Live data from Hacker News

Microsoft, Once Infested with Security Flaws, Does an About-Face

nytimes.com

11–20 of 185 posts

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#11
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

I'm just curious but why do you think Google is better at security than Microsoft? Number of exploits on Android vs Windows? Amount of funding on security research?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#12

"Still, episodes of online hacking have become even more startling, including the theft of personal data from millions of Target customers and terabytes of private emails from Sony Pictures Entertainment (and both companies use some Microsoft products)." So somewhere in Sony and Target's organisations there are one or more Windows computers? This is just lazy reporting NYT. Do better.

Agreed - I bet they use Google search every day and their execs have iPhones too.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#13
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

Apple has always been exceptional in this regard as well. It usually drives people up a wall when this is pointed out, as the fanboys like to trumpet it a bit too loudly, but it's true. In-the-wild exploits are rare, and the company moves quickly to squash them and to prevent the entire category of exploit from biting them a second time.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#14
post #5

Earlier quoted context omitted.

Not to mention the usability front. Windows is ugly and confusing. It didn't used to be so ugly and was less confusing in the past.

I think windows 10 is quite nice. Windows 8 is a POS.

For $3 you could get StartIsBack and you would never know the Start menu had changed since Windows 7, or the nature of the desktop vs. the tiles screen. That made Windows 8 work just fine for me.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#15
"Microsoft was once the epitome of evrything that is wrong with security in technology."

Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem.

But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's something about Windows that makes it a far greater liability than all the rest.

It's closed source.

How are you ever going to assess the quality of this software in terms of security? By reading the New York Times?

Boatloads of cash also buys PR.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#16

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

>But the fact remains Windows is still the easiest target of any OS.

How is that a fact?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#17
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

I'm just curious but why do you think Google is better at security than Microsoft? Number of exploits on Android vs Windows? Amount of funding on security research?

I actually agree with you (that Microsoft's internal processes are more security orientated than Google's version of the same).

That being said: A lot of Android's security issues are not always Google's fault. Some of them are in generic Linux libraries, some of them are in OEM added components (Samsung), and some of them are security issues unique to an app ecosystem (i.e. on Windows Win32 user applications normally have full permissions as that user, on Android an APK running as a user has a limited set of permissions, if it exceeds those permissions this is now an "exploit" which is now an additional set of security issues), and many are simply malware being placed on an app store.

Android's biggest issue isn't really that it is poorly designed (in particular with SELinux as standard). Android's biggest issue is how horribly the OS update mechanism works, so relatively minor security issues may not be fixed for years.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#18
post #6

Not sure 10 years is an about face?

Plus they are talking about caring about security and putting plans in place. Are they claiming they never cared and never had plans to make the situation better?

This is just like reporting on government where they report an idea a President mentions as "President dramatically reverses his entire 20 year belief system"

Cynically (and probably accurately), it’s a clever way to disguise a user feature (security) as a way to gather data so as to "protect" them. Sound familar?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#19
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

> Tellingly, Google's security efforts were also a top-down reaction to a major security incident.

What was that? All I can think of is when the chinese stole their source code but the response to that would presumably be more about managing who has access to what internally than improving the security of their user facing products.

edit: to be clear I'm thinking of the time they had code stolen by a chinese employee in their china office, presumably on request of the govt.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#20
post #5

Earlier quoted context omitted.

I think windows 10 is quite nice. Windows 8 is a POS.

Windows 8 was great if you went straight to the desktop and never looked back. There were some terrific upgrades to the classic desktop (even the task manager got real-time graphs and proper hierarchies for the first time). I always pictured a really talented dev team somewhere in Redmond plugging away thanklessly on things that the powers that be thought no-one cared about (like security and usability) until one day…

Very true. But every time I pressed the Windows key to open an application, I was reminded of the horrors that lurked outside of the desktop.
Post reply on HN