Google ditches Windows on security concerns
ft.com
ft.com
If they favor OS X over Windows that is completely fine, but I think they are implying something that isn't true in regards to security. If someone exploits OS X on them, is everyone moving to Linux next?
Did Google roll their own Linux? Which kernel do you target? which apps?
Where are virus writers going to put most of their effort?
Windows being as secure as Mac wouldn't help make it safer because a lot more implemented exploits are going to exist in the wild.
In other words, with open source Google is on a more level playing field against potential attackers.
Think about what you're saying, you're saying Google is going to sit there and review all of the source code, and all patches and new releases to that source code. Really? Do you actually believe this...
As per China having the source, do you really think it matters? If someone wants to break in, they're going to get in... (regardless if its Windows/Linux/Mac) why... because that's their job and they are going to spend every minute of every day until they figure it out, and that's what makes them better than you. Majority of the time the issue is not software itself, but the policies in place. Hell, why even break in technically, when I can probably call one of these 10,000 employees up and they'll give me their password. Duh.
If you believe security is 1-dimensional, then you are bound to fail. History has shown this time and time again, just read a book / biography in regards to this topic.
Considering the difficulty of patching security holes in proprietary software versus patching holes in open software, Google indeed would hugely benefit by drastically reducing the difference between the cost of defense and the cost of cracking.
It's not so much levelling the playing field, as removing Harrison Bergeron's buckshot-filled equality harness.
[1] http://www.zdnet.com/blog/security/apple-fixes-old-java-for-... [2] http://www.dailytech.com/Charlie+Miller+to+Unveil+20+Zeroday... [3] http://en.wikipedia.org/wiki/Charlie_Miller_(security_resear... [4] http://www.forbes.com/forbes/2010/0412/technology-apple-hack...
It's not crazy to pay someone on their security teams to review checkins to OSS apps they use. Saying 'OH MY GOD' loudly and repetitively doesn't consitute an argument and is rude to the parent poster. Be civil.
Maybe not Google by itself, but the sum total of everyone reviewing all the source code and sharing what they know is that it's far easier to develop a more complete security profile for Linux than it is for a proprietary system we can only study by reverse engineering.
Meanwhile, most bugs aren't discovered in careful source code review or by static analysis tools. Instead, we write programs to exercise the code, either by sending random dumb buffers to the target or by working out the expected format and varying messages until we cover every basic block in the target. You can do this with or without any source code.
I think you would have a hard time finding a professional to say that they trust Mac OS X dramatically more than they trust WinAPI in 2010, and I say this as a full-time Mac user.
There aren't many mansions where I live, yet they seem to need the most security.
Software != hardware literally.
1> Very few Macs are running anti virus/spyware software, as the users generally believe their systems to be immune to malware
2> The malware authors are probably already targeting Windows, why not do Macs as well? The sites I work with are up to 25% Mac usage now. That is significant.
3> As Mac browsers have not been attacked as often and scrutinized as carefully by attackers, it appears Apple and other browser vendors have not taken as much care to harden the Mac browsers and OS.
4> Is having a Mac a weak financial signal? I wonder what data is there is out there about the affluence of the Mac-owning audience. Apple isn't targeting the low end of the market, that's for sure.
So, in summary: it might be relatively easy, plus, why not.
I answer: Because for the same amount of effort you can make an order of magnitude more money.
The same logic works out for normal ('voluntary') software applications, doesn't it? Most companies decide to focus their efforts on producing software for Windows, based on the idea that the market is much larger. Companies nevertheless do decide to produce software for Macs, for various reasons.
This is why homogeneity is dangerous. The more diversity an ecosystem has, the less vulnerable it is to viri, whether we're talking about crops or computer networks.
The reason was, to put it bluntly, that IIS was designed without any regard to real security, whereas Apache had _some_ regard to security.
That's also the case for Windows through its history; it has been making leaps recently, but doing things more securely requires it to become less convenient / not backwards compatible, and therefore it is still, relatively speaking, way more vulnerable when used by your average user.
I'm not up-to-date, but up until 2007 or so, a significant number of web browser vulnerabilities were directly or indirectly a result of Windows and Explorer's love of executing files after wrongly identifying them as e.g. wav or doc files.
The single Unix design decision that a file must have an executable flag out-of-band, and the convention that by default this flag is off, both of which date back to 1970, have kept Unix safe from these kinds of bugs. Sane default permissions on system directories are another decision; the latter has been adopted by Windows in XP SP2 IIRC, the former still hasn't.
There had been security audits of the apache code base since its early dates (as NCSA Web Server), whereas IIS didn't (or, judging from its track record, if it did have they were done by incompetents who didn't notice the strcpy(host_field, ...) would overflow with a host name > 1024 bytes.
IIS had everything in the same process, meaning every thing exploitable somewhere would bring the whole server with it. Apache used a worse-performing but better compartmentalized process-per-request model.
Just to be clear, apache at the time was NOT a beacon of security or good design or anything. But it did follow standard Unix practices, which put it a significantly better place than the IIS of the time (which was written like a Windows desktop program). At the time, IIS exploits were being found at a rate of 4 remote roots per month, with worms actively exploiting them, whereas apache had one of these every several months, usually only exploitable if you knew the exact O/S version it was running on.
For herd immunity to apply in this case, we'd be assuming that OS X users are more likely to take proper measures to ensure that their system is not compromised (which may or may not be the case).
Then again, Jeff Goldblum was able to write a virus on his Mac that he used to infect the alien mothership, so maybe they're not so secure after all...
The ideal contest wold take a reasonably permissive system that's 3 months out of date and see how long that lasts under normal usage.
Wait, so they're phasing out Windows for security reasons, and moving to Mac instead? It at least made sense when they were moving to Linux or ChromeOS, but OS X's security track record as of late is far worse than Windows.
