Live data from Hacker News

Microsoft, Once Infested with Security Flaws, Does an About-Face

nytimes.com

21–30 of 185 posts

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#22

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

That's an interesting opinion... what makes you think it's the easiest OS to target? Do you have any data to back up the claim that a modern Windows OS is less secure than it's major competitors (OSX and, in some circumstances, Linux)

My feeling would be that Microsoft have done a lot in the security line and have also given a lot back to the security community (their SDL documentation which is freely avaiable for example) and that they are one of the better examples of security in the software industry these days

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#23
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

Apple has always been exceptional in this regard as well. It usually drives people up a wall when this is pointed out, as the fanboys like to trumpet it a bit too loudly, but it's true. In-the-wild exploits are rare, and the company moves quickly to squash them and to prevent the entire category of exploit from biting them a second time.

I can't help but think this is more a result of low volume and extremely tight control over their ecosystem rather than an intentionally prioritizing on security.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#24
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

I joined Microsoft in 2003 maybe two weeks after SQL Slammer to do internal security work. "Dramatic" is a pretty good way to describe the situation. There were some very hostile debates even over very small bugs that got escalated to the executive level to which the answer was more or less "what part of the policy is unclear? fix it". It's an impressive transformation and I wish, say, Apple were that good. I had hopes for Apple when someone I knew from the Windows group went there but it doesn't seem from outside like the company really prioritizes security to the same degree as MS.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#25
Would anyone agree that complexity provides a foundation for insecurity while simplicity makes audits easier? Large software with many parts have more potential for flaws. Small software with few parts have less potential for flaws because they are easier to find and fix. Implausible? Well, I happen to believe this.

If Microsoft ever released the Windows source code, what would we find? Simplicity?

How easy would it be to audit?

Bias disclosure: I like small software. Windows and most all other software released by Microsoft is large, or packaged in such a way as to necessitate a large download/install.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#26
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

Apple has always been exceptional in this regard as well. It usually drives people up a wall when this is pointed out, as the fanboys like to trumpet it a bit too loudly, but it's true. In-the-wild exploits are rare, and the company moves quickly to squash them and to prevent the entire category of exploit from biting them a second time.

The pwn2own contestants never have any problems pwning Macs, but iOS's security record is hugely impressive.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#27

Would anyone agree that complexity provides a foundation for insecurity while simplicity makes audits easier? Large software with many parts have more potential for flaws. Small software with few parts have less potential for flaws because they are easier to find and fix. Implausible? Well, I happen to believe this. If Microsoft ever released the Windows source code, what would we find? Simplicity? How easy would it…

All software is large. If you break it into smaller pieces, it's still large. If you look into how iOS devices are jailbroken, it's usually combination of bugs from different pieces of smaller software that makes it possible.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#28

Would anyone agree that complexity provides a foundation for insecurity while simplicity makes audits easier? Large software with many parts have more potential for flaws. Small software with few parts have less potential for flaws because they are easier to find and fix. Implausible? Well, I happen to believe this. If Microsoft ever released the Windows source code, what would we find? Simplicity? How easy would it…

> If Microsoft ever released the Windows source code, what would we find? Simplicity?

Windows source code has been available for a long time under the Shared Source initiative. Some governments (including Russia), large companies, universities, partners and maybe even MVPs have had access to some versions. Email source@microsoft.com

https://www.microsoft.com/en-us/sharedsource/

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#29

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

I remember my first experience with Linux back in the early 90's -- once connected to the Internet that Redhat box was rooted almost immediately.

From my perspective, Windows doesn't seem to be less secure but it has a greater share of users who do stupid things.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#30
post #14
post #5

Earlier quoted context omitted.

I think windows 10 is quite nice. Windows 8 is a POS.

For $3 you could get StartIsBack and you would never know the Start menu had changed since Windows 7, or the nature of the desktop vs. the tiles screen. That made Windows 8 work just fine for me.

For free, you can use ClassicShell. I actually forget I'm on Windows 8.1 at home vs Windows 7 at work as they're almost identical.
Post reply on HN