OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Linux Journal article (Postfix)
From: Brad Knowles (blkskynet.be)
Date: Fri Sep 22 2000 - 13:49:31 CDT


At 11:30 AM -0700 2000/9/22, edalcpress.com wrote:

> Bernstein's survey looks plausible to me and I see no evidence
> of the results are skewed in any way. It's possible that
> someone you don't like or trust can still be telling the truth.

        Let me quote from an earlier post on this subject by Matthias
Andree <madt.e-technik.uni-dortmund.de> in Message-ID
<m37l84idz0.fsfemma1.emma.line.org>:

>> True, but the survey is 5 months old, and that's a long time, and a very
>> limited view. No .org, no .net, no .edu, no country-specific domains. A
>> random selection rather than "1/256 sample of all second-level *.com"
>> would have been more informative, but I admin that would be hard to do.

        I would add, what is this 1/256th? Is it the .1 IP address
within the /24 CIDR blocks associated with that .com? And how do you
determine whether or not that domain is a virtual hosting, or
actually has their own machines? What if they've got a smaller CIDR
block than a /24? Has anyone done a study of the distribution of
mail servers within /24 CIDR blocks? Maybe there's a
disproportionate number of them that are located at .2, and if he's
testing .3, he's going to miss a lot of these.

        There are a lot of questions left unanswered, and the fact that
he samples .com only is just the first and perhaps the biggest
question/bias.

> As for Netcraft, their survey of web servers is skewed in favor of
> Apache. This is explained at the following web site.
> http://www.biznix.org/surveys/

        The methods and assumptions behind the Netcraft surveys are
published by Netcraft themselves, and are well understood. Sometimes
there are biases that can't be controlled for when testing things on
the Internet, and you just have to learn to accept that.

        However, they follow proper etiquette by telling you what their
methods and assumptions are. You can't ask for anything more than
that.

--
   These are my opinions -- not to be taken as official Skynet policy
======================================================================
Brad Knowles, <blkskynet.be>                || Belgacom Skynet SA/NV
Systems Architect, Mail/News/FTP/Proxy Admin || Rue Colonel Bourg, 124
Phone/Fax: +32-2-706.13.11/12.49             || B-1140 Brussels
http://www.skynet.be                         || Belgium

"They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety." -Benjamin Franklin, Historical Review of Pennsylvania.