Live data from Hacker News

Google ditches Windows on security concerns

ft.com

51–60 of 158 posts

Re: Google ditches Windows on security concerns

#51

Is there any evidence that Windows 7 is less secured than Snow Leopard? Windows employs more advanced security techniques. IE has outlasted Safari in Pwn2Own since IE8. Windows releases security fixes much faster. If they favor OS X over Windows that is completely fine, but I think they are implying something that isn't true in regards to security. If someone exploits OS X on them, is everyone moving to Linux next?

And what happens when someone exploits Linux?

You have a nice ecosystem of Unix OS's. Solaris, OpenBSD, NetBSD, ... and a handful of major Linux distros: Ubuntu, Fedora, Suse, Gentoo, Debian, etc. Once you've gone Unix you have lots of choices, including the Mac.

Did Google roll their own Linux? Which kernel do you target? which apps?

Re: Google ditches Windows on security concerns

#53
post #45
post #34

Earlier quoted context omitted.

That's a myth. There are some parts like libc and the command line apps that were ported from BSD, the the kernel is a mach-that-isn't-anymore hybrid oddity, and the user interface is an Apple-only system. So, to a good approximation, you can say that the command line is based on BSD, and the rest came from NeXT and Apple, with a bit of GNU mixed in. The BSD heritage is rather insignificant when it comes to security,…

Mac OS X Leopard receives UNIX 03 certification: http://arstechnica.com/apple/news/2007/08/mac-os-x-leopard-r...

Sure, but that just means it provides the correct library calls, has the right shell utilities, and so on. It says nothing about the pedigree, or the amount of security. It's undoubtedly a good thing, but it's not important in this context.

Re: Google ditches Windows on security concerns

#54
post #7

Lots of new Mac and Linux users. Hopefully, some of the people will be dedicating some of their 20% time to improving the Mac and Linux platforms.

Engineering at Google is already 100% linux or OS X (at least when I was there in 2007), unless you were writing a client application targeting windows. This decision is about sales, marketing, HR, etc...

Re: Google ditches Windows on security concerns

#55

As Google still develops and tests for Windows I question that line about needing CIO approval for any Windows machine. Still, great to hear.

I agree--I think the google employee either didn't know what he was talking out or was taken out of context.

They could always do windows development and testing inside of VMs though.

Re: Google ditches Windows on security concerns

#56
post #53
post #45

Earlier quoted context omitted.

Mac OS X Leopard receives UNIX 03 certification: http://arstechnica.com/apple/news/2007/08/mac-os-x-leopard-r...

Sure, but that just means it provides the correct library calls, has the right shell utilities, and so on. It says nothing about the pedigree, or the amount of security. It's undoubtedly a good thing, but it's not important in this context.

Where do you draw the line when a BSD based OS has been customized to the extend that it can't be considered a BSD based OS?

Re: Google ditches Windows on security concerns

#58

Is there any evidence that Windows 7 is less secured than Snow Leopard? Windows employs more advanced security techniques. IE has outlasted Safari in Pwn2Own since IE8. Windows releases security fixes much faster. If they favor OS X over Windows that is completely fine, but I think they are implying something that isn't true in regards to security. If someone exploits OS X on them, is everyone moving to Linux next?

Mac OSX is inferior from a security standpoint, but enjoys herd immunity so the actual risk of infection is lower.

Re: Google ditches Windows on security concerns

#59

Is there any evidence that Windows 7 is less secured than Snow Leopard? Windows employs more advanced security techniques. IE has outlasted Safari in Pwn2Own since IE8. Windows releases security fixes much faster. If they favor OS X over Windows that is completely fine, but I think they are implying something that isn't true in regards to security. If someone exploits OS X on them, is everyone moving to Linux next?

Security contests are poor measures of security. A "new" windows flaw is a valuable commodity and most people who are aware of such things are not going to use them to "win" a contest. In the real world there are three issues, systems that are not up to date, systems that are more open than ideal, and unknown issues.

The ideal contest wold take a reasonably permissive system that's 3 months out of date and see how long that lasts under normal usage.

Re: Google ditches Windows on security concerns

#60
post #38
post #35

Earlier quoted context omitted.

http://www.computerworld.com/s/article/9129978/Researcher_cr... Mac isn't significantly more secure. In fact, after all the bad press, Microsoft has invested significant amounts of money on intrusion mitigation systems like address space randomization, non-executable stacks, and so on. Linux is playing catch up to Windows in some regards there, and from what I know about OSX, it's also far behind in intrusion mitigat…

Uh, citation, please? You liked to an article that says "there once existed a vulnerability in Safari" and then right away claimed that Linux and OSX are "still catching up to" Windows in terms of security. Now, I want to believe you, but it sounds to me like you're speaking with a little too much conviction relative to the evidence you're presenting.

I'm not sure of the overall security level of Linux & Windows, but Linux ASLR is weak: http://jbrownsec.blogspot.com/2009/07/beating-linux-aslr.htm...
Post reply on HN