6 ms·
This is an honest question: The vast majority of malware targets Windows, so how is it acceptable security practice to run Windows as your company's main operat
by matt2000 8y ago
This is an honest question: The vast majority of malware targets Windows, so how is it acceptable security practice to run Windows as your company's main operating system?
There is a second question as to whether Windows is still inherently more susceptible to these kinds of attacks (I would guess the answer is yes), but that's kind of irrelevant. The threat exists, why wouldn't you just use Macs or Chromebooks or whatever else? Basically _anything_ other than Windows? Even in the case where you have Windows-only business critical software, just run it in a VM on something else.
- pavel_lishin 8y agoI can't speak to this authoritatively, but Macs are typically more expensive than Windows machines. They might have run the numbers, and decided that (cost of malware) * (risk of malware) < (cost of macbooks) But really, I'd wager that Windows is just the standard solution, and more people probably use Windows than Mac.
- e40 8y agoThis equation is lacking, since he doesn't account for the cost of ownership. I'm moving all my people to macs from windows because the amount of lost work on windows and the amount of IT help needed is much greater for windows. Also, the anti-virus solutions on windows, which are much more needed there[1], have gotten really terrible recently. AVG was basically making the machines useless. [1] The standard I use for new mac users is they are not administrators, like everyone is on Windows. That prompt on windows to ask to install something that all users get numb to and say "yes"? Doesn't exist for my mac users, since they aren't admins. That alone helps in so many ways.
- pavel_lishin 8y agoI didn't know everyone had to be an admin by default on Windows. How do users lose work on Windows? Just by installing garbage all over the place?
- MagicPropmaker 8y agoThey don't. The person who said this is pushing an agenda trying to scare people away from Windows so his company can make more money.
- chillwaves 8y agoI feel like the people who work in this space see the post and it doesn't pass the smell test. For everyone else, I do not mind them learning the hard way why most businesses run a certain way. The obvious answer is the tools fit their needs best. It's not like OSX is some big secret.
- mcv 8y agoYou don't have to be an admin on Windows, but you can't do anything if you aren't. At every company that hires me where I have to use their PC, one of the first steps is always to request admin rights, because I need to be able to install dev tools. On Linux, you can have a special user account that can only install apps, without requiring root access. I think that would go a long way to preventing this sort of ransomware. Although losing data on a user machine should of course never be crippling to a company in the first place. Make sure everything is committed to a central location, as well as backed up at regular times.
- hobs 8y ago"Everyone being administrators" is a default on OSX and Windows - and you can configure both trivially to avoid the issue you state.
- protomyth 8y agoNo sane System or Windows Admin gives anyone admin rights on Windows without a very, very good reason (e.g. they are a developer and admin on their machine is a good thing). There also are very few computer uses that require local storage of any sort.
- user5994461 8y agoShould developer have any admin rights by default anymore? I worked in bank for a while without admin. In many years, the only tool that needed admin rights to run was the Visual Studio C++ Debugger.
- protomyth 8y agoDebuggers were one one, but also some other development tools just wouldn't run unless the developer had admin. Virtualization does mitigate some stuff.
- MagicPropmaker 8y agoThis is simply untrue. No corporate IT team configures Windows so users are Administrators by default.
- piginit 8y agoMicrosoft’s does, interestingly.
- ben_jones 8y agoHonest question, have you tried upgrading the hardware (mainly by adding an SSD) for windows users? An SSD can make a night and day difference in performance that may invalidate your decision to move everyone to Mac.
- l24ztj 8y agoI'd say desktop Linux is more insecure than Windows, and the only reason we don't see malware is that nobody uses it. So if high profile targets, like energy companies, started using Linux on the desktop, it may end up being worse than Windows.
- ejstronge 8y ago> I'd say desktop Linux is more insecure than Windows, and the only reason we don't see malware is that nobody uses it. So if high profile targets, like energy companies, started using Linux on the desktop, it may end up being worse than Windows. What's the basis for your assertion? At the level of systems we're discussing, a Windows installation would be operated by experienced Windows administrator. Thus the appropriate comparison group for Linux would be something like a university-run supercomputing cluster. We don't often hear of these being taken over for ransom.
- l24ztj 8y agoI said desktop, not server. I don't have any basis, just what I expect. Windows has been fuzzed and reverse engineered to the moon and back. Desktop Linux? I doubt it.
- penagwin 8y agoYou do know that "desktop linux" and "server linux" are the same thing, just with different default programs and configuration styles? I'd agree that yes, distros meant for desktop usage have less secure defaults, but that's not necessarily to say they're "less secure" if you understand how you're using them.
- l24ztj 8y agoNo, they are not the same thing in their USE, which is exactly the point I'm making. I trust nginx, sshd, postgres, postfix, etc. much more than I trust the gnome file manager, evince, dbus, pulse. For every exploit that nginx currently has, there probably are a thousand lurking in gnome's file roller.
- rjf72 8y agoImagine you're making a game that targets desktop and you can only target one platform. Do you launch on Windows, Mac, Linux, or something else? If you put personal ideology aside, it'd be Windows every time because that's where the users are. Exact same thing for malware devs. Malware targets Windows because that's where the users are. If the majority of people swapped to e.g. Mac or whatever else, then you'd see the majority of malware start to target Mac. You even see this as smaller players increase marketshare. E.g. in 2015 Macs ran into more malware than in the 5 previous years combined. [1] There was no major discovery or anything happening. The only thing that happened was that Macs gained a decent clip of marketshare, and so became more worthwhile to target. [1] - https://www.documentcloud.org/documents/2459197-bit9-carbon-black-threat-research-report-2015.html https://www.documentcloud.org/documents/2459197-bit9-carbon-...
- zrm 8y ago> Malware targets Windows because that's where the users are. If the majority of people swapped to e.g. Mac or whatever else, then you'd see the majority of malware start to target Mac. Even if this is true, it doesn't change the calculus for the individual company. If they switched to something else while everyone else is still on Windows, now they're using something with less malware targeting it. If everybody did that then maybe more malware would target the other thing, but that only matters if they mostly actually do and that actually causes there to be more malware than there is on Windows.
- MagicPropmaker 8y agoI don't think this is an honest question. You've pushing your agenda. Linux has a big ransomware problem and with inexperienced users running it, it can be easy to attack. See: https://www.scmagazine.com/home/security-news/new-b0r0nt0k-ransomware-roughs-up-linux-servers/ https://www.scmagazine.com/home/security-news/new-b0r0nt0k-r... and https://www.bleepingcomputer.com/news/security/b0r0nt0k-ransomware-wants-75-000-ransom-infects-linux-servers/ https://www.bleepingcomputer.com/news/security/b0r0nt0k-rans... And Mac is certainly not immune: https://www.cultofmac.com/416299/stealthy-malware-will-hold-your-mac-ransom/ https://www.cultofmac.com/416299/stealthy-malware-will-hold-...
- post_break 8y agoWhen the program you use to run certain machines only runs on windows, what choice do you have?
- Gpetrium 8y agoThere are many reasons why companies decide to buy/stay with a certain operating system, I will list a few: * Industry norm - In some cases, certain operating systems become a norm. Requesting someone to implement X solutions to a different operating system can cost more, have unexpected risks, etc. * Adaptability - It is easier to hire someone to do a job in X operating system/tool if that person has a similar system at home or used it in a previous company. * False sense of security - Transitioning to based on your rationale can mean that the business and its users will feel overconfident of their security. This can lead to increased careless mistakes.