1 |
On Mon, 21 May 2007, Thilo Bangert wrote: |
2 |
|
3 |
> > I've held off on using Gentoo in larger deployments because the idea of |
4 |
> > putting a C compiler on a production box is just silly. |
5 |
> |
6 |
> why? |
7 |
> |
8 |
> some production quality software _requires_ a compiler to run. |
9 |
> http://varnish.projects.linpro.no/wiki/FAQ |
10 |
|
11 |
As do many rootkits. If somebody gets local access to a server with a |
12 |
suite of development tools they're well on their way to rooting the box. |
13 |
Removing these tools is simply a good example of security in depth. |
14 |
|
15 |
|
16 |
-Ronan |
17 |
-- |
18 |
gentoo-server@g.o mailing list |