Live data from Hacker News

Windows: Insecure by Design

theregister.com

1–10 of 37 posts

Re: Windows: Insecure by Design

#4
Of course, we are on what, 30 years of trying and failing to certify protection against attackers with moderate attack potential [1][2].

Page 53: “The evaluator will conduct penetration testing, based on the identified potential vulnerabilities, to determine that the OS is resistant to attacks performed by an attacker possessing Basic attack potential.”

Maybe at some point we will start believing what they achieve in their certifications rather than what their marketing spews.

[1] https://learn.microsoft.com/en-us/windows/security/security-...

[2] https://www.commoncriteriaportal.org/files/ppfiles/PP_OS_V4....

Re: Windows: Insecure by Design

#5
What's really annoying me today is the security holes Microsoft is adding – by design – into Windows.

I mean of course Microsoft Recall. This delightful AI addition to the next generation of Windows PCs would have taken regular snapshots of everything you do on your computer.

Security and privacy are not the same thing. I get the frustration about Microsoft's security practices, but equating those two is a mistake.

Re: Windows: Insecure by Design

#6
The gulf between what the average person knows and what they would need to know in today's world to live an autonomous self-directed life with full agency, free from covert coercion by large corporate entities, is truly staggering. Every now and then I contemplate writing a book or a series of blog posts with all the things that I wish someone would tell me if I were a young person today, but then I read articles like this which remind me of the magnitude of the task and it takes all the self-control I can muster just to avoid curling up in a fetal position and sinking into the pit of despair, let alone actually start writing.

Re: Windows: Insecure by Design

#7

Clickbait titles should be automatically flagged/not even show up on the front page.

What's clickbait about it? It's the title of the article as written by the author. How would one even go about automatically flagging "clickbait" titles? Obviously the term means different things to different people.

Re: Windows: Insecure by Design

#8
post #5

What's really annoying me today is the security holes Microsoft is adding – by design – into Windows. I mean of course Microsoft Recall. This delightful AI addition to the next generation of Windows PCs would have taken regular snapshots of everything you do on your computer. Security and privacy are not the same thing. I get the frustration about Microsoft's security practices, but equating those two is a mistake.

You can't have privacy without security. Adding automation to violate privacy (even locally), is a new security risk, imo.

Re: Windows: Insecure by Design

#9
Even as a well known "windows hater", this is hyperbole. It's not insecure by design really. In fact in principle it's a lot better than anything Unix side due to the ACL and security model. It did however exist before anyone gave a crap about security, was implemented in a vastly insecure language and runtime and grew to a huge size and surface area and that is hard to fix retrospectively.

I'll give Linux a stab here: half the stuff I can run can write to my ~/.profile if it wants to. Anything which can read ~ is a problem because there's where all my important shit is...

Re: Windows: Insecure by Design

#10
Qube OS is nice, but when people are paid to get things done security is not forgotten but cut by a thousand paper cuts. It might all seem to be based on a secure design somewhere but even in small teams of 50 people you will always find people who have made short cuts.
Post reply on HN