4 ms·
Specialization vs. generalization. One aims to do one thing and do it well (in this case, to provide a means to use an embedded PC as a secure firewall), while
by lowtolerance 10y ago
Specialization vs. generalization.
One aims to do one thing and do it well (in this case, to provide a means to use an embedded PC as a secure firewall), while the other aims to provide a complete solution to make use of a vast repository of free software for many platforms.
The developer of SmallWall follows the same philosophy put in place by the developer of m0n0wall that preceeded it:
> SmallWall is a firewall, and the purpose of a firewall is to provide security. The more functionality is added, the greater the chance that a vulnerability in that additional functionality will compromise the security of the firewall.
SmallWall is barebones FreeBSD with about 10 utilities strung together to provide the functionality one would expect of a commercial-grade firewall. That's not to say that SmallWall is impenetrable, of course, but it does mean that its attack surface is a few orders of magnitude smaller than Debian's, which attempts to make possible virtually anything that can be done today with free software, on multiple architectures.
You don't have to rush to patch the latest vulnerability in a piece of software if you've made a conscious decision to avoid using that software in the first place. For instance, while people on Debian's security team scrambled to patch Shellshock, m0n0wall was unaffected because it doesn't provide shell access.