8 ms·
"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? No
by loginusername 11y ago
"Microsoft was once the epitome of evrything that is wrong with security in technology."
Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem.
But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's something about Windows that makes it a far greater liability than all the rest.
It's closed source.
How are you ever going to assess the quality of this software in terms of security? By reading the New York Times?
Boatloads of cash also buys PR.
- smackfu 11y ago>But the fact remains Windows is still the easiest target of any OS. How is that a fact?
- raesene4 11y agoThat's an interesting opinion... what makes you think it's the easiest OS to target? Do you have any data to back up the claim that a modern Windows OS is less secure than it's major competitors (OSX and, in some circumstances, Linux) My feeling would be that Microsoft have done a lot in the security line and have also given a lot back to the security community (their SDL documentation which is freely avaiable for example) and that they are one of the better examples of security in the software industry these days
- loginusername 11y agoThe "security line" is not simply a question of "doing a lot" and "giving a lot back", ex post facto, or setting an "example" in the "security industry". It also has to do with design goals and priorities. Layer upon layer of cruft, with an OS weighing in at multiple GB, is not a confidence builder in the "security line". It also includes default configurations. There are reasons that so many Windows instances have been and are now part of botnets. There are reasons why the security updates have increased in quantity and frequency over the years and appear to be neverending. Some of those reasons have to do with design and priorities. Others with default configurations that Redmond assumes no user will ever change. No amount of PR can change reality (e.g., massive botnets of Windows users), although it might change people's perception of reality. Also, I never said "major competitors". I said "other OS". For example, the OS I use is probably not a "major competitor". It is much smaller and open source. That is what is important to me.
- raesene9 11y agoSure design goals, well I'd argue that Windows has had "improving security" as a design goal for some time now, and that this has had measurable impacts on the security of their products. For example take SQL server as a good example, compare the number of RCE issues that it's had with say.... Oracle's Database server, another well funded company with loads of "PR" money. You'll find the SQL server has many fewer security issues than the competition, and I would suggest this is evidence of Microsofts improved attention to security... MS default configuration are really very good. I'd compare to your OS of choice, but you don't choose to disclose it :) So on the server-side I'd say that when I test modern default installs of windows based products they tend to have a good security posture out of the box. Security Updates, well everyone has a load of those, are you suggesting the MS is worse than their competition? Counting OS vulnerabilities is notoriously difficult to it's hard to get an Apples to Apples comparison here. Botnets, well there are botnets on linux for sure, and OSX has had it's share of malware to as has Android. If you like a small open source OS then that's fine, but it doesn't necessarily make another entirely different OS have bad security. now I know there's a reasonable chance you're thinking I'm an MS "fanboy" or similar at this point, but I'm not. I use OSX/Linux and Windows (as well as some iOS and Android) where they work best for me.
- Sanddancer 11y agoThe reason is exactly why MS has improved their security over the years. One of the things they've done is made automatic updating a mandatory feature of the OS. People can't just lazily turn updates off anymore because they can't be hassled for a 45 second break for their computer to maintain itself. Were these people running Linux, a lot of them would be doing the same thing, with the same results. Windows has a lot of botnetted computers because Windows runs the vast majority of computer systems out there. The neverending security updates is part of the difficult balance MS has to take between compatibility and security. Fixing a security problem that breaks a buggy program written 20 years ago by a company that no longer exists suddenly becomes a support issue, because there are a lot of people who don't want to hear that they have to upgrade their copy of PrintShop. MS releases security updates in part because they audit their code, and are making strides to get rid of a lot of the cruft. Windows 10 pulled a lot more services out of kernel space and into user space, for example. They're doing so while being conscientious of user needs, instead of telling the user to just code the fix for older programs themselves. In your small OS, who do you go to for support if something breaks? Who will you go to for support when a program from today breaks ten years from now? These are responsibilities many open source programmers will slough onto the end user, while they're working on the Latest and Greatest PulseConsoleSystemAudioKitD.
