5 ms·
How much if this problem is solved when you have only accept Linux and Apple workstations in your network? Years ago, Google discovered some kind of intruders
by pibefision 12y ago
How much if this problem is solved when you have only accept Linux and Apple workstations in your network?
Years ago, Google discovered some kind of intruders inside their network, and mandated everyone to leave Windows and accept only Mac or Linux desktops. This has a cost of course, but I think something to think about.
I'm not telling that Linux or Macs has no malware/security problems, but is a very small problem compared with Windows today.
- pavel_lishin 12y agoI imagine that this would prevent casual attackers, but probably wouldn't seriously deter someone who's specifically looking to attack you.
- freehunter 12y agoIt would, however, make it a bit more difficult. Windows has more valid attack vectors than Unix-like systems do. Windows simply has more known vulnerabilities. It's not impossible to break into a Unix-like system, but for a dedicated attacker, it's almost trivial to break into a Windows environment. I can send someone an EXE that they can double click and install and I'm in. On Linux, that's much more rare of an occurrence. Try convincing someone to compile your malware from source...
- alex_anglin 12y agoThe fact that most Windows users run as Administrator doesn't help. Using root in Unix-like systems is frowned upon unless absolutely necessary is one of the basic security advantages Unix-like systems have.
- unscaled 12y agoThat hasn't been true for the vast majority Enterprise environments for the last decade or so, and even before for places which dumped the the Windows 9x lineage earlier. Even home users on anything beyond XP rarely run with default Administrator privileges anymore, although they're still a click away for most users, through UAC. Curiously enough, while Linux power users frown upon running as root, in Windows it's usually the power users who choose to disable UAC, although it's less bothersome than sudo (no password needed).
- maccard 12y ago> I can send someone an EXE that they can double click and install and I'm in. On Linux, that's much more rare of an occurrence. I can do that with linux binaries too? The difference is that a Windows user is more likely to install untrusted software.
- freehunter 12y agoTrue it's possible. Which is why I said it's not impossible. But it's very rare to find Linux binaries, especially Linux binaries that are not distro-specific. It's much harder to throw an infected binary at a user when you need to know more about them than "they run Windows 7".
- maccard 12y agoI wonder if I post on HN/proggit about my cool new ruby project, and start it off with curl | sh, but put something malicious, how many people will blindly install it?
- marcosdumay 12y agoYou can not get a Linux executable from the network. You can only give a file execution permission after it's local.
- higherpurpose 12y agoSecurity is all about raising the bar. If we could get every single machine/device to "only be breached through targeted attacks", I think that would be quite good.
- SlipperySlope 12y agoThe issue is having the dominant operating system. If you using a minority OS on a platform, then your point is valid. But where Linux is dominant there is malware. Reportedly, Android mobile OS malware is up exponentially in the last two years. http://bitcast-maa1.bitgravity.com/quickheal/documents/others/quick_heal_quarterly_threat_report_Q3_2014.pdf http://bitcast-maa1.bitgravity.com/quickheal/documents/other...
- higherpurpose 12y agoI don't think the Android ecosystem should be compared to an enterprise Linux ecosystem. Android is pretty secure on its own, I think with a security/sandboxing design that beats Windows's design for example. It even has SELinux enforced by default now, something even most Linux distros don't have. But every piece of software has bugs, some of which are catastrophic to the security of the device (GoTo Fail, Heartbleed, etc). Therefore updates are critical to the security of the ecosystem of machines. An enterprise environment can (should?) get updates much more easily than the vast majority of Android phones out there right now. Many of them get no updates and people keep them for 2-4 years. Many others get only one update in that same time, and only a smaller percentage are updated for like 18 months, even though many of those same users keep using them longer. Android's main security problem is the lack of updates. Windows' main security problem is its bad design - apps/malware can do almost anything once they are installed, and we all know people do stupid things such as installing exe's from email attachments. Heck, Windows even gives you admin privileges by default, and we are still surprised Windows has so much malware built for it? It's like asking for it.
- jodrellblank 12y agoAndroid's main security problem is the lack of updates. Windows' main security problem is its bad design - apps/malware can do almost anything once they are installed Do you know there have been windows releases since Windows 98se? Ones with real user accounts, ACLs, firewalls and UAC? You onky get limited access by default, admin access requires you to approve the UAC checks. And you're still comparing a home Windows system with an "Enterprise Linux ecosystem". No normal business Windows deployment will give anyone admin rights by default. Once software is installed on any OS using administrative/root permissions, it can do anything. Run a software installer on Linux as root and it could disable SELinux, for example.
- wglb 12y agoA large part of the problem is on the human side of things. Folks are very easily socially engineered regardless of what OS is underneath. There are likely exploits for root in almost anything. In recent memory, we saw ntpd, which often runs as root, get hammered. And of course everyone remembers heartbleed. As a thought experiment, on your linux command line, do a 'top' and ask yourself who has audited all those programs for security. Or, what the heck are all those things doing? And as a second thought experiment, open wireshark inside a totally linux-based enterprise and see what information is flowing there. Do linux-based enterprises run TLS internally everywhere? Encrypt all file sharing protocols? My bet is the answer is no. Additionally, breaches aren't all about getting root. Very common vector of exfiltration is SQL injection along with other injections. These happen at the application level. Remember a little while ago when IE had a forever bug that led to a remote code execution? I think in the same week Chrome did as well. While I grant that but is a very small problem compared with Windows today may well be true, small does not mean zero. All it takes is one improperly secured server sitting on the internet or one goofy neglected corner-case application page to lead to a total compromise. It only takes one tiny pinprick to deflate an inner tube flotation device.
- tim333 12y agoI'm guessing you are correct that there would be less problem if they used Mac and Linux. For whatever reason Microsoft does not seem to prioritise security that much. Just the fact that you can infect the system by clicking on an email attachment is a bad idea. On a Mac you have to click on the attachment and type your system password which makes it much less likely for a secretary to get malware on the system by clicking an attachment. The technical difficulty of implementing that is pretty much nothing. It seems more a question of attitude and not taking it seriously. I'm reminded of https://news.ycombinator.com/item?id=6978626 https://news.ycombinator.com/item?id=6978626 where the guy took a virus course. Better designed systems seem the way forward.
- tim333 12y agoIt's funny - I knew I'd be downvoted but I'm not a Mac fan boy especially - I've got a pc and a Mac and find Apple annoying in many ways but I just think it's a fact that the security engineering is better on some systems than others. I see Apple now have over 40m people on Mavericks/later and have sold over 800m ios devices but have way less than 1% of the malware. It's hard to explain that by just being a small target.
- graycat 12y agoIf on Windows and in Outlook I click on an email attachment that has extension EXE, WHAT happens? You are saying that Outlook will run the EXE? Really??????
- tim333 12y agoAh no - not what I meant. Just that you don't need to enter a password.