4 ms·
I wasn't aware Windows had better security than Linux. Do you have a source for this?
by bigstumpy 12y ago
I wasn't aware Windows had better security than Linux. Do you have a source for this?
- teamhappy 12y agoThey got the code signing right very early on. ALSR is still better than on Linux (I think). The whole privilege isolation thing is neat. Feel free to google it, this shouldn't be news. Just to be clear: Linux is doing fine. OS X is a hell of a lot worse. --- I forgot to say what I actually wanted to say: I said security features, not overall security. Linux is FOSS.
- joshstrange 12y agoOS X has code signing and a I think you mean ASLR not ALSR. Further OS X has ASLR the SAME YEAR as Windows (2007) according to wikipedia [0]: > Windows > Microsoft's Windows Vista (released January 2007) and later have ASLR enabled for only those executables and dynamic link libraries specifically linked to be ASLR-enabled. For compatibility, it is not enabled by default for other applications. Typically, only older software is incompatible and ASLR can be fully enabled by editing a registry entry "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\MoveImages", or by installing Microsoft's Enhanced Mitigation Experience Toolkit. > The locations of the heap, stack, Process Environment Block, and Thread Environment Block are also randomized. A security whitepaper from Symantec noted that ASLR in 32-bit Windows Vista may not be as robust as expected, and Microsoft has acknowledged a weakness in its implementation. > Host-based intrusion prevention systems such as WehnTrust and Ozone also offer ASLR for Windows XP and Windows Server 2003 operating systems. WehnTrust is open-source. Complete details of Ozone's implementation is not available. > It was noted in February 2012 that ASLR on 32-bit Windows systems prior to Windows 8 can have its effectiveness reduced in low memory situations. Similar effect also had been achieved on Linux in the same research. The test code caused the Mac OS X 10.7.3 system to kernel panic, so it was left unclear about its ASLR behavior in this scenario. > Mac OS X > In Mac OS X Leopard 10.5 (released October 2007), Apple introduced randomization for system libraries. > In Mac OS X Lion 10.7 (released July 2011), Apple expanded their implementation to cover all applications, stating "address space layout randomization (ASLR) has been improved for all applications. It is now available for 32-bit apps (as are heap memory protections), making 64-bit and 32-bit applications more resistant to attack." > As of OS X Mountain Lion 10.8 (released July 2012) and later, the entire system including the kernel as well as kexts and zones are randomly relocated during system boot. [0] http://en.wikipedia.org/wiki/Address_space_layout_randomization http://en.wikipedia.org/wiki/Address_space_layout_randomizat...
- teamhappy 12y agoI do mean ASLR. I even tried to correct it, but I spelled it wrong again ... They all have ASLR, but the Windows implementation is supposed to be better than Linux' (even if it's just a little). Anyway, they're both better than Apple's. The details really do matter here. --- By the way: Linux plays a very odd role here because it's also run on servers. Might be an unfair comparison. --- You really shouldn't google for these things (for the same reason you shouldn't listen to me either). Having said that, this source seems alright: https://www.cert.org/blogs/certcc/post.cfm?EntryID=191 https://www.cert.org/blogs/certcc/post.cfm?EntryID=191 Make sure to have a look at the Reddit discussion as well. Another good example for this is how /dev/urandom is implemented in Linux and FreeBSD/OS X. They both have it but it's not quite the same. --- Also note that the reason MS invests more into security than Apple does is because of their painful history. Makes all the sense in the world, doesn't it? --- Here's another one: https://en.wikipedia.org/wiki/Comparison_of_operating_system_kernels#In-kernel_security https://en.wikipedia.org/wiki/Comparison_of_operating_system... Note that Capsicum and SELinux aren't used that much (unfortunately). I don't know if Apple's sandbox is "inspired by" Capsicum. I also don't know why the MS sandbox isn't listed there. What's the feature called that gives each app it's own System32?
- joshstrange 12y agoDo you have a source on that? I'm googling for differences in implementation and the benefits and downsides of them but I'm not finding much, I may not be searching for the right thing though. Edit: Found this but it's from 2011 so probably out of date: http://www.theregister.co.uk/2011/07/21/mac_os_x_lion_security/ http://www.theregister.co.uk/2011/07/21/mac_os_x_lion_securi...