6 ms·
So that more secure implementations than MS's can offer a transition for organizations dependent on it.
by calais 7y ago
So that more secure implementations than MS's can offer a transition for organizations dependent on it.
- tptacek 7y agoMicrosoft has one of the best software security teams in the world, one that arguably created the template that Google and Apple used to create the other best security teams in the industry. The idea that a Microsoft breakup would have improved computer security is an extraordinary claim.
- calais 7y agoWe can reasonably disagree about the quality of their security. More generally though tech diversity makes a difference in security: Dan Geer did an excellent talk about this.
- tptacek 7y agoWhat Dan Geer & co wrote about software monocultures is pretty much the last thing anyone seriously wrote about the topic, which hasn't had much predictive power in the ensuing years. The major bastions of software security on the Internet today --- Apple's iOS hardware/software platform, and Google's Chromium --- are both monocultures, and selecting yourself out of either of them will materially reduce your security (this is not a point HN commenters tend to enjoy reading, but it is nonetheless true). Geer & co wrote their paper right after the first "Summer of Worms", in which the insecurity of Microsoft's software was such a hot topic that there were congressional hearings on it. His analysis presumed that Microsoft wouldn't commit itself, organization-wide, to correcting the problem, because no other large organization had. But that's exactly what Microsoft did. On an edict from Bill Gates, the whole company pivoted towards security. They hired a huge number of software security people and contracted out essentially the entire software security consulting industry to assess everything from the TCP/IP drivers to Minesweeper (they now host an internal conference, "Blue Hat", to socialize the results of 3rd party audits from blue-badge vendors and internal researchers). They delayed and re-roadmapped whole projects around security, Longhorn being probably the most obvious example. They trained all their software teams on software security, and enacted company-wide controls on "safe" and "unsafe" library functions. Essentially, Bill Gates did the same thing in reaction to the Blaster worm that Theo de Raadt did with his fork of NetBSD: a site-wide top-to-bottom audit (I was, somewhat peripherally, involved with the OpenBSD audit of the 1990s; I had some findings and wrote the advisories but was very far from the most productive person in the project). But unlike Theo, Gates had a cubic fuckload of money to throw at the project, and it showed. The results, I think, more or less refute Geer's argument. Microsoft was able to (significantly, albeit incompletely) address its security gap because it had the resources to do so. Moreover, each major component of Microsoft's software security risk was, individually, huge: a desktop operating system, an office suite, a browser, etc. All required vast resources, and many were able to effectively share resources between each other. Diverse, (necessarily) smaller organizations could not have pulled this off, and, had they existed in 2004 when Geer wrote about them, they'd have started with approximately the same tech debt Microsoft had. And so today, if you're looking at a desktop operating system and choosing between one secured by the former monocultural bohemoth and another run by a dedicated and passionate band of volunteers, you will in fact usually be better off with the former. If instead of desktop operating systems we look at mobile platforms, the difference is even more stark, to the point where if you're not using either Apple, or Google's flagship supported platform, you're almost surely running something with grave vulnerabilities.
- calais 7y agoWhat an informed reply! Thank you for pointing out the influence of mobilized, coordinated resources on security. I will have to factor this perspective into my own and reconsider.
- tptacek 7y agoI appreciate the warm response! Usually when I marshal a wall of text to rebut someone on HN, they're less happy about it than you are. :)
- mwcampbell 7y agoSo what do we do if we want to oppose monocultures on principle? Clearly we can't just bury our heads in the sand and deny the truth you've presented here. Maybe the key is to make it easier to develop secure software, so one doesn't need a security team the size of Microsoft's, Apple's, or Google's. So I'm glad Mozilla is introducing more and more Rust into Firefox.