Bastille Adds Reporting, Grabs Fed Attention
johnny.ihackstuff.com writes "NewsForge interviews the Bastille project lead Jay Beale about Bastille's cool new assessment feature, which reports and scores Linux security and -- as always -- makes Linux lockdown super-easy. Available for many distros and Mac OS X, too. Best of all, it's free and open source!" As Jay points out in the interview, the work was "sponsored by the U.S. government's Technical Support Working Group." An anonymous reader summarizes the new capability: "In essence, Bastille now does two things. In one mode, it locks down an operating system, tweaking the configuration for increased security, asking you about each step and teaching you along the way. In the new Assessment mode, it reports on what hardening steps have been taken and what could be taken."
... but if I were starting a Linux security project, I'd name it after a prison which was difficult to escape from, rather than one famous for being stormed by about 1,000 upset Frenchmen.
Athletic Scholarships to universities make as much sense as academic scholarships to sports teams.
Why do we need hardening wizzards, tools software and so on. Why can't distributions be secure out of the box ?
Perhaps he should have used Bastille himself...
Gentoo Linux - another day, another USE flag.
I don't suppose someone could port this to windows could they?
There's not a lot of decent tools for non-security-expert admins and windows could do with something like this (not meant as an anti-windows troll).
Unfortunately too many corporate windows admins have so many pressures on their time that security of every server isn't always given the time it needs it sounds like this could provide a framework for that security.
Anyone else haveing problems getting this to run on Windows XP?
This is an excelent example of making an application have a "value" as incentive to do the right thing. People are by nature competative and will strive to improve a "score" even if it doesn't necessarily help them in any way. I give cudose to whoever decided to add this feature.
The download instructions for OSX were a little intimidating, even for someone like me with basic Unix skills...
Once Bastille for OSX becomes completely point and click it will take off like Jean Valjean after stealing a loaf of bread.
3D Printing Tips and Tricks at Zheng3.com
The ironical thing about this software is that it only works on *n*x systems, while the OS that probably could benefit most from it is Windows...
The windows admins here keep saying that Windows has better security stuff than Linux; so before raising this issue with them, I wanted to get a heads up on how they might respond.
A "lockdown" program such as this is only half of the battle. You need to keep your kernel updated, patch programs with fixes, and also make sure that a lockdown program such as Bastille is actually doing what it's supposed to, by making sure that the rules and configurations it creates are actually sane.
I'm pretty stoked about this. Of course, this is the first time I've even *heard* about Bastille Linux, but as a Windows IT guy that wants to move to linux (gentoo, here I come?), I'm glad to see these innovations and changes.
On a related note, if Windows made updates/innovations at this rate, I highly doubt that there would be this much criticism towards them. It's amazing that a company that hosts the richest man in the world can't cope with the innovation of an 'inferior' (I'm being facetious here, not trolling) business model.
War isn't about who's right. It's about who's left.
Was going to do that. No account. To create one they email me the pw, at work I don't have full email access. But thanks for the suggestion.
Bastille Linux is a program, not a flavor. It should run on any flavor of Linux Distro with the appropriate tweaking.
It's really nice; I was introduced to it with the book "Hackproofing Linux" and it does a lot of neat stuff.
Sets up sudo (if it's not already configured) Creates a second root user that is the "true" root user, and keylogs everything that root does, and alerts the true root of any attempted accesses
And a bunch of other stuff. I just thought the root stuff was extra sexy.
You better watch out, there may be dogs about . .
I wave my private parts in your general direction!
[hurls poop]
I don't use OS X, but if anyone is looking to have a good impact with little effort email jay at bastille-linux.org
I'm a bit surprised that it has been ported to a primarily desktop-OS (OS X), rather than Free/Open/Net-BSD. Anyone know of efforts to get this into ports? Are there already equivalent *BSD tools?
ok... dos dude your a troll :o)
[root@localhost root]# bastille --report
ERROR: 'MN9.2' is not a supported operating system.
.. when do we get one for Slackware
Suchetha
learn from yesterday, plan for tomorrow, party tonight
or one out of three ain't bad
I've been working with Tiger quite a bit over the last few months (even contributing some changes) and I'm pretty impressed with what it can do.
Also handy is the fact that it runs on most of the proprietary *NIX's.
[/Tiger Plug]
Custom, hands-free Linux installs. Instalinux
You can pick up an easy bonus point if you spell "kudos" correctly (hint: it's from Greek).
--MarkusQ
I like Free Software (GPL) because of the license. As a consequence of this license, many programs are good or very good. I actually prefer Free Software to other open source. This attitude is rather common, but so is yours. In the end, most of this stuff exists because of the licensing model. One should respect that. Should we call it the "best" feature? Probably not. GPL or just OSS does not imply quality automatically.
No, just commenting on the never ending, "it should come this way out of the box", statements.
