Live data from Hacker News

Google ditches Windows on security concerns

ft.com

91–100 of 158 posts

Re: Google ditches Windows on security concerns

#91
post #47

Earlier quoted context omitted.

Market share: Windows 90%, Mac 9%, Linux 1%. Where are virus writers going to put most of their effort? Windows being as secure as Mac wouldn't help make it safer because a lot more implemented exploits are going to exist in the wild.

I, for one, am pretty bored by the market share defense. There are millions of macs out there, owned by people who could drop a little coin on their hardware, and that make them less of a target? There's not one virus writer out there who doesn't want the cred and the potential gain of a new audience of victims, many of whom are probably pretty complacent about security because they've never had to worry about it? Th…

But its not just the size of the market... Windows machines are more likely to come into contact with another windows machine than macs are to come in contact with other macs. Thus a mac virus will spread much more slowly...

This is why homogeneity is dangerous. The more diversity an ecosystem has, the less vulnerable it is to viri, whether we're talking about crops or computer networks.

Re: Google ditches Windows on security concerns

#92

http://www.pcworld.com/businesscenter/article/159565/mac_os_... It says there were 48+ security fixes. Doesn't matter what the reality is. People just want to believe Apple is more secure.

Count is a poor measure. Both Apple and Microsoft lump together fixes for remote code execution vulnerabilities (terrifying), privilege escalations (not a big deal for personal machines) and denial-of-service vulnerabilities (not important except for public servers) as "security fixes".

Re: Google ditches Windows on security concerns

#93
post #51

Earlier quoted context omitted.

And what happens when someone exploits Linux?

You have a nice ecosystem of Unix OS's. Solaris, OpenBSD, NetBSD, ... and a handful of major Linux distros: Ubuntu, Fedora, Suse, Gentoo, Debian, etc. Once you've gone Unix you have lots of choices, including the Mac. Did Google roll their own Linux? Which kernel do you target? which apps?

It seems reasonable to assume that they'd standardize on a distribution, and centrally manage patching client machines. I cannot imagine that they would expect every employee to concern themselves with such things.

Re: Google ditches Windows on security concerns

#94

"Getting a new Windows machine now requires CIO approval," said another employee. I really hope that's quoted out of context (e.g. maybe it's really getting a second machine, regardless of OS, that requires CIO approval?). I doubt we're getting the whole story here. I'm sure there are everyday tasks that can be done more effectively on Windows (I've been Linux-only for a couple of years now, so I can't imagine what t…

I don't know about needing approval directly from the CIO, but last I talked to a friend of mine that works as a sys admin at Google, he did mention that they were requiring users to have to be able to make a business case for getting a Windows machine, otherwise they were deploying all Linux and Mac systems. This has been maybe 4 or 5 months ago now, not sure what, if anything, has changed since then.

Re: Google ditches Windows on security concerns

#95
post #35

Earlier quoted context omitted.

Citation? I haven't seen anything near the equivalent of Windows flaws on OS X. How many remotely exploitable OS X vulnerabilities have there been in the last 2 years?

http://www.computerworld.com/s/article/9129978/Researcher_cr... Mac isn't significantly more secure. In fact, after all the bad press, Microsoft has invested significant amounts of money on intrusion mitigation systems like address space randomization, non-executable stacks, and so on. Linux is playing catch up to Windows in some regards there, and from what I know about OSX, it's also far behind in intrusion mitigat…

The core difference between Unix and Windows, that has persisted since the beginning, is that by default on any Unix you get a user account which is different from the root account. On Windows, this hasn't even been possible until a few years ago (Vista? 7?), and AFAIK you still have to specifically configure Windows to give you a user account that really, really has no administrator rights. My parents wouldn't know how to do that.

On Linux, if someone hacks my browser all I could ever lose is the stuff on my home directory. Should that happen, I can just log in as root, kill all processes of my user account, rm -rf the home directory and restore the most recent backup, and relogin with my account. Without rebooting.

There are local vulnerabilities that might give you root privileges on Linux, too. But that's already a secondary attack and one of its own. Given the diversity of various Linux builds, it takes a lot more to crack into a machine and if successful, even that one is only one kind of a machine. With Windows, the homogeneity sweeps large installation bases at once.

Re: Google ditches Windows on security concerns

#96
post #95
post #35

Earlier quoted context omitted.

http://www.computerworld.com/s/article/9129978/Researcher_cr... Mac isn't significantly more secure. In fact, after all the bad press, Microsoft has invested significant amounts of money on intrusion mitigation systems like address space randomization, non-executable stacks, and so on. Linux is playing catch up to Windows in some regards there, and from what I know about OSX, it's also far behind in intrusion mitigat…

The core difference between Unix and Windows, that has persisted since the beginning, is that by default on any Unix you get a user account which is different from the root account. On Windows, this hasn't even been possible until a few years ago (Vista? 7?), and AFAIK you still have to specifically configure Windows to give you a user account that really, really has no administrator rights. My parents wouldn't know…

On Linux, if someone hacks my browser all I could ever lose is the stuff on my home directory.

Of course these tend to be precisely the only things you actually care about in the whole system. Assuming it's a desktop machine of course.

Re: Google ditches Windows on security concerns

#97
post #85

Earlier quoted context omitted.

I, for one, am pretty bored by the market share defense. There are millions of macs out there, owned by people who could drop a little coin on their hardware, and that make them less of a target? There's not one virus writer out there who doesn't want the cred and the potential gain of a new audience of victims, many of whom are probably pretty complacent about security because they've never had to worry about it? Th…

While you might liken the rarity and the glamour of owning a Mac to that of owning a mansion, a thief has much more to gain by targeting a large house that's more likely to be filled with expensive electronics and jewels. On the other hand, I doubt that Macs are significantly more likely to contain data that a hacker would be looking for.

Bad analogy.

Software != hardware literally.

Re: Google ditches Windows on security concerns

#98
post #61
post #45

Earlier quoted context omitted.

Mac OS X Leopard receives UNIX 03 certification: http://arstechnica.com/apple/news/2007/08/mac-os-x-leopard-r...

That's like saying Windows is UNIX-based because it conforms to POSIX.1.

That would be like calling someone a Ph.D. after completing kindergarten.

UNIX 03 certification means MacOS X is a UNIX. It doesn't say anything about its status as a BSD though.

Re: Google ditches Windows on security concerns

#99
The main reason a Mac user (in practical terms) is more secure then a Windows user is because Mac users typically are using the latest version of the OS, whereas an typical Windows user is at least one SP behind, maybe more?. Especially if said Windows sits in an office environment where there is a very slow adaption rate.

Also, any unauthorized copy of Windows is most likely never updated.

Re: Google ditches Windows on security concerns

#100
post #69

Earlier quoted context omitted.

Herd immunity? That's a pretty bad metaphor. There is not "safety in numbers" on the Mac. Safety comes from their lack of numbers. Unless you meant to imply that Macs are like the kids at school whose dipshit parents don't vaccinate them.

Actually, that's not what herd immunity means. Herd immunity is based on the concept that, if a large enough subset of the population is protected from infection, then others in the population are inherently more protected due to lower transmission rates. For herd immunity to apply in this case, we'd be assuming that OS X users are more likely to take proper measures to ensure that their system is not compromised (wh…

If Windows computers make up a majority of the market, then the transmission rate for viruses that target only OS X is low. Therefore, you could argue that computers collectively enjoy herd immunity versus OS X viruses, even if machines running OS X individually have weaker security than average.
Post reply on HN