20 ms·
The Windows ecosystem typically deployed in corporate PCs or workstations is often insecure, slow, and poorly implemented, resulting in ongoing issues visible t
by frankohn 2y ago
The Windows ecosystem typically deployed in corporate PCs or workstations is often insecure, slow, and poorly implemented, resulting in ongoing issues visible to everyone. Examples include problems with malware, ransomware, and Windows botnets.
In corporate environments, IT staff struggle to contain these issues using antivirus software, firewalls, and proxies. These security measures often slow down PCs significantly, even on recent multi-core systems that should be responsive.
Microsoft is responsible for providing an operating system that is inherently insecure and vulnerable. They have prioritized user lock-in, dark patterns, and ease of use over security.
Apple has done a much better job with macOS in terms of security and performance.
The corporate world is now divided into two categories:
1. Software-savvy companies that run on Linux or BSD variants, occasionally providing macOS to their employees. These include companies like Google, Amazon, Netflix, and many others.
2. Companies that are not software-focused, as it's not their primary business. These organizations are left with Microsoft's offerings, paying for licenses and dealing with slow and insecure software.
The main advantage of Microsoft's products is the Office suite: Excel, Word and Powerpoint but even Word is actually mediocre.
EDIT: improve expression and fix errors:
- Darvon 2y agoIf you were ready to ditch corpomicrosoft why would you go to corpoapple instead of something foss like debian tho
- nextos 2y agoI'd say something implementing the ideas of NixOS, i.e. immutable versioned systems and declarative system definitions, is poised to replace the current deployment mess, which is extremely fragile. With NixOS, you can upgrade without fear, as you can always roll back to a previous version of your system. Regular Linux distributions, macOS, and Windows make me very nervous because that is not the case.
- throwaway48476 2y agoIdeally there would be a usable security first os based on something like sel4 with a declarative package system for slow to change mission critical appliances.
- candiddevmike 2y ago> I'd say something implementing the ideas of NixOS, i.e. immutable versioned systems NixOS isn't immutable, things aren't mounted read only. AFAIK, it can't be setup that way. > With NixOS, you can upgrade without fear, as you can always roll back to a previous version of your system. Regular Linux distributions, macOS, and Windows make me very nervous because that is not the case. Because you can't roll back to a previous backup?
- nextos 2y agoThe store is immutable in the functional programming sense, as the package manager creates a new directory entry for each hash value. Backups could be an option, but it is much better to have a system where two computers are guaranteed to be running the exact same software if configuration hashes are the same. In other OSes, the state of your system could depend on previous actions.
- Wytwwww 2y ago> Regular Linux distributions, macOS, and Windows make me very nervous because that is not the case. I'm personally only really nervous when updating Linux distributions. Besides security updates it usually hardly matters or is noticeable on macOS/Windows (well besides the random UX changes..).
- deleted 2y ago[deleted]
- illiac786 2y agoHow do you automatically roll back if you’re in a boot loop?
- nextos 2y agoIn NixOS, you have a bootloader to load your OS. Unless you botch your bootloader, you can't paint yourself into an unbootable state. If one system configuration doesn't work, you reboot and choose the prior one before the OS begins to load in a menu displayed by the bootloader. This is also true of most regular Linux setups. Except that in those, you can only choose the kernel. Hence, if you have broken other parts of your configuration, your system might not be bootable. So the safety net is much thinner.
- illiac786 2y agoI really have no problem imagining an antivirus company convinced the bootloader needs an upgrade =)
- 1over137 2y agoBecause there is software that runs only on certain OSes, and not others.
- sirdvd 2y agoFewer and fewer. And there's VM for that, so you can rollback in case like this.
- danaris 2y agoBecause for some people (certainly not all), their objection is not to a "corporate" OS, but to the specific things Microsoft does that Apple does not.
- harimau777 2y agoWhen I took a Linux course in college I had an old laptop that I installed Linux on. However, for some reason my wireless card wouldn't work. I mentioned it to my professor and the next day he told me "It's actually quite simple, you just have to open up the source code for the wireless driver and make a one line change." Maybe things have gotten better, but I think that's why people use Mac. It's POSIX but without having to jump through arcane hoops.
- twothamendment 2y agoThings have definitely gotten better. I remember the painful years. My most recent Ubuntu install on a new laptop was about 3 years ago. As someone who has used Linux as the daily driver for more than a decade (and dual booted as a second OS for another decade) I was pleasantly surprised that everything just worked! I think that was a first It was an HP from Costco, not something special sold with Linux. My wireless worked, dual monitors just worked, even the fingerprint reader that I never use. I remember sitting there thinking "I didn't have to fight anything?" Hopefully that becomes the norm, maybe it is - I haven't needed a new laptop yet.
