Hackers exploited Word flaw for months while Microsoft investigated
1–10 of 105 posts
Re: Hackers exploited Word flaw for months while Microsoft investigated
#2The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period.
Are these commenters suggesting that other, open source operating system choices have not also improved since that time period? Should one consider how much did each respective system need to improve?
(By "other, open source operating system choices", I mean the ones that were able to connect to the internet for years before Gates decided the www was something his company should be interested in and to copy the TCP/IP stack from an open source kernel into the Windows kernel).
Are there convincing arguments why Microsoft deserves special treatment compared to the open source alternatives, i.e., why their users should not be permitted to freely evaluate the Windows kernel or Office source code via the public web? Are there compelling reasons why MS users should not be allowed i.e. given the option to edit/remove source code they are uncomfortable with and recompile? Consider the effects of limiting the number of people who can find and fix defects in a product.
Does closed source status of Windows make Microsoft's software superior to the longstanding open source operating system alternatives?
Re: Hackers exploited Word flaw for months while Microsoft investigated
#3https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…
What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of.
If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But linux wasn't made to be easy to use, to be quick and easy to install, to install other software onto, etc... and that has kept it back, and it kept it back long enough for microsoft to establish a de-facto standard on the home desktop market...
The closed or open source status of a product has no bearing over its superiority at all. Again, in the world of geeks, it may, but in the world at large, it doesn't, and really, it shouldn't.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#4https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…
It's kind of like when a very lazy person turns into a marathon runner. They made huge changes.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#5Looking at this story, it's possible that 90 days is almost too long and should be shortened. As time goes on, it's becoming more and more common for multiple parties to become aware of the same vulnerabilities. Not all of those parties have good intentions, as we see here. Shortening the window of exposure is key.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#6https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…
Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…
Microsoft managed to gain a monopoly (legally or illegally - doesn't matter) and has used it to illegally keep others out, and network effects now (and for the past 20 years) have been that "goodness" measure - technical mediocrity had been sufficient (although recently they have been doing a lot of excellent technical work since the horrible 2000's)
In every single field Microsoft has not been able to leverage their monopoly (e.g. Phones) they are not in a dominant position, even though in some they maintain a competitive one (Xbox one, c#, SQL server)
Re: Hackers exploited Word flaw for months while Microsoft investigated
#7https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…
Microsoft was really really bad at security. Then the internet became a popular thing. I think an fresh xp install would, on average survive 15 minutes before getting infected by blaster. Microsoft, to their credit, improved dramatically. I don't know if they're extraordinarily good compared to other software producers. Microsoft gets the mention because it was so very bad, back in the day. It's kind of like when a v…
Re: Hackers exploited Word flaw for months while Microsoft investigated
#8https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…
Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…
Doesn't this have a lot more to do with pre-installs, and the marketing power that comes with it?
Dell's XPS Linux line and the Asus EEE PC were/are both pretty popular with the average person, so far as I'm aware.
Re: Hackers exploited Word flaw for months while Microsoft investigated
#9https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…
Their users don't need to be allowed to freely evaluate the source, period. When you write software, you control its distribution. What the users are free to do, however, is use an operating system/stack that they CAN evaluate the source of. If linux or any other open source alternative was a better actual product, it would find its way to the top of the market. In fact, it already has, on the server... by far. But l…
Just for the record in case someone isn't aware: Modern Linuxes are often easier to install and install software onto (as long as that software isn't written specifically for Windows or Mac OS.)
Re: Hackers exploited Word flaw for months while Microsoft investigated
#10https://mobile.twitter.com/hashbreaker/status/85322416941220... The strange "counterargument" I commonly see on HN to any suggestion that Microsoft closed source software could potentially be unsafe for use on an internet-connected computer is that the company has "improved" since some earlier 1990's/2000's time period. Are these commenters suggesting that other, open source operating system choices have not also imp…
Most people feel Microsoft is managing security better than the main Linux-based operating systems do, in terms of auditing, coding standards, code reviews, and developer security education. (That doesn't mean that they're doing this better than each and every individual open source project.)
Some of the people agitating for giving Microsoft more credit about this have personally seen the results, as in-house or contracted developers or auditors.
It can be hard to make an apples-to-apples comparison about what this means for the security of deployed systems because people are potentially using the systems in different ways with kind of different attack surfaces. (For example, quite a few Windows desktop users may still be downloading unsigned binaries from HTTP sites, which Linux users would be less likely to do because of the prevalence of package managers -- though maybe some of those Linux users will do the curl | sh thing from an HTTP site too.)
I don't think that a typical open source project has improved to the extent that Microsoft has during this timeframe, though, again, it's hard to know exactly what to compare or how to compare it.