IMO things began to go down hill when 'they' started trying to make unix friendly. It's a tool and you don't put doilies on a tool.
Making the various distros suit the majority of whiners is as much wasted effort as trying to shoot a duck on the midway using a rubber barreled 'rifle'.
A major reason that nix systems have a reputation hereabouts for superior security is that developers bother to write tools like this, and admins bother to run them and pay attention. It's not ironic -- it's an object lesson. As linux gets more exposure, we'll have an increasing need for this type of thing.
...
For example, I've worked under linux at work for years, I could whip out the perl command to ROT-13 your entire drive in a couple of seconds, and I'm pretty sure any linux box I set up would be totally insecure. Don't downplay the significance of tools like this
In the IT acronym OS means Operating System. If you need an abbreviation for open source use OSS. That is standard convention. When you don't follow standards you confuse and annoy people and will continue getting modded down.
You mentioned Gentoo.
It is definitely more work to setup (though, if you are computer literate you doubtless will be able to do it, so long as you pay close attention to the Handbook) but more rewarding in the end.
For me, other than that I found Gentoo to be the distribution that really started teaching me about linux, Gentoo was my eventual "only choice" because of the range of programs I use.
I found no other distribution had *all* the programs I use in their native software repositories. And installing from third-party repositories eventually caused me problems on other systems. (SuSE, Debian, Ubuntu and Xandros were my other linux attempts.)
So, let me heartily suggest, if you do make a decision to try out linux; do some research about programs first to make sure you can get the software you need with the distro you choose.
If you do go with Gentoo, I (and the myriad other forum users at http://forums.gentoo.org/ will be happy to help you). If you'd like some pre-installation tips or help with figuring out linux equivelant programs send me a private message at http://forums.gentoo.org/ (username: danuvius) and I'll be happy to help you out.
Akarsz Magyar Gentoo fórumot? Akkor
http://castle.altlinux.ru/
Ahhh, but you do want to keep somebody from pulling a "prison-break" and getting your data out...
This new reporting feature reminds me of the CIS Security Benchmark which was recently covered by NewsForge. The thing that has always bothered me about CIScan, however, is the mandatory registration process you have to go through before you download it. With Bastille offering similar functionality the need to use CIScan is greatly deminished in favor of a more "open" solution (not to bash CIS, but I don't enjoy having to keep track of yet-another-download-account).
What really makes the CIS benchmark great is the manual it comes with (which I briefly described in a comment here), so I hope the Bastille project doesn't neglect to document the benchmark in a similar way as to inform adminstrators about the various trade-off's involved. I suspect Bastille has modeled the reporting-feature after CIScan, though, so it will probably turn out to be a great replacement.
Great work guys, this new feature is welcomed with open arms.
Out of curiosity,
Do you write GPL software or just use GPL software?
How odd, a space got in that URL.
SlashCode seems to automatically add a space when a long line wraps. how nice and helpful of it! [Must resist making snarky comment about OSS quality...]
Remove the space and it works...
Contrary to popular belief, coding is not all free blow-jobs and beer. Those things cost MONEY!
I run archlinux (modified version of slackware) and while the source does compile fine, the executable won't run because of "unknown" OS. Even if I specify one of the supported OS types via the "--os" parameter, it still won't run.
Meh.
Doggonit! I just knew that I should have trademarked my name. I mean, I'm flattered and all, but really! Ah, well... at least I can get a free copy :-)
Derek Bastille
Wait, wasn't KuDOS an early PC operating system?
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
What, no webmail?
Actually for "you will be emailed your activation code" type activities, I recommend:
http://www.mailinator.com/
It's convenience itself: just make up an email account (up to 15 chatracters) @mailinator.com and use that to fill in the form with. There's no need to CREATE an account ahead of time: that is done automatically whenever an email is recieved. You don't even need a password!
Why hastle yourself with YET ANOTHER hotmail account for ANOTHER password when you only need to use it once?
What is the difference between a small revolutionary change and a large evolutionary change?
OK. So it looks like I'm a flamebaiting troll posting interesting articles. Cheers to the moderators! I told you to call me a troll. I never said anything about rating.
If I GPLed my first hello-world program, the best thing you could say about this piece of software is that it's free and open source. Surely, Bastille is a lot better than my hello-world, which wasn't even standard compliant.
What if you went shopping for a used car and the salesman told you "and the best thing: it's got a little light in the ashtray!"?
Yes, Slashdotters prefer free and OS software to commercial apps. But it seems to me that Slashdotters aren't the ones that decide about what software gets to run on the company's servers. It's the people that are called 'suits' around here and those people generally don't pay that much attention to the license. If these people think that a particular piece of software is good, they will happily shell out lots and lots of money.
If you want those people to use OS software, then please don't sound like bad used-cars salesmen.
Thanks for not reading this.