- Stranger43 2y agoThings have definitely gotten better. The problem with the linux desktop was usually that most hardware companies were either not spending any time/effort on non-windows drivers/compatibility or when they did it was a tiny fraction of the effort that went into working around bugs in the windows driver API's. Today with the failure of windows in both the mobile and industrial control space we now see vendors actually giving a damn about the quality of their Linux drivers. Today the main factor keeping the enterprise marked locked on windows is the fat clients written around the turn of the millennium, and that's as much a problem for mac adaptation as it is Linux adaptation. The macs are slick well designed devices that speaks to a huge segment of the consumer market so will eventually find the way into the high cost niches where no specific dependency on legacy software exists but they are too expensive and inflexible to replace all of the wintel system so for Microsoft and it's partners to have their license to screw over the enterprise sector revoked Linux(or FreeBSD) will have to play a role too.
- Wytwwww 2y ago> foss Because you just want stuff to work and couldn't care less about the ideology part? Also no feature parity (it's not about Windows being "better" than Linux or the other way around, none of that matters) there are not out of the box solutions to replace some of the stuff enterprise IT relies in Windows/etc. which would mean they'd have to hire expensive vendors to recreate/migrate their workflows. The costs of figuring out how to run all of your legacy Windows software, retraining staff etc. etc. would be very significant. Why spend so much money with no clear benefits? To be fair I'm not sure how Apple figures into this. They don't really cater to the enterprise market at al..
- naasking 2y ago> Because you just want stuff to work I think the current outage undercuts this premise.
- Wytwwww 2y agoWhy? Both things seem pretty tangential. Poorly written software exists or can exist on any platform, just like the IT infrastructure wouldn't somehow automagically become robust if they just switched to Linux.
- deleted 2y ago[deleted]
- quotemstr 2y ago> The Windows ecosystem typically deployed in corporate PCs or workstations is often insecure, slow, and poorly implemented Yes, but that's not because of Windows itself (which is fast and secure out of the box) but because of an decades-old "security product" culture that insists on adding negative-value garbage like Crowdstrike and various anti-virus systems on the critical path, killing performance and harming real security. It's a hard problem. No matter how good Windows itself gets and no matter how bad these "security products" become, Windows administrators are stuck in the same system of crappy incentives. Decades of myth and superstition demand they perform rituals and make incantations they know harm system security, but they do them anyway, because fear and tradition. It's no wonder that they see Linux and macOS as a way out. It's not that they're any better -- but they're different, and the difference gives IT people air cover for escaping from this suffocating "you must add security products" culture.
- rlanday 2y ago> > The Windows ecosystem typically deployed in corporate PCs or workstations is often insecure, slow, and poorly implemented > Yes, but that's not because of Windows itself Come on. There’s a reason Windows users all want to install crappy security products: they’ve been routinely having their files encrypted and held for ransom for the last decade.
- codebolt 2y agoI'd wager if Linux had the same userbase as Windows, you'd see more ransomware attacks on that platform as well. Nothing about Linux is inherently more secure.
- pid-1 2y agoYeah I don't get where this "Linux is more secure" thing comes from. Basically any userspace program can read your .aws, .ssh, .kube, etc... The user based security model desktops have is the real issue. Compare that with Android and iOS for instance. No one needs anti-virus bloatware, just because apps are curated and isolated by default.
- oytis 2y ago> Companies that are not software-focused, as it's not their primary business. These organizations are left with Microsoft's offerings I wonder why is it the case. These companies still have IT departments, someone has to manage these huge fleets of Windows machines. So nothing would prevent them from hiring Linux admins instead of Windows admins. What makes the management of these companies consider Windows to be the default choice?
- gvurrdon 2y agoI don't know, but I would guess that Microsoft Office is what retains people; personal anectodal experience suggests that anything else (Apple's offerings, Google Docs, LibreOffice &c.) is not acceptable to the average user. My suspicion is that Microsoft would be very unhappy to have MS Office running successfully on Linux systems.
- dariosalvi78 2y agoOffice. The entire world runs on Excel, Word and Powerpoint. Unfortunately.
- 7thaccount 2y agoYou can get that on Mac right?
- dariosalvi78 2y agothe comment I am replying to explicitly mentions Linux as an alternative to Windows. In any case, yes, one could use Mac, as I do, but it comes with its own issues, starting from price. I'd happily switch 100% to Linux if I didn't need to work on documents edited with Office. The online version may actually solve this, but it's still buggy as hell.
- briandear 2y agoWord and PowerPoint are disposable. Pages and Keynote work just fine. Excel on the Mac is perfectly fine. But that aside — Excel is a single application. That one app doesn’t determine an entire Corporate IT strategy.
