Live data from Hacker News

Microsoft, Once Infested with Security Flaws, Does an About-Face

nytimes.com

71–80 of 185 posts

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#72
post #67

Earlier quoted context omitted.

> in a lot of practical ways better than that of Android. Umm no - the update situation is better on iOS but fundamentally iOS has bigger problems - https://twit.tv/shows/security-now/episodes/532?autostart=fa... . That problem is unfixable easily due to the way ObjC works. Android gets code access control for free with Java. There have always been Jailbreaks for most iOS versions and it's not like they haven't had o…

I don't understand what your argument is. Untethered jailbreaks on iOS are worth gigantic amounts of money because they are not easy to come by.

But they have existed for every version of iOS none the less. The relative difficulty may quite well be due to other reasons - closed source, locked down hardware etc. Says nothing about software security.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#73

Earlier quoted context omitted.

That's an interesting opinion... what makes you think it's the easiest OS to target? Do you have any data to back up the claim that a modern Windows OS is less secure than it's major competitors (OSX and, in some circumstances, Linux) My feeling would be that Microsoft have done a lot in the security line and have also given a lot back to the security community (their SDL documentation which is freely avaiable for ex…

The "security line" is not simply a question of "doing a lot" and "giving a lot back", ex post facto, or setting an "example" in the "security industry". It also has to do with design goals and priorities. Layer upon layer of cruft, with an OS weighing in at multiple GB, is not a confidence builder in the "security line". It also includes default configurations. There are reasons that so many Windows instances have b…

Sure design goals, well I'd argue that Windows has had "improving security" as a design goal for some time now, and that this has had measurable impacts on the security of their products.

For example take SQL server as a good example, compare the number of RCE issues that it's had with say.... Oracle's Database server, another well funded company with loads of "PR" money. You'll find the SQL server has many fewer security issues than the competition, and I would suggest this is evidence of Microsofts improved attention to security...

MS default configuration are really very good. I'd compare to your OS of choice, but you don't choose to disclose it :)

So on the server-side I'd say that when I test modern default installs of windows based products they tend to have a good security posture out of the box.

Security Updates, well everyone has a load of those, are you suggesting the MS is worse than their competition? Counting OS vulnerabilities is notoriously difficult to it's hard to get an Apples to Apples comparison here.

Botnets, well there are botnets on linux for sure, and OSX has had it's share of malware to as has Android.

If you like a small open source OS then that's fine, but it doesn't necessarily make another entirely different OS have bad security.

now I know there's a reasonable chance you're thinking I'm an MS "fanboy" or similar at this point, but I'm not. I use OSX/Linux and Windows (as well as some iOS and Android) where they work best for me.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#74
post #67

Earlier quoted context omitted.

I don't understand what your argument is. Untethered jailbreaks on iOS are worth gigantic amounts of money because they are not easy to come by.

But they have existed for every version of iOS none the less. The relative difficulty may quite well be due to other reasons - closed source, locked down hardware etc. Says nothing about software security.

Rooting your phone when your not allowed is so common in android it might as well be a non-event.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#75
post #36

Earlier quoted context omitted.

There are a lot of great people at Apple and the security model of iOS is an achievement --- in a lot of practical ways better than that of Android. But I do not know a lot of people who would argue the Apple has a better security program than Google does. Google's team is better funded and better staffed, and has a much broader charter than Apple's.

> in a lot of practical ways better than that of Android. Umm no - the update situation is better on iOS but fundamentally iOS has bigger problems - https://twit.tv/shows/security-now/episodes/532?autostart=fa... . That problem is unfixable easily due to the way ObjC works. Android gets code access control for free with Java. There have always been Jailbreaks for most iOS versions and it's not like they haven't had o…

Some recent figures: (http://betanews.com/2015/06/26/android-is-the-biggest-target...)