- wvenable 11y agoI remember my first experience with Linux back in the early 90's -- once connected to the Internet that Redhat box was rooted almost immediately. From my perspective, Windows doesn't seem to be less secure but it has a greater share of users who do stupid things.
- loginusername 11y agoMaybe Redhat's configuration was at fault? I have seen popular Linux distributions where interfaces are enabled and have programs listening by default. I, the user, never asked for that. This is one reason I do not use Linux distributions. Too many assumptions about what the user wants.
- wvenable 11y agoYou have to remember this was the 90's and it was a different time back then. I think there's a tendency to compare Windows in the 90s with how Linux is now. This was the same era as Mac OS 9 where a single application could still crash the entire system. Exploiting common faults in Linux system software was pretty easy back then too.
- ksk 11y ago>How are you ever going to assess the quality of this software in terms of security? I am not aware of a single third party that has reviewed all of the code that goes into a Linux distribution. Do you know of one?
- loginusername 11y agoNot sure what Linux has to do with my comment. Are you assuming I use a Linux "distribution"? Sometimes I have done so, but only occasionally when I need to check something on Linux. Anyway, I am missing your point.
- neckro23 11y agoYou're not sure what the most popular open-source OS has to do with your comment about open source OSes?
- loginusername 11y agoNope. Maybe you can explain? My comment was about closed source versus open. Popularity is only relevant to the extent someone would argue Windows is not the easiest target but rather the most frequent one, due to its popularity, i.e., userbase size. There's more to open source than just Linux.
- ksk 11y agoWell, I simply highlighted the difference between theory and practice. The average user does not have the money to audit open source software. And even if you get someone to bankroll the cash, you will need to re-do the audit for every single check-in since the audit. You made a point about Windows being impossible to audit, but in practice you're in pretty much the same boat when it comes to Linux.
- loginusername 11y agoAgain, you mention Linux. I do not use it. How is it relevant to my comment? And then there's this mythical "average user". But what does that have to do with me and my own solutions? I know only one user: myself. I know what works for me. I live in a tty. Do I need a Windows GUI? No. Finally, I also know that what one can do, another can do. But that is their decision and I am not trying to convince anyone to do what I do. Windows is a massive, complex truckload of legacy source code that keeps growing with every edition; it has a lot of flaws and the number grows every year; it is not "open source" in the sense of public source code respositories and enabling users to compile from source. This is not opinion. It's fact. These facts do contribute to the state of Windows "security". Bravo for fixing flaws in recent years. But no points for having them to begin with: poor quality control.
- blakeyrat 11y ago> But the fact^W opinion remains Windows is still the easiest target of any OS. Windows isn't the easiest to target; but it is the most profitable, simply because it has the highest proportion of users.
- loginusername 11y agoOK, I'll bite. What do you think is the easiest? Keep in mind what I said about configuration. Distinguish configuration from source code. Proper configuration s within the user's control and can be anticipatory and preventative. Whereas poor quality code in a closed source program is outside the control of the user to fix and usually requires knowledge of someone exploiting it before it will be fixed. This is, unfortunately, after the fact. Proactive versus reactive.
- robotresearcher 11y ago> How are you ever going to assess the quality of this software in terms of security? If it's very important to you, you can obtain a license that includes source code: https://www.microsoft.com/en-us/sharedsource/ https://www.microsoft.com/en-us/sharedsource/
- loginusername 11y agoOr I could just use an open source alternative that does not require jumping through such hoops. One where I can edit and compile the source, run it and redistribute it, too. All for free. But I guess all that is also possible under this shared source program you mention?
- robotresearcher 11y agoI don't think you need to sarcastically explain the benefits of Free Software in this forum.
- loginusername 11y agoI agree. Which is why I do not understand how anyone can claim Windows is not "closed source" in the sense of the opposite of "open source", as that term is commonly understood in this forum. Maybe they were being sarcastic?