldn't work, because if the floppy is user-mountable, all files on it belong to said user, so again suid to *you*. (I admit, I didn't try it with a floppy with an ext2 or minix FS, but AFAIR when the device is user-mountable, "exec,nosuid" is the default...)

      Regards, Ulli

      --
      Simple things should be simple, complex things should be possible.
  89. dual-boot... ugh by Darmox · · Score: 2, Interesting

    The university that I work at(CS dept.) has every now and then talked about going to dual boot machines in the lab. I just can't think of anything worse. We actually had some dual-boot machines in TA offices, did not work well for the most part, because any support we had to do on them(patches and such) all had to be done right there.

    Plus, if they're machines that someone in the dept. can just reboot like that, you really can't enjoy the idea of allowing remote access at all to them.

    Every now and then someone thinks this is a brilliant idea for the lab, and I have to come back and explain that there is *no reasonable way* to keep a beast like that up to date.

    Okay, done ranting

    --
    If I was that drunk, I would have remembered it -- H. Simpson
  90. Re: Windows Policy Editor - could it be any worse? by wobblie · · Score: 1

    Policies are nothing more than a tacit admission that windows is a poor design. 99.9% of what it does is solved in *nix simply by having an intelligent filesystem layout.

    Add to the mix that you are continually running into walls with windows unless you are running a domain, or otherwise spend a boatload of money on something you shouldn't really need.

    Lock down a linux machine? Bah, they're already that way; all I need do is add users. When unix users talk about "locking down" the system, they're talking "refinement", not "square one" - putting them about a week ahead of the windows admins who are still piddling with policy editors and saving up for more CALs for Active Directory.

  91. Hello by No+More+Soviets · · Score: 0

    I am a "Soviet Russia" troll blacklist. Please subscribe to me.

  92. IE & AR Links by cnmill · · Score: 1

    Funny, the icons for the links to the course catalog for international students are the MSIE & Adobe icons. Ironic for an intitution that is moving away from windows. Perhaps they sub out their web work to frontpage-based web developers to save money.

    --
    How sleepless is the egg, knowing that which throws the stone forsees the bone.
  93. As a former lab tech... Re:Hehehehe... by Eneff · · Score: 5, Interesting

    I worked as a tech at a local high school for a year.

    I can tell you that the lab tech who obsesses over Quake is going to lose. You've got 0 budget and the products to secure the network are chosen by unqualified people who got the job of head of IT in the district because in 1985 they were teaching second grade and happened to tinker with an Apple II at home...

    The smart ones just secure against the stupid people and look for the smarter ones and bargain with them that you'll let them play quake if they keep out of the pr0n and viruses, and they kind of keep their eye out for stupid people trying to ruin it all for them.

    BTW, Rarely are the colleges any better. They have better heads of departments, but their main workers are CS students without the motivation to find a higher paying job in industry. (I generalize, of course, but I haven't seen many exceptions.)
    _____

    (OBTopic: nice win for Linux. I always thought that Linux might make a superior corporate solution for precisely these reasons. In a non-development environment, only a system administrator should be able to install an applicaition, for example.

    However, I know that Apple tried to play both sides of the fence as well, and they never had much success breaking into the desktop side of Multinationalica.)

    1. Re:As a former lab tech... Re:Hehehehe... by Sj0 · · Score: 2

      We've got slightly different circumstances, I think. I too worked in a high school IT dept. for a year, but here's what I found; First off, it wasn't a high school IT dept. The three techs, including myself, were the admins for over 10 schools, with several large high schools with multiple labs. The techs in that lab were good at what they did -- if they weren't, they wouldn't be working in such a demanding job. They work 12 months a year(compare to maybe 10 months tops for teachers) at full-tilt, and when something went down, it needed to be up -- NOW. We're talking about dozens of servers, WAN connections into, out of, and within this area whose bandwidth was good enough to run video conferencing over while still allowing(already large amounts of) regular traffic to run, thousands of workstations... Needless to say, it wasn't exactly a walk in the part ensuring that both the school administrators(ie. principals and secrataries, not computer Administrators) and the thousands of students all were running fine.

