Live data from Hacker News

Microsoft, Once Infested with Security Flaws, Does an About-Face

nytimes.com

161–170 of 185 posts

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#161
post #133

Earlier quoted context omitted.

Not sure what Linux has to do with my comment. Are you assuming I use a Linux "distribution"? Sometimes I have done so, but only occasionally when I need to check something on Linux. Anyway, I am missing your point.

Well, I simply highlighted the difference between theory and practice. The average user does not have the money to audit open source software. And even if you get someone to bankroll the cash, you will need to re-do the audit for every single check-in since the audit. You made a point about Windows being impossible to audit, but in practice you're in pretty much the same boat when it comes to Linux.

Again, you mention Linux. I do not use it. How is it relevant to my comment?

And then there's this mythical "average user". But what does that have to do with me and my own solutions?

I know only one user: myself. I know what works for me. I live in a tty. Do I need a Windows GUI? No.

Finally, I also know that what one can do, another can do. But that is their decision and I am not trying to convince anyone to do what I do.

Windows is a massive, complex truckload of legacy source code that keeps growing with every edition; it has a lot of flaws and the number grows every year; it is not "open source" in the sense of public source code respositories and enabling users to compile from source. This is not opinion. It's fact. These facts do contribute to the state of Windows "security". Bravo for fixing flaws in recent years. But no points for having them to begin with: poor quality control.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#162

Earlier quoted context omitted.

Perhaps you could explain how the statement "All software is large" "furthers the conversation"? How am I supposed to respond to that? You think that false statement is a respectable "response" to a comment on the benefits of small software? Small software exists both in the past (when memory and storage were more limited) and in the present. The very idea of small programs is a foundational one in the field of compu…

> In fact I am writing this comment with a small program. Which small program is that?

Are you saying you are unaware of any program that can post text to a web server that is "small"?

If all you are aware of is large software, then your statement that "All software is large" makes more sense.

"All software is not as large as Microsoft's software."

Would you agree with that?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#163

Earlier quoted context omitted.

A well-deserved endorsement from a Microsoft employee. (Assuming your HN profile is up-to-date.) The kernel I start with is indeed derived from the same one that project started with.

My profile is up-to-date, although maybe I should add the caveat that my opinions are merely my own. :)

Of course.

Though I'm sure you are not the only Microsoft employee who has used OpenBSD.

At one point, after the Danger acquisition, Microsoft HR was advertising a position for a NetBSD developer.

Are there any rules about using a non-Windows OS in the office? Even if it increases your capabilities and productivity?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#164

Earlier quoted context omitted.

Or I could just use an open source alternative that does not require jumping through such hoops. One where I can edit and compile the source, run it and redistribute it, too. All for free. But I guess all that is also possible under this shared source program you mention?

I don't think you need to sarcastically explain the benefits of Free Software in this forum.

I agree. Which is why I do not understand how anyone can claim Windows is not "closed source" in the sense of the opposite of "open source", as that term is commonly understood in this forum. Maybe they were being sarcastic?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#165
post #133

Earlier quoted context omitted.

Well, I simply highlighted the difference between theory and practice. The average user does not have the money to audit open source software. And even if you get someone to bankroll the cash, you will need to re-do the audit for every single check-in since the audit. You made a point about Windows being impossible to audit, but in practice you're in pretty much the same boat when it comes to Linux.

Again, you mention Linux. I do not use it. How is it relevant to my comment? And then there's this mythical "average user". But what does that have to do with me and my own solutions? I know only one user: myself. I know what works for me. I live in a tty. Do I need a Windows GUI? No. Finally, I also know that what one can do, another can do. But that is their decision and I am not trying to convince anyone to do wha…

>Again, you mention Linux. I do not use it. How is it relevant to my comment?

Um, because you compare like to like. If you are comparing millions of lines of code to 10,000 lines of code, then obviously its easier to audit. Your point about auditing code makes no sense unless you compare the task of auditing equal amounts of source code.

>Windows is a massive, complex truckload of legacy source code that keeps growing with every edition

Please enlighten us how you got access to the source code, which parts you evaluated, what methods you used to evaluate it, and why you think those methods are accurate and scientifically valid.

Unless you do those things, you cannot claim to be fact based. Its fine to have an opinion. Many non technical users who don't understand the NT OS design, confuse the implementation flaws of user mode code, kernel code, third party code, and are unable to differentiate it from NT design flaws. Sure, from a responsibility standpoint, I'm right there with them - If you ship it - you should own up to the flaws regardless of where they come from. I think that MS in the past made some super bone headed decisions (possibly driven by commercial reasons) that screwed them security wise because the 'default install' of Windows was insecure out of the box.

