I have a bone to pick with most, maybe all, Linux distributors: Why in the world do they ship such security nightmares? To their credit, many stay on top of security issues, sending urgent messages to registered users and mailing list subscribers when a potential security exploit is found in a particular package, along with workarounds, updated packages, or both. But the way that a lot of distributions install by default, this is a lot like putting locking lug nuts on the wheels while leaving the doors unlocked and the key in the ignition.