- arccy 2y ago> Apple has done a much better job with macOS in terms of security and performance. Do not underestimate corporate IT's ability to slow down Macs with endpoint security software.
- ChrisMarshallNY 2y agoThis has been my experience. I used to run a C++ shop, writing heavy-duty image processing pipeline software. It did a lot, and it needed to do it in realtime, so we were constantly busting our asses to profile and optimize the software. Our IT department insisted that we install 'orrible, 'orrible Java-based sneakware onto all of our machines, including the ones we were profiling. We ended up having "rogue" machines, that would have gotten us in trouble, if IT found out (and I learned that senior management will always side with IT, regardless of whether or not that makes sense. It resulted in the IT department acting like that little sneak that sticks his tongue out at you, while hiding behind Sister Mary Elephant's habit). But, to give them credit, they did have a tough job, and the risks were very real. Many baddies would have been thrilled to get their claws on our software.
- balder1991 2y agoYeah, idk what they do, but in my company some new MacBook Pros with M3 are taking 15 minutes to login after typing the user password.
- ta1243 2y agoHad a problem with a "slow network" from a mac to a nas drive, was capping about 800mbit a second, despite having a 10g link. As I looked through I killed sophos. Suddenly speeds shot up above 7gbit. A few seconds later they dropped back down, sophos has retured. A "while (true) pkill sophos" later and the malware was sedated. Having proved it wasn't a network problem I left it with the engineer to determine the best long term solution.
- dagaci 2y agoI think you represent the schism in your own post. Retail is hyper focused on the name Microsoft and Windows. But the enterprise and technical people are focused on rolling back a bad CrowdStrike bad update. They will spend hours and even days focusing on doing that, asking why they were vulnerable to such an update and what they should have done to avert being vulnerable to a bad update. And for them it will be a bit of a stretch to say Microsoft should have stopped us deploying CrowdStrike. I’m sure Microsoft would love to do just that and sell its own Microsoft Solution. Now if enterprises decide to run only Linux, BSD, or MacOS would they have been invulnerable to a bad CrowdStrike update: https://www.google.com/search?q=crowdstrike+kernel+panic https://www.google.com/search?q=crowdstrike+kernel+panic No so your entire premis is fully invalidated by a single google search. On the other had I do feel Microsoft does have life far too easy in so many enterprises, but the fault here lies as much with the competition.
- gred 2y ago> it will be a bit of a stretch to say Microsoft should have stopped us deploying CrowdStrike I read GP's post to mean that if you take a step back, Windows' history of (in)security is what has led us to an environment where CrowdStrike is used / needed.
- rfoo 2y agoWell, then why would we have Linux and macOS versions of CrowdStrike Falcon Sensor (tm), too?
- oneeyedpigeon 2y agoTo make money? Just because CrowdStrike is available for Linux and Mac doesn't mean that a) people buy and use it in substantial numbers b) people need to buy it. It would be interesting to hear from someone using CrowdStrike in a Linux/Mac environment.
- onewheeltom 2y agoCS installed on my managed Mac. Generally no problems except randomly network stops working. Fixed by waiting.
- slumberlust 2y agoWhat makes you think the FAANG companies don't use windows? Spent four years at Amazon recently and unless you were a dev, you were more likely to have a windows PC than Mac. Saw zero Linux laptops.
- marcyb5st 2y agoDepend on which FAANG I guess. Approaching now 10y at Google and I saw Windows laptops only used by very few sales people. Everyone else is either using Macs or Chromebook.
- drewmate 2y agoFellow Googler here. I'm the exception that proves the rule. After 7 years of Macbook and Linux devices, I needed Windows for a special project, so I got a "gWindows" device and found it very well supported. Aside from the specific Windows-only software I needed, I would still just ssh into a Linux workstation, but gWindows can do basically everything my Mac can. I was pleasantly surprised.
- ttyprintk 2y agoWhat’s the secret sauce in gwindows? Do they add a hidden Russian keyboard or locale to neutralize malware?
- mdip 2y agoIt's funny how that works. Leave FAANG and most internal developers at large corporations are running Windows. It wasn't until I started at a smaller shop that I found people regularly using Linux to do their jobs, usually in a dual-boot or with a virtual Windows install "just in case" but most never touched it. I'm presently working supporting a .NET web app (some of which is "old .NET Framework) but my work machine runs OpenSUSE Tumbleweed. I can't see that flying at the larger shops I have previously worked at. I'll admit, that might be different -- today -- I haven't worked at a large shop in more than a decade.
