Live data from Hacker News

Microsoft, Once Infested with Security Flaws, Does an About-Face

nytimes.com

31–40 of 185 posts

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#31
post #2

Too bad it's doing the opposite on the privacy front, trying to collect more data than ever about Windows users, by default.

Set telemetry to Basic, in which case it doesn't collect any data about Windows users.

This whole debate has gone overboard through an inability to recognize the difference between telemtry and "spying". For example, between counting cars (important for city planning) and numberplate recognition.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#32

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

>How are you ever going to assess the quality of this software in terms of security?

I am not aware of a single third party that has reviewed all of the code that goes into a Linux distribution. Do you know of one?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#33
post #26

Earlier quoted context omitted.

Apple has always been exceptional in this regard as well. It usually drives people up a wall when this is pointed out, as the fanboys like to trumpet it a bit too loudly, but it's true. In-the-wild exploits are rare, and the company moves quickly to squash them and to prevent the entire category of exploit from biting them a second time.

The pwn2own contestants never have any problems pwning Macs, but iOS's security record is hugely impressive.

[deleted]

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#34

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

That's an interesting opinion... what makes you think it's the easiest OS to target? Do you have any data to back up the claim that a modern Windows OS is less secure than it's major competitors (OSX and, in some circumstances, Linux) My feeling would be that Microsoft have done a lot in the security line and have also given a lot back to the security community (their SDL documentation which is freely avaiable for ex…

The "security line" is not simply a question of "doing a lot" and "giving a lot back", ex post facto, or setting an "example" in the "security industry".

It also has to do with design goals and priorities. Layer upon layer of cruft, with an OS weighing in at multiple GB, is not a confidence builder in the "security line". It also includes default configurations.

There are reasons that so many Windows instances have been and are now part of botnets. There are reasons why the security updates have increased in quantity and frequency over the years and appear to be neverending.

Some of those reasons have to do with design and priorities. Others with default configurations that Redmond assumes no user will ever change.

No amount of PR can change reality (e.g., massive botnets of Windows users), although it might change people's perception of reality.

Also, I never said "major competitors". I said "other OS". For example, the OS I use is probably not a "major competitor". It is much smaller and open source. That is what is important to me.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#36
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

Apple has always been exceptional in this regard as well. It usually drives people up a wall when this is pointed out, as the fanboys like to trumpet it a bit too loudly, but it's true. In-the-wild exploits are rare, and the company moves quickly to squash them and to prevent the entire category of exploit from biting them a second time.

There are a lot of great people at Apple and the security model of iOS is an achievement --- in a lot of practical ways better than that of Android. But I do not know a lot of people who would argue the Apple has a better security program than Google does. Google's team is better funded and better staffed, and has a much broader charter than Apple's.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#37
post #32

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

>How are you ever going to assess the quality of this software in terms of security? I am not aware of a single third party that has reviewed all of the code that goes into a Linux distribution. Do you know of one?

Not sure what Linux has to do with my comment.

Are you assuming I use a Linux "distribution"?

Sometimes I have done so, but only occasionally when I need to check something on Linux.

Anyway, I am missing your point.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#38

Earlier quoted context omitted.

Apple has always been exceptional in this regard as well. It usually drives people up a wall when this is pointed out, as the fanboys like to trumpet it a bit too loudly, but it's true. In-the-wild exploits are rare, and the company moves quickly to squash them and to prevent the entire category of exploit from biting them a second time.

I can't help but think this is more a result of low volume and extremely tight control over their ecosystem rather than an intentionally prioritizing on security.

The MacOS X ecosystem is 25 years old now, counting NextStep, and has an installed base of close to a hundred million systems, most of them unsophisticated personal computer users running a full Unix operating system with internet access. That is a prime target, considering there are malicious exploits that take advantage of Z-series mainframes in recent years. (one of the Pirate Bay founders got popped for looting the mainframe at a tax accounting firm)

I think it's more to do with the development culture inside Apple. The features in Swift designed to improve secure coding shows you they're actively thinking about secuirty and how to achieve it, and have been for a while.

The only regular security headlines you see about the Mac is in the Pwn2Own contest and their like, where researchers trot out vicious exploits that are then dutifully squashed by Apple in the next update, never to be seen in the wild. (And there's a reason Apple makes it a PITA to install Flash and Java these days, and includes their own very nice .pdf reader.)

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#39

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

I remember my first experience with Linux back in the early 90's -- once connected to the Internet that Redhat box was rooted almost immediately. From my perspective, Windows doesn't seem to be less secure but it has a greater share of users who do stupid things.

Maybe Redhat's configuration was at fault?

I have seen popular Linux distributions where interfaces are enabled and have programs listening by default.

I, the user, never asked for that.

This is one reason I do not use Linux distributions.

Too many assumptions about what the user wants.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#40
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

Apple
Post reply on HN