4 ms·
To me, going to Microsoft for security is like going to the desert for ice-cream. The article seems quite biased, since "embarassing security failures" tend to
by nathanappere 15y ago
To me, going to Microsoft for security is like going to the desert for ice-cream. The article seems quite biased, since "embarassing security failures" tend to happen more often at Microsoft.
- canistr 15y agoThere tends to be a lot of myths about Microsoft security particularly in the non-Windows using community. The fact of the matter is that Microsoft tends to be very good about security updates, disclosure of bugs and holes, and remains vigilant about finding and patching up unknown flaws. Additionally, Microsoft hasn't had to answer before Congress on the matter of the securing their user's data. So trying to compare Microsoft's apparently "embarassing security failures" to Dropbox having to testify to Congress is like comparing your post to a PG essay.
- nathanappere 15y agoI happen to use 7 / archlinux / Os X almost equally. Of course my comment was trollesque, but an affirmation like "Microsoft ... tends to be very good about security updates" is not realistic. Time elapsed between exploit discovery and patch proposal to the user is everything but short. And If every website with a security issue was to answer to the congress, well it would not do much else. Plus, given the money Microsoft spend lobbying, I doubt very much that in a similar situation they would have to answer to the congress. Dropbox just seems to be a marked man.
- canistr 15y agoYes there is a time between discovery and patching but if you look at their competitors, Windows is much farther ahead in the security realm. Microsoft's whole security cycle is better defined and IT managers have a much easier time managing security updates from Microsoft than anyone else. Dropbox isn't a marked man because it doesn't have the capital of Microsoft, they've had to testify because they have a serious security and privacy problem.
- nathanappere 15y ago"if you look at their competitors, Windows is much farther ahead in the security realm" and that of course is not heresay but solid facts. If you exclude linux, bsd distros, and solaris of the "competitors", then you may be right. So far most of the securty / pen tests reports I have read (and my personal experience demonstrate) that it is way more easy to penetrate a Windows system than a unix / linux one. I like this sentence "There tends to be a lot of myths about Microsoft security particularly in the non-Windows using community" because the symetry is interesting: most non-unix/linux fail to see that these systems are usually more secure. I have used both kinds for 10 years and had much more security problems with Microsoft (which does not mean that I have stopped using it). I do not believe I am the exception.
- eli 15y agoYou are of course free to disagree with the author, but I hardly think that makes it biased. Logging in with any password is objectively a pretty embarrassing security lapse. I'm not aware of any problems like that with Live Mesh. Or even, really, with any online Microsoft products.
- nathanappere 15y agoI do agree on the fact that it is totally embarassing for Dropbox, and I do not either recall a similar issue with Microsoft, which does not make it safe. DEP / ASLR mechanism have been "easily" bypass several times this year, which to me is also embarassing. But the fact that this issue happened with Dropbox does not mean that it will again, and I'm pretty sure that it will make security one of their top priority. I do believe that going to Microsoft for better security is an odd move.
- canistr 15y agoAgain, you're making this point based on heresay. Of all the Dropbox competitors and cloud storage solutions, I'd tend to trust Microsoft the most because they will likely have the security experts employed to audit their products. Or simply that because they are Microsoft, 3rd-party security firms will investigate the security of Live Mesh.
- nathanappere 15y agoAnd yet there are a lot of active exploits targetting Windows. If your logic was sound, given that Windows is by far the most used system it should also be the most secure: then again I invite you to research the subject, security reports often show that it is more vulnerable than most linux/unixes. I find 7 to be an acceptable OS (and I still use it everyday) but blindly beliving that Microsoft ecosystem is secure because it is Microsoft's is a mistake.
- canistr 15y agoIt's not blindly believing Microsoft to be a better ecosystem. This has nothing to do with the OS. This is about the fact that they have a whole network of professionals who are more likely than a startup to audit their systems and keep it safe.