4 ms·
That assumes total security competence at Microsoft. The Linux model benefits from public audit.
by burnthrow 6y ago
That assumes total security competence at Microsoft. The Linux model benefits from public audit.
- TrueDuality 6y agoFor what it's worth I'm familiar with Microsoft's security team (both for their infrastructure and code) first hand and they are some of the most competent individuals I've ever had the pleasure to know. I'm personally not a huge fan of Windows, and it definitely has flaws but the amount of considerations taken into account, and the speed with which issues are identified and repaired in a code base of that size, especially while maintaining a disgusting amount of backwards compatibility is crazy impressive. That aside, having access to the source code does make finding issues easier. It sounds like that knowledge is assumed in their risk assessments which would make that a fair statement.
- mol4711 6y agoHow about their bug tracking software, MS equivalent to Jira issue tracker (I assume they aren't using an outside product). Do we know if they had access to their issue tracker? That would make it far easier to make zero-day exploits faster.
- RMPR 6y agoRaymond chen posted about that https://devblogs.microsoft.com/oldnewthing/20200317-00/?p=103566 https://devblogs.microsoft.com/oldnewthing/20200317-00/?p=10...
- rbanffy 6y agoThis puts them on the same level of Linux - when doing Linux threat assessment we can count the attacker has the source code for everything. In any case, it's silly to think otherwise. It's always safer to assume everyone that we wouldn't want to know something already knows that, whatever it is.
- to11mtm 6y agoIt's the same assessment level but may or may not be the same exposure level. While Microsoft does not assume that attackers haven't seen the source code, we cannot say how many people who are capable of spotting security issues have reviewed the code. That being said, it's worth also saying it's a hard comparison to make overall; it's possible there are important parts of the Linux code base that have in fact had less eyes on them than Microsoft has had on theirs; without numbers it's hard to be certain.