3 ms·
I don't recall any *nix OS's having automount and autorun enabled by default? What I'm trying to say is, physical access does not necessarily mean full physica
by cryptarch 10y ago
I don't recall any *nix OS's having automount and autorun enabled by default?
What I'm trying to say is, physical access does not necessarily mean full physical access, and when the virus has to spread through some storage medium connected to e.g. USB the underlying OS certainly matters.
I mean, they probably autorun that for the subs, but I think its indicative of the design philosophy behind most MS products. "Made for those who don't need full control, with politics prioritized over security", because what security-minded programmer would ever enable that by default?
Edit: inserted middle paragraph + fixed typo
- izacus 10y agoWait, do you really think that embedded Windows versions behave the same as end-user ones?! That's like saying "Linux sucks for embedded devices because Ubuntu automatically updates kernel and breaks stuff".
- ktRolster 10y agoWait, do you really think that embedded Windows versions behave the same as end-user ones?! Typically they're worse, in my experience. Harder to work with, easier to make mistakes.
- avian 10y ago> Wait, do you really think that embedded Windows versions behave the same as end-user ones?! After having to install anti-virus software on an 100k+ EUR oscilloscope, yes. Yes, they do behave the same as end-user ones.
- foldr 10y agoYou have no idea whether this is true in the case of British nuclear submarines, though.
- pjc50 10y agoPoint-of-sale Windows dev checking in: yes, mostly they do behave the same. Especially the "embedded" ones, which are desktop versions with different licensing, a few management features, special bits of userland (e.g. the OPOS subsystem) and, most crucially, longer support life. "Compact" versions (CE, or "embedded compact") genuinely have removed features, but CE will still automount devices if it has drivers for them and you've not turned it off.
- TazeTSchnitzel 10y agoIs that CE Windows CE, which is a completely different operating system designed for less powerful devices?
- Pyxl101 10y ago> I don't recall any *nix OS's having automount and autorun enabled by default? If you're implying that Windows does, then that's the consumer version. These settings can be controlled by group policy. In a military or corporate environment operated by an administrator, they certainly should not be assumed to take on their default value, and instead should be assumed to take on their configured value.
- cryptarch 10y agoDon't they share the same codebase? Of course there's gpedit and probably some other management tools, but I stand by my point that it indicates not prioritizing security, and it makes me supect the military will just have compliance-related differences while the IoT version will have functions somewhat haphazardly removed, with no real improvements on the underlying code. I also have bad experiences with their open-source products (Visual Studio Community, Xamarin, .NET libraries written by them), their IoT for RPi offering. Their consumer OS's require manual cleanup and yearly full reinstalls. I've had software updates break my drivers, and one game (Gmod) on Windows 7 kill my graphics card twice, the second time taking my mobo with it. Their software installation/deinstallation system is unreliable. I've had automatic disk repair completely wreck a hardware RAID 2 setup. I had about two BSOD's a year until I switched to Linux. I think my most stable Microsoft software experience I've had was Age of Mythology, and even that crashed sometimes.
- foldr 10y agoIf the devs lack sufficient clues to turn off automount, it really wouldn't matter what OS they used. I think there's a danger of comparing the current solution to some hypothetical perfect solution, which could never in fact be engineered within budget. An interesting comment on the Microsoft blog post: > I have an insider view on this as when the ‘Vangard’ class of subs were being built in Barrow I was a member of the command System trials team…this was long before Windows and Microsoft and needless to say niche software, produced in very small quantities was much, much more unstable and buggy than any Windows release! I remember one long session where the only way the system would pass a particular tiral was for every one to ‘hands off’ their ‘pucks’ (and upside down mouse) for 15 mins. All went well until 2 minutes to go and some one brushed by the puck. The system went down!!! After a very long day we manged to get past this step!! > Give me Windows anytime!!!
- wolfgke 10y ago> I don't recall any * nix OS's having automount and autorun enabled by default? But I recall * nix-like OS's that have telnet enabled by default with insecure default passwords: > https://www.malwaretech.com/2016/10/mapping-mirai-a-botnet-case-study.html https://www.malwaretech.com/2016/10/mapping-mirai-a-botnet-c... "Mirai propagates by bruteforcing telnet servers with a list of 62 horribly insecure default passwords, starting with the infamous admin:admin."