> But no points for having them to begin with: poor quality control.

How do you know this?

As an aside, I find it ironic for you to lament about "complex truckload of legacy source code" while using a TTY which itself is the exact same thing. Ah ! C'est la vie

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#166

Earlier quoted context omitted.

> In fact I am writing this comment with a small program. Which small program is that?

Are you saying you are unaware of any program that can post text to a web server that is "small"? If all you are aware of is large software, then your statement that "All software is large" makes more sense. "All software is not as large as Microsoft's software." Would you agree with that?

I'm also interested in the answer to their question instead of these diversions.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#167
post #166

Earlier quoted context omitted.

Are you saying you are unaware of any program that can post text to a web server that is "small"? If all you are aware of is large software, then your statement that "All software is large" makes more sense. "All software is not as large as Microsoft's software." Would you agree with that?

I'm also interested in the answer to their question instead of these diversions.

And why are you interested?

A comment in response to a NYT "article" (=PR piece) on Microsoft's approach to "security" where the comment points out that Windows is an extremely large program with layers upon layers of historical cruft and that it remains closed source. Additionally I suggested Windows is the easiest target for finding security flaws. It is a very large attack surface.

Is this really controversial?

For better or worse, I am responding to these comments no matter how nonsensical they are.

The best comments have actually come from Microsoft employees, past or present.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#168
post #165

Earlier quoted context omitted.

Again, you mention Linux. I do not use it. How is it relevant to my comment? And then there's this mythical "average user". But what does that have to do with me and my own solutions? I know only one user: myself. I know what works for me. I live in a tty. Do I need a Windows GUI? No. Finally, I also know that what one can do, another can do. But that is their decision and I am not trying to convince anyone to do wha…

>Again, you mention Linux. I do not use it. How is it relevant to my comment? Um, because you compare like to like. If you are comparing millions of lines of code to 10,000 lines of code, then obviously its easier to audit. Your point about auditing code makes no sense unless you compare the task of auditing equal amounts of source code. >Windows is a massive, complex truckload of legacy source code that keeps growin…

"How do you know this?"

As a user, I don't. It's closed source. That's the point. What users have is only circumstantial evidence. And then there is the marketing and PR, such as the NYT article.

One of original two comments was "What would we find?" There is nothing to suggest I have read the source code.

Unless and until Windows becomes an open source project, such as the ones that are routinely discussed in this forum, where users can remove code they do not want, then no amount of "updates" or PR by Redmond is going "fix" Windows to my satisfaction. As I said, I am not expecting that to happen, ever.

There is a comment in these threads from a former Microsoft employee that confirms my suspicions about poor quality control. Are you still in disbelief?

As for your aside, I agree. There's legacy code in both. But I suspect it is far less code overall. And, in my opinion, it's in some cases higher quality than what I am getting with Windows (there are certainly exceptions: Dave Cutter's work on the NT kernel being one). Of course, I do not have the Windows source code so I can only speculate what is in there.

More importantly, the size of the software is much smaller and I can modify and recompile it.

I can see to some extent what has been added and changed over the years. I can continue to learn from the source and the people who wrote it, instead of from a marketing department.

Living in a tty is "the exact same thing" as using Windows?

Is that an example of "comparing like to like"?

I am in VGA textmode. I am not using a graphic layer.

The amount of code to implement the tty, which is available to me to read, edit, compile and redistribute, is, I speculate, much smaller and less complex than the amount of code and complexity used to implement the Windows GUI.

Pure speculation of course.

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#169

Earlier quoted context omitted.

> In fact I am writing this comment with a small program. Which small program is that?

Are you saying you are unaware of any program that can post text to a web server that is "small"? If all you are aware of is large software, then your statement that "All software is large" makes more sense. "All software is not as large as Microsoft's software." Would you agree with that?

Why didn't you just answer the question? Which small software are did you use to post your comment? Why be so vague?

Re: Microsoft, Once Infested with Security Flaws, Does an About-Face

#170
post #166

Earlier quoted context omitted.

I'm also interested in the answer to their question instead of these diversions.

And why are you interested? A comment in response to a NYT "article" (=PR piece) on Microsoft's approach to "security" where the comment points out that Windows is an extremely large program with layers upon layers of historical cruft and that it remains closed source. Additionally I suggested Windows is the easiest target for finding security flaws. It is a very large attack surface. Is this really controversial? Fo…

Windows is actually very modular; even the kernel is designed in a micro-kernel style even though it all runs in ring 0. There are versions of Windows with no GUI.

Every other comparable operating system is in the same order of magnitude in the size of the code. The attack surface for any large OS is going to be about the same.

Post reply on HN