      One year, they tried to lock everything down tighter than a drum. It all worked, but the security came at a huge cost in terms of flexibility and ease of use, so we were forced to take a different approach. This year, we've placed draconian terms of use onto the students (from the 'legislative' side, not the technical side) so they can't go installing kazaa and banzai buddy on their machines. I was against it when I was a student, but on the other side, it's obvious that the single greatest problem with most of the machines that came in was the fact that they were so crap-laden that nobody could use them, so we're forced to ensure that we could punish people who abused our network. During our summer software rollout, we took special steps to remove all students software from the machines.

      By the way, you haven't lived until you've tried to roll out over 10 schools in one month(the other month was dedicated to infastructure, inventory, and server stuff). Especially when A)you have to rewrite the installer because the IEAK installer is so flaky, B)you have to patch every computer in the board because of a bug in IE6 with the IEAK(those who know which one will grimmace with me), C)The Wan connections are going up and down like yoyos because of work being done to them, and D)some of the software on the list needs to be tricked into running as a regular user.

      --
      It's been a long time.
    2. Re:As a former lab tech... Re:Hehehehe... by kraksmoka · · Score: 2

      note, i spoke of college admins. the school district folks ive met usually have it rough, like u do. i have the utmost respect for those types of challenges. uniTards on the other hand dont know the difference between their a$$hole and their earholes.

      --
      "You never want a serious crisis to go to waste." - Rahm Emanuel
  94. Spiky fish? by kzadot · · Score: 1

    What OS is the spiky fish?

    1. Re:Spiky fish? by glitchvern · · Score: 1

      OpenBSD's mascot is the blowfish. Blowfish is the name of one of the ciphers for ssh and I think the password system. The OpenBSD team wrote that cipher, and at some point someone drew a picture of a blowfish for it. Because the daemon was so strongly associated with FreeBSD, and Theo liked the blowfish so much, it became the mascot for OpenBSD. You can see their various posters, t-shirts, and cd covers featuring blowfish here.

  95. As a UoW student... by gkbarr · · Score: 1
    I have fond memories of my ECTE 196 course that I just completed in the UoW labs. Tri-boot machines are actually what they had - Win2k, WinME, and Linux with KDE. Yeah, some of the machines had issues but I can't imagine it was really THAT much of a problem. Who cares really, this isn't exactly /.'s headline du jour.

    --G Barr

    --
    Sapere Aude - Homer
  96. that's far far ahead by TomK32 · · Score: 0

    of the university of Rosenheim (Germany) I'm studying at. They even don't have dual-boot on their machines :-(
    I really have to speak with the staff about some dualboot (at least that would be a beginning).

    --
    -- just a geek - trying to change the world
  97. Why couldn't they lock down Win boxen? by Anonymous Coward · · Score: 0

    Any Windows admin worth his spit can easily lockdown the boxen using appropriate rights and policies on the users. There is no reason they couldn't have limited the users to what they could do in Windows.

    I think about the only "lock down" they get from gnu/lunix is through the obscurity that no one KNOWS how to tamper with it in first year...

    mod me down

  98. Ob. Simpson's (mis)Quote by Mignon · · Score: 2

    Warning: disparaging the dual-boot is a bootable offense.

  99. What distro did they choose? by Anonymous Coward · · Score: 0

    Would like to know.

    Thanks!

  100. because windows is inferior! by noisyb · · Score: 0

    doing that with windows is like "driving car with a bicycle"..

  101. University of Warwick by Shade,+The · · Score: 2

    The University of Warwick here in England runs mainly Windows NT, with some Unix workareas dotted about, but the Computer Science building runs only Linux (Redhat) and Solaris. There's quite a lot of work done in the Computer Science course here that needs a fairly good working knowledge of Linux. Which is a pretty good thing, IMHO :)

  102. Re: Windows Policy Editor - could it be any worse? by Anonymous Coward · · Score: 0
    "lock out all registry tools, disable "command prompt" and run on the start menu - and you're screwed - no more windows administration. time to reformat the box. "

    You have not spent enough time working on hideously locked down machines.

