Live data from Hacker News

Microsoft, Once Infested with Security Flaws, Does an About-Face

nytimes.com

141–150 of 185 posts

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#141
post #110

"All software is large." FALSE. But this statement does not surprise me. It is this distorted view of programs that is a large part of the "security" problem, in my opinion.

Saying it is false and calling views "distorted" does nothing to further the conversation. If you're interested in furthering conversation on the subject try providing reasoning behind your statements instead of condescension.

Perhaps you could explain how the statement "All software is large" "furthers the conversation"? How am I supposed to respond to that?

You think that false statement is a respectable "response" to a comment on the benefits of small software?

Small software exists both in the past (when memory and storage were more limited) and in the present. The very idea of small programs is a foundational one in the field of computing.

"All software is large" is not a "view" that is in agreement with reality. As such, it is distorted.

I am using small software every day. In fact I am writing this comment with a small program. When I write software, it is small, at least relative to anything from Microsoft.

I am too dumb to write large software.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#142

Earlier quoted context omitted.

>The data they collected was list of installed apps, serial numbers, and some sort of AppleID numeric identifier. In particular, they did not (could not) collect email addresses. [Edited for unnecessary stuff] Oh the article you linked has Apple response that is quoted verbatim below - it references user email addresses. Specifically. “We’ve identified a group of apps that are using a third-party advertising SDK, dev…

Maybe there's a private API on iOS that leaks the user's email addresses without the proper permissions. Maybe there's one on Android too. Neither OS has a runtime that will prevent malicious apps from exploiting such an API. > What I wrote was you are not going to be able to call an Android API via private invocation and succeed if the API requires a specific permission and your app hasn't declared it Just like on i…

A Safari zero day was just sold to governments (Nov 2nd). But yeah continue to assert otherwise if that makes you feel better. I am sure you have some explanation for that and all the previous jailbreaks for iOS and how they show iOS security being extraordinary! Android phones with botnets? Yeah you can believe that so hard it will make it a fact soon!

/jeez why do I bother with Apple fanboys?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#143

Would anyone agree that complexity provides a foundation for insecurity while simplicity makes audits easier? Large software with many parts have more potential for flaws. Small software with few parts have less potential for flaws because they are easier to find and fix. Implausible? Well, I happen to believe this. If Microsoft ever released the Windows source code, what would we find? Simplicity? How easy would it…

If you like small code, simplicity, and a code-audit culture, look no further than OpenBSD.

A well-deserved endorsement from a Microsoft employee. (Assuming your HN profile is up-to-date.)

The kernel I start with is indeed derived from the same one that project started with.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#144

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

> But the fact^W opinion remains Windows is still the easiest target of any OS. Windows isn't the easiest to target; but it is the most profitable, simply because it has the highest proportion of users.

OK, I'll bite. What do you think is the easiest?

Keep in mind what I said about configuration. Distinguish configuration from source code. Proper configuration s within the user's control and can be anticipatory and preventative.

Whereas poor quality code in a closed source program is outside the control of the user to fix and usually requires knowledge of someone exploiting it before it will be fixed. This is, unfortunately, after the fact.

Proactive versus reactive.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#145

Earlier quoted context omitted.

Not sure what Linux has to do with my comment. Are you assuming I use a Linux "distribution"? Sometimes I have done so, but only occasionally when I need to check something on Linux. Anyway, I am missing your point.

You're not sure what the most popular open-source OS has to do with your comment about open source OSes?

Nope. Maybe you can explain?

My comment was about closed source versus open.

Popularity is only relevant to the extent someone would argue Windows is not the easiest target but rather the most frequent one, due to its popularity, i.e., userbase size.

There's more to open source than just Linux.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#146

"Microsoft was once the epitome of evrything that is wrong with security in technology." Certainly they have improved over the last decade, but who hasn't? Not to mention they have boatloads of cash to throw at the problem. But the fact^W opinion remains Windows is still the easiest target of any OS. A user can configure any OS to be less secure, and other OS can become as popular a target as Windows but there's some…

> How are you ever going to assess the quality of this software in terms of security? If it's very important to you, you can obtain a license that includes source code: https://www.microsoft.com/en-us/sharedsource/

Or I could just use an open source alternative that does not require jumping through such hoops.

One where I can edit and compile the source, run it and redistribute it, too. All for free. But I guess all that is also possible under this shared source program you mention?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#147
post #110

Earlier quoted context omitted.

Saying it is false and calling views "distorted" does nothing to further the conversation. If you're interested in furthering conversation on the subject try providing reasoning behind your statements instead of condescension.

Perhaps you could explain how the statement "All software is large" "furthers the conversation"? How am I supposed to respond to that? You think that false statement is a respectable "response" to a comment on the benefits of small software? Small software exists both in the past (when memory and storage were more limited) and in the present. The very idea of small programs is a foundational one in the field of compu…

> In fact I am writing this comment with a small program.

Which small program is that?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#148
post #110

Earlier quoted context omitted.

Saying it is false and calling views "distorted" does nothing to further the conversation. If you're interested in furthering conversation on the subject try providing reasoning behind your statements instead of condescension.

Perhaps you could explain how the statement "All software is large" "furthers the conversation"? How am I supposed to respond to that? You think that false statement is a respectable "response" to a comment on the benefits of small software? Small software exists both in the past (when memory and storage were more limited) and in the present. The very idea of small programs is a foundational one in the field of compu…

The point is small software just does less; when you need to do more you either build large software or you put together a bunch of small software which is effectively, from a security standpoint, the same thing.

Small programs that don't do anything are secure but nobody cares.

And you've probably written software larger than Notepad; a very popular small Microsoft program.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#149
post #80

Earlier quoted context omitted.

> UAC was one of the biggest security improvements I assumed it was just an interface stapled onto the old system, and something underneath that allowed changing permissions without logging off. It might have had a big effect, but it doesn't sound like a significant change in the system. But maybe my assumptions are wrong ...

In XP, you could always change permission without logging off, by using the runas command or Run as... in the context menu. I think you could also set shortcuts to run programs as Administrator. So you could run as a non privileged users, and you'd only need to log in as Administrator for some very specific tasks. However, there were many applications that didn't play nice with that model and required you to run as A…

You could do that under XP, but needed a separate user account for administrator. It was also more of a hassle, as you always had to enter the password when starting a program as Administrator. I ran with such a setup on my desktop, and remember that to install programs I usually logged out and logged in as Administrator again.

Vista introduced a model that was almost as good, but made it more user-friendly and the default.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#150

Earlier quoted context omitted.

> I'm curious why you mention Google though, their security record on Android is a lot worse than either Windows phone or IOS. In many ways I feel like they are exactly Windows in 2003 with regard to "its secure if you use our APIs" kind of security. Chrome (OS)'s security model is a lot better, and compared to Android it was designed more in-house. Android was an acquisition and has more legacy design baggage (thoug…

Android's security is actaully fantastic. The problem is the inability for google to distribute security updates. In 6.0 I now get monthly security updates and there is even a "security update version" of like "november 2015" in the status. The latest junk even made it into Android 4.1 devices for security updates. But that is neither here nor there, the fact that we have 4.1 devices is a problem.

My 4.3, 4.4 and 5.0 devices from Samsung and Asus (operator free) are yet to receive the said updates.
Post reply on HN