>"There was significant growth in Android malware, which currently consists of 97 percent of all mobile malware developed. In 2014 alone, there were 1,268 known families of Android malware, which is an increase of 464 from 2013 and 1,030 from 2012", it said.

Apple’s iOS, on the other hand, went through last year basically unscratched. The report said that there were just four iOS targeted attacks in 2014, and the majority of those were designed to infiltrate jailbroken devices.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#76
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

Not that weird. Illustrative perhaps. So you and I would have agreed in 2007 that Windows was much better at security than they had been, but we are both pretty tightly connected to the technology market. Today, 8 years later, my Mom and Dad think Windows is a "secure" system as they haven't had any issues for long enough that their opinion of it has changed. The final leg of this journey will be when Windows + Windo…

> I'm curious why you mention Google though, their security record on Android is a lot worse than either Windows phone or IOS. In many ways I feel like they are exactly Windows in 2003 with regard to "its secure if you use our APIs" kind of security.

Chrome (OS)'s security model is a lot better, and compared to Android it was designed more in-house. Android was an acquisition and has more legacy design baggage (though of course the vast majority of the code has been written by Google at this point).

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#77

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

> But the fact^W opinion remains Windows is still the easiest target of any OS.

Windows isn't the easiest to target; but it is the most profitable, simply because it has the highest proportion of users.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#78
post #75

Earlier quoted context omitted.

> in a lot of practical ways better than that of Android. Umm no - the update situation is better on iOS but fundamentally iOS has bigger problems - https://twit.tv/shows/security-now/episodes/532?autostart=fa... . That problem is unfixable easily due to the way ObjC works. Android gets code access control for free with Java. There have always been Jailbreaks for most iOS versions and it's not like they haven't had o…

Some recent figures: ( http://betanews.com/2015/06/26/android-is-the-biggest-target... ) >"There was significant growth in Android malware, which currently consists of 97 percent of all mobile malware developed. In 2014 alone, there were 1,268 known families of Android malware, which is an increase of 464 from 2013 and 1,030 from 2012", it said. Apple’s iOS, on the other hand, went through last year basically unscrat…

I would not read too much into 'reports' by companies trying to sell you security products.

If you want to talk impacts - both iOS and Android have been similarly impacted - big name apps getting into App Store that were compiled by hacked XCode, Ad SDKs using forbidden APIs etc. Likewise most Android malware is due to rooting and side loading apps from questionable sources.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#79
post #60
post #7

This is a weird story, since professional security people would have told you the same thing back in 2007. Windows wasn't originally designed to be secure. Even NT, which is a serious multi-user kernel, was a product of 1990s C programming style. And while that's true of the Unices of the time as well, none of them had Microsoft's absurd user base, and so none of them had the same terrible malware incentives. This al…

I don't know. My father-in-laws Windows PC is routinely bogged down with malware/adware. It's not the same kind of security holes that used to be rampant, but it's still too easy for malicious software to cause trouble.

Though Microsoft have improved their computers still often come laden with crapware much of the time unlike Apple or I think most Chromebooks. You then end up with stuff like Superfish if you're not lucky.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#80

Earlier quoted context omitted.

Vista was a major security redesign, not just bug fixes. UAC was one of the biggest security improvements in the OS, because it meant that users were no longer running as admin by default.

> UAC was one of the biggest security improvements I assumed it was just an interface stapled onto the old system, and something underneath that allowed changing permissions without logging off. It might have had a big effect, but it doesn't sound like a significant change in the system. But maybe my assumptions are wrong ...

In XP, you could always change permission without logging off, by using the runas command or Run as... in the context menu. I think you could also set shortcuts to run programs as Administrator.

So you could run as a non privileged users, and you'd only need to log in as Administrator for some very specific tasks.

However, there were many applications that didn't play nice with that model and required you to run as Administrator. By changing the default, MS had to do a big push to make software makers abide by the rules (which had been in place since XP (edit: in the mainstream branch) but were often ignored)

Post reply on HN