    All you have to do is create a file regenable.reg with the following text:

    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Cu rrentVersion\Policies\System]
    "DisableRegistryTools"=dword:00000000

    Run it and you have regedit.exe back again and thus you can undo everything else.

  103. Maybe... by Anonymous Coward · · Score: 0

    If the article is as boring as you say it is, then I'm glad this got threadjacked.

  104. Wollongong? by Anonymous Coward · · Score: 0


    Wollongong?

    That's easy for you to say.

  105. The box... by Anonymous Coward · · Score: 0

    which was locked in my high school.

  106. Re:Slashdot Social Experiment - flawed by Chilli · · Score: 1
    People have been saying for years that Slashdotters don't read the article, so I thought that I'd test the theory.
    You are jumping to conclusions to quickly. I actually did read the article before looking at the comments (or even posting one). Nevertheless, when reading the article, I focused on what you call the "insignificant" bits of the article. After all, the summary on the /. frontpage is what made me read the article, in the first place.

    So, if you can conclude anything from your experiment, it is that people concentrate on their first impression. Not really a new insight.

    Chilli

    --
    -=- Just a random lambda hacker
  107. Re:UNSW (Computer Science and Engineering) by Chilli · · Score: 1
    Now they have (or are) moving to Intel Linux.
    All our student computer labs, except two, are running a customised version of Debian GNU/Linux. One exception is a Windows lab used for a course that depends on some Windows software. The second non-Linux lab is a Mac-based HCI lab. Overall, there are 20 Linux labs; see this overview for details. In addition, almost all of our servers run on GNU/Linux.

    CSE.UNSW has a long Unix tradition, part of which has been publicised by the Salon article about John Lions.

    Chilli

    --
    -=- Just a random lambda hacker
  108. Finally some positive press about UOW by bcg · · Score: 1
    Given all the bad press about soft marking for paying students and shafting the academic that reported it, hearing some positive things about uow.edu.au makes me feel a bit better about the computer science degree I have from there.


    On another note, Wollongong uni circa 1994 had two labs - well they were actually two portable demountable buildings, one on top of the other, called earthlab and skylab. Skylab was a whole heap of floppy only Mac SE machines (I'm not kidding) for the first years. And Earthlab contained a whole bunch of Solaris terminals. So I think it is fair to say that UOW has always looked for the cheapest solution for first year students...

  109. Links in articles by saunder3 · · Score: 1

    I am a new slashdot user. I might be able to lend an "outsider's" point of view.

    I first visited slashdot a few weeks ago. I found an article on quantum computing next to a link to a Lego site. This combination has kept me coming back.

    When I saw the Linux in the university piece, I was overwhelmed by the three links in the body of the article. (I know it is as simple as looking at the URLs, but I found it easier to go straight to the forums.)

    While this story had fewer links than many, it would be easier to read the article if it was clearly marked as such.

    People will post without reading as long as it is easier than searching through URLs.

    (At the same time, I appreciate the links to this or that organization which place the article in perspective.)

  110. Re: Windows Policy Editor - could it be any worse? by E-Rock · · Score: 2

    It's amazing how difficult something can be when you do it wrong. Try loading the MMC, then add local policies, no regedit needed. After it's locked to the Nth degree, load the same tool from a remote box and connect to your secured machine.

  111. Last Post! by alpg · · Score: 1

    * dpkg hands stu a huge glass of vbeer
    * Joey takes the beer from stu, you're too young ;)
    * Cylord takes the beer from Joey, you're too drunk.
    * Cylord gives the beer to muggles.
    -- #Debian, celebrating the 5th anniversary

    - this post brought to you by the Automated Last Post Generator...