It seems that every time we take a step toward better security by default, we end up taking one or two back just a short while later. Take the iPhone 5s. It's got that fingerprint scanner, betokening renewed attention being paid to security. But it also has what I'd have to call reckless out-of-the-box security configurations.
Let me give you a bit of context. My first encounter with the security-by-default wars was way back in the early 1990s, when Sun Microsystems famously and consistently delivered its systems with a "+" in its /etc/hosts.equiv files.
What's the big deal? Well, that little "+" resulted in every default-configured Sun machine trusting (for remote logins and file system mounts) the entire network to which it was connected. To exacerbate the problem, in those largely firewall-free days of the Internet, it meant that a default-configured Sun ended up "trusting" the entire Internet.
To continue reading this article register now