3 ms·
I just hope someday the general public realize what a poor job Microsoft has done regarding security on Windows operating systems and embrace other (and more pr
by unknown2374 10y ago
I just hope someday the general public realize what a poor job Microsoft has done regarding security on Windows operating systems and embrace other (and more promising) alternatives
- nchelluri 10y agobroadly speaking, how would you design things? All I can think of doing is putting explicit permission grants on everything, requiring everyone to click a million times as was done with the first version of Vista's UAC, IIRC, which is no solution IMO.
- digler999 10y agoever heard of code signing ? Maybe MSFT could use some of its 23 BILLION dollars of yearly profit to test some of the programs and conditionally approve them if they pass muster, also based on the historical reputation of the signer (like ebay feedback). Then if they contain sleeper code or other exploits, the keys are pulled, updates are pushed to ALL users of the program that revokes the key, thereby preventing mass exploits Come on, you're talking about the biggest and one of the oldest technological conglomerates on earth. They could fix the ecosystem if they wanted. But since they dont care about users, they'll wait till google does it for them and then sue over IP rights
- lazaroclapp 10y agoSure, because it is not like anyone would accuse them of abusive business practices and of trying to kill open source if they made it impossible to run software not signed by them... /s Even if you assume they would add a UEFI "enable developer mode" setting, this would get them so much bad press (and, also, it would actually make developing and distributing software on Windows a lot harder for smaller and open-source developers, and deploying custom software harder for enterprise costumers).
- digler999 10y agoOne of the things I love to criticize MS for is their "user account control" : gee, looks like you're actually trying to....USE.... your computer for something. You know, actually ...USING...your computer might damage it. Since making a secure platform isn't profitable, we'll just make the screen darker, cause you know, darkness kills the spyware. See, the signing system doesn't have to be mandated. It could pop up a UAC-like screen but with an actually useful message: this code is known to have malware, we recommend you dont run it. If you absolutely want to, press OK at your own risk. Another message could say it's completely unsigned, so devs could still write and distribute their own code. But make it free to submit to the "app store" and get reviewed by MS. That would work wonders to improve security across their whole ecosystem, and not force anything down the users' throats.
- Sylos 10y agoWell, broadly speaking, more Unix-like. I fully agree that putting administrator permissions on everything is not a solution, as users will start clicking it away without thought, but there's a good number of things in this article where I could not believe that it does not require administrator permissions. So, simply a clearer separation would be necessary.
- tensor 10y agoMac and Unix do this right. Yes, there is a lot more permission granting, but it seems to work just fine without people raging at it.