Live data from Hacker News

Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

thenextweb.com

61–70 of 137 posts

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#62
post #53
post #18

Is it getting safer to say that antivirus software may soon be a thing of the past?

My question is, would you run Windows 7/8 without any anti-virus software at all? Do you feel that comfortable? After years of Linux/OS X I can safely say that I won't use an OS that requires anti-virus ever again.

I have never run a windows system with anti virus. There is a very simple technique. Don't install viruses.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#64
post #25

Earlier quoted context omitted.

It is inherently more secured in the same context. The JVM applet sandbox has to stand up to random code off the internet, whereas native code is almost only installed explicitly. Remember ActiveX and how it was worse than Java applets?

It seems to me that the only reason we put up with JVM applets (whereas anyone suggesting we put up with people ActiveX would rightfully be laughed down these days) is because of that steady monotonous stream of crap about how much better Java is for security. It has dropped our collective paranoia far too low.

Java is or was until very recently as anyone who has used it since 1995 will know and remember. Recent issue have arisen, hopefully Oracle is going to get its track record up to what Sun's was. Until then, a few bad recent reports for Java 7 will not wipe out decades of countless security reports for all of Windows Operating System and many relied upon Windows applications.

Java applets are still far more efficient and far more powerful and have far greater operability with Java web server software than even HTML5 will have.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#65
post #53

Earlier quoted context omitted.

My question is, would you run Windows 7/8 without any anti-virus software at all? Do you feel that comfortable? After years of Linux/OS X I can safely say that I won't use an OS that requires anti-virus ever again.

I have never run a windows system with anti virus. There is a very simple technique. Don't install viruses.

I've had a single virus on a windows machine, and I was about 90% sure that it was going to be a virus and wanted to see what happened.

I don't run anti-virus software, but I think it's only the power users that are capable of doing so. User education is still too low. Would you trust your parents or grand-parents to "not install a virus" ?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#66
Let's take a look at CERT, shall we?

17 Sep 2012 VU#480095 Microsoft Internet Explorer 6/7/8/9 contain a use-after-free vulnerability

17 Sep 2012 VU#389795 Windows Phone 7 does not check certificate Common Names when sending or receive

Hmm. OK, how about #1 service being remotely attacked right now:

MS Terminal Services

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#67
post #53

Earlier quoted context omitted.

My question is, would you run Windows 7/8 without any anti-virus software at all? Do you feel that comfortable? After years of Linux/OS X I can safely say that I won't use an OS that requires anti-virus ever again.

I have never run a windows system with anti virus. There is a very simple technique. Don't install viruses.

Considering the kinds of vulnerabilities we've seen, this may prove difficult. I remember one where browsing to a folder with a specially crafted image provoked a buffer overflow that got exploited.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#68

Earlier quoted context omitted.

What can we trace this security priority initiative of Microsoft back to?

Jan 15, 2002 email from Bill Gates to all MSFT staff [1]. Includes some real gems, like; >So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. 1. http://www.wired.com/techbiz/media/news/2002/01/49826

I was hugely impressed by Bill when I read that memo, I checked with my friends who worked there to see if it was 'real' or a PR stunt, and they universally agreed it was very very real.

I suspect Google is about to be tested in this way given the adoption of Android on mobile devices. It is fortunate that they have a strong security culture to begin with but nothing proves that like being battle tested.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#70
post #55
post #36

Reading http://www.securelist.com/en/analysis/204792250/IT_Threat_Ev... , I find it surprising that the Netherlands manages to be the best malware exporter in the world (third in 'production', close behind Russia and the USA (both with a much larger population), but also in the top 10 for 'least consumption', a list that neither Russia nor the USA made). Does anybody have any idea how that comes about? The only reaso…

Amsterdam is a criminal epicenter

Any further links or reading? I am very interested in this subject.
Post reply on HN