It is one of my favorite posts of Theo's but it is a bit dated. Still what is advocated is not really practical (building a secure computer system (ISA, System Architecture, OS)). Something security folks have wanted to do for years and years, I even got to bid on one for some Maryland agency when I was at Sun.
That said, you could do a lot worse than just running OpenBSD out of the box on your servers connected to the Internet security wise, and be hard pressed to do better without a lot of training.
Comments
It is one of my favorite posts of Theo's but it is a bit dated. Still what is advocated is not really practical (building a secure computer system (ISA, System Architecture, OS)). Something security folks have wanted to do for years and years, I even got to bid on one for some Maryland agency when I was at Sun.
That said, you could do a lot worse than just running OpenBSD out of the box on your servers connected to the Internet security wise, and be hard pressed to do better without a lot of training.