- 2y ago
- jimnotgym 2y ago>Apple has done a much better job with macOS in terms of security and performance. I really like their corporate IT products that are going to push MS out as you say. I particularly love iActive Directory, iExchange, iSQLserver, iDynamics ERP, iTeams. Apples office products are the reason noone uses Excel any more. Their integration with their corporate cloud, iAzure is amazing. I love their server products in particular, it being so easy to spin up an ios server and have dfs filesharing, dns etc is great. MS must be quaking in their shoes
- frankohn 2y ago> I particularly love iActive Directory, iExchange, iSQLserver, iDynamics ERP, iTeams. Apples office products are the reason noone uses Excel any more. I see your sarcasm backfire as most you are listing is just Microsoft dog-food with no real usefulness. The only good thing in your list is Excel, all the rest is bloatware. Teams is a resource hog that serve no useful purpose. Skype was perfectly fine to send messages or have some video call. I admit I don't have experience as an IT administator but things like managing emails, accounts, database, manage remote computers can be done with well estalished tools from the linux/BSD world.
- datavirtue 2y ago"I admit I don't have experience as an IT administator" Then just hit the back button.
- dartos 2y ago> I don’t have experience as an IT Admin Wild that you’d write this comment with such a confident voice then. I worked at a company who’s IT team managed both windows and Mac computers and apparently MS’s ActiveDirectory is leagues ahead of apple’s offering. Which makes sense. MS is selling windows to administrators, not to users
- red-iron-pine 2y agoI'm a die hard FOSS guy, but as someone who has done LDAP work with FreeIPA and OpenLDAP -- AD does a better job. Admittidly, it's mostly a better job at integrating with Microsoft-powered systems, so it should damn well do a better job, but it's a core business offering and has polish on it in ways that many FOSS offerings don't. disclaimer: haven't done FreeIPA and LDAP work in the last ~3 years, maybe they got better.
- Intermernet 2y agoHonestly, windows out of the box is pretty secure. I don't want to defend Microsoft here, but adding third party security to Windows hasn't been anything but regulatory compliance at best and cargo culting at worst for over a decade now. If you actually look at core windows exploits compared to market share, they're comparable to Apple. Enterprises insist on adding extra attack surface area in the name of security. I agree that people who actually know what they're doing are generally running Linux backends, but Microsoft have enterprise sewn up, and this attack is not their fault.
- patmorgan23 2y agoA lot of active directory defaults are wildly insecure, even on a newly built domain, and there are a lot of active directory admins out there that don't know how to properly delegate as permissions.
- datavirtue 2y agoThis is true. You are basically one escalation attack on the CFO away from someone wiring money to hackers and a new remotely embedded admin freely roaming your network.
- mattmcknight 2y agoApple on the desktop/laptop, Google in the cloud for email, collaboration, file sharing, office suite. I ran a substantial sized company this way for a decade. Then we did a merger and had to migrate to Microsoft- massive step backwards, quintupling of IT problems and staff.
- gortok 2y agodownvoted, because in your response you conflate two issues: 1. The problem with using Microsoft 2. The lack of institutional knowledge of securing BSD and MacOS and running either of those at the scale Microsoft systems are being run at. The vast majority of corporate computer endpoints are running windows. The vast majority of corporate line-of-business systems are running Windows Server (or alternatively Microsoft 365). That means a whole lot of people have knowledge on how to administer windows machines and servers. That means the cost of knowledge to adminster those systems is going down as more people know how to do it. Contra that with MacOS Server administration, endpoint administration, or BSD Administration. Far fewer people know how to do that. Far fewer examples of documentation and fixing issues administrators have are on the internet, waiting to help the hapless system administrator who has a problem. It's not just about better vs. worse from your perspective; it's about the cost of change and the cost of acquiring the knowledge necessary to run these corporate systems at scale -- not to mention the cost of converting any applications running on these Windows machines to run on BSD or MacOS -- both from an endpoint perspective and a corporate IT system perspective. It's really not even feasible to suggest alternatives to any of the corporations using Microsoft that are impacted by this outage. If you want to create an alternative to Microsoft's Corporate IT Administration you're gonna need to do a lot more than point to MacOS or BSD being "better".
- __MatrixMan__ 2y agoThe poor quality of Windows and associated software is not the problem here. The problem is that Microsoft especially, but software vendors generally, encourage users to blindly accept updates which they do not understand or know how to roll back. And by "encourage" I mean that they've removed the "no thanks" and "undo" buttons. Here on Linux (NixOS), I am prompted at boot time: > which system config should be used? If I applied a bad update today, I can just select the config that worked yesterday while I fix it. This is not a power that software vendors want users to have, and thus the users are powerless to fix problems of this sort that the vendors introduce. It's not faulty software, it's a problematic philosophy of responsibility. Faulty software is the wake-up call.
- glitchc 2y agoWindows is leagues ahead of MacOS in terms of granularity of permissions and remote management tools. It's not even close. That's mainly why enterprise IT prefers it to alternatives.