<p dir="ltr">Dear All,</p>
<p dir="ltr">Using a FOSS is not the ultimate solution for security. Actually, The more an OS is used by (or open to) many people, the more chance there is that a vulnerability assessment/Penetration testing will reveal issues as the system is also open for worldwide hackers to know how it works and how it shouldn't ! </p>
<p dir="ltr">For your information, Android  and Linux were the most vulnerable OS in 2016 according to Business Insider (image attached)</p>
<p dir="ltr">Also :</p>
<p dir="ltr">100% security is not achievable <br>
80% + of attacks come from insiders<br>
90% of attacks target application layer</p>
<p dir="ltr">Therefore, Even when using a FOSS, consider the following rules :</p>
<p dir="ltr">Use most stable versions, <br>
Conduct regular Vulnerability Assessment and Penetration Testing. Apply latest patches and updates as soon as possible. <br>
Development Information Security policy in your entity and implement it. <br>
Conduct awareness campaigns  (this is one of the most important rule : the more a user is ignorant the more he/she is prone to use his /her IT asset in a more vulnerable way)<br><br></p>
<p dir="ltr">Best Regards<br>
@__f_f__<br>
<a href="http://about.me/farell">about.me/farell</a> <br>
________________________________.<br>
Mail sent from my mobile phone. Excuse for brievety.</p>
<div class="gmail_quote">Le 15 mai 2017 15:35, "Enrique Chaparro" <<a href="mailto:echaparro@vialibre.org.ar">echaparro@vialibre.org.ar</a>> a écrit :<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">[[SLIGHTLY OFF-TOPIC FOR THE LIST]]<br>
<br>
Some quick notes:<br>
1<br>
If you are interested in the worm mechanism spreading<br>
the infection, there's a good article here:<br>
<a href="https://blog.malwarebytes.com/threat-analysis/2017/05/the-worm-that-spreads-wanacrypt0r/" rel="noreferrer" target="_blank">https://blog.malwarebytes.com/<wbr>threat-analysis/2017/05/the-<wbr>worm-that-spreads-wanacrypt0r/</a><br>
<br>
2<br>
You may adopt FOSS for many good reasons, but security<br>
is not one of them. Unpatched vulnerabilities in critical<br>
FOSS pieces have lived for years. E.g., 'Dirty Cow'<br>
(CVE–2016–5195) was sitting unnoticed(?) for nine<br>
years; the bug causing CVE-2015-7547 glibc vulnerability<br>
was around for 8 years, etc.<br>
<br>
3<br>
As ecosystems show, diversity is A Very Good Thing™.<br>
However, diversity in the critical Internet infrastructure<br>
is actually very poor. A critical exploit affecting Cisco core<br>
routers may bring the Internet to its knees... and there is<br>
nothing we can do in a highly concentrated, quasi-monopilistic<br>
market.<br>
<br>
Regards,<br>
<br>
Enrique<br>
</blockquote></div>