So, to a good approximation, you can say that the command line is based on BSD, and the rest came from NeXT and Apple, with a bit of GNU mixed in.
The BSD heritage is rather insignificant when it comes to security, since the largest attack surface comes from Apple applications like Safari, or the file manager, or other apps the end user uses directly on a regular basis.
My mistake.
UNIX 03 certification means MacOS X is a UNIX. It doesn't say anything about its status as a BSD though.
I had to dive into it headfirst for a Black Hat presentation in 2007, in which we loaded probes into a running xnu kernel to detect hypervisors. I was surprised by how easy it was to navigate based on my familiarity with FreeBSD's kernel. Obviously, there's quite a bit of non-BSD code in OS X, but for anyone who has worked with a BSD kernel before, the similarities are impossible to miss.
Hell, even if you can't read kernel code, the fact that OS X has sysctl, doesn't have proc, and debugs with ptrace() doesn't tell you anything?
Popularity is unrelated to quality of code.
While it is true that popularity = bigger target = more incentive to attack the platform's security, it is also often used as an excuse to try to hand-wave away bad, insecure code.
Another platform becoming more popular would indeed mean that it would have more people targeting it. But it does not, in any way, mean that the people would have the same level of success exploiting it as they do Windows.
We could probably safely expect that the platform would be successfully exploited more than it currently is. And people that think OS X is a security panacea are living in a fantasy world. But the argument that "[i]f everyone jumps to another OS so will the security problems" is a woeful oversimplification, and confuses two separate issues.
Also, as a side note, people seriously underestimate the level of incentive that currently exists for targeting non-Windows platforms. It is not the case that the incentive scales proportionally to audience size. Any sufficiently popular platform is a desirable target to attack. It's not like a platform has to have 90% of the market to be worth the effort. The relative ease of attack is a far more important factor than the potential audience size once we're talking millions of users.
As for the rest of your comment: both Windows and OS X are conventional monolithic operating systems written in C with core facilities designed and built in the '90s. Both are multiuser operating systems repurposed for single-user deployments. Both have strong kernel/userland barriers with well-defined interfaces. In fact, if you've done systems programming on both, they simply aren't all that different, even to a software developer.
But: for the past 10 years, Microsoft has been getting hammered by attackers, and has the benefit of a decade-long trial by fire. So when Microsoft randomizes library offsets, they don't (for instance) miss the entire runtime loading subsystem.
Also: most of Microsoft's most sensitive application code is written in C for WinAPI on x86, which is one of the best-understood application runtimes in the world. Much of OS X runs on cross-platform Objective C, which has received nowhere nearly as much research. Put simply: nobody knows how to write exploit countermeasures for OS X. I think mostly because nobody cares.
(Again: I say this as a Unix dev from '93 at a company standardized on Macs).
Mac isn't significantly more secure. In fact, after all the bad press, Microsoft has invested significant amounts of money on intrusion mitigation systems like address space randomization, non-executable stacks, and so on. Linux is playing catch up to Windows in some regards there, and from what I know about OSX, it's also far behind in intrusion mitigation techniques. (edit: here's a blog post that covers some of them: http://blogs.msdn.com/b/michael_howard/archive/2006/05/26/ad...)
There are perfectly good reasons for switching to OSX (like, for example, the fact that the interface isn't a pain to use, and the command line doesn't suck, although I still favor Linux with a good tiling WM), but I don't think security is a valid one.
You liked to an article that says "there once existed a vulnerability in Safari" and then right away claimed that Linux and OSX are "still catching up to" Windows in terms of security. Now, I want to believe you, but it sounds to me like you're speaking with a little too much conviction relative to the evidence you're presenting.
http://web.archive.org/web/20080111062141/http://www.matasan...
Another (fairly poorly written) article about it: http://www.tomshardware.com/news/hack-windows-security-snow-...
I'm sure you can find more if you dig around.
Also, non-executable stack has been supported OSX since it was shipped, but non-executable heap is new. I believe (I'm not sure) that non-executable stack is also disabled fairly often because of trampolines in GCC.
Security in OSX isn't broken, of course, but the mitigation measures are strongest in Windows, out of the mainstream OSes these days.
MacOS -- and I say this as a long-time user, since the System 6 days, and as an OS atheist -- only seems to have a better security track record in the minds of users because it hasn't been targeted anywhere near as much as Windows has.
As far as Google is concerned, they may just be banking on security-through-obscurity. Use a system that the bad guys aren't familiar with exploiting, and you're less likely to be exploited.
On Linux, if someone hacks my browser all I could ever lose is the stuff on my home directory. Should that happen, I can just log in as root, kill all processes of my user account, rm -rf the home directory and restore the most recent backup, and relogin with my account. Without rebooting.
There are local vulnerabilities that might give you root privileges on Linux, too. But that's already a secondary attack and one of its own. Given the diversity of various Linux builds, it takes a lot more to crack into a machine and if successful, even that one is only one kind of a machine. With Windows, the homogeneity sweeps large installation bases at once.
Of course these tend to be precisely the only things you actually care about in the whole system. Assuming it's a desktop machine of course.
This doesn't mean your backup couldn't get infected...
It's the long, painful reinstallation process that I would have to do on a typical Windows machine to fully restore the pristine installation state after a virus/malware attack.
The only thing you can do with root that you can't do with a user account is write vanity malware that persists in ways that are harder to detect. But the most effective malware isn't written as a vanity exercise.
In Google's case, it's even less important to have root; what Google is protecting is access to their corporate network.
ducks
Seriously though, I'm sure that the folks who are allowed to use Windows are exactly the ones who need it: Picasa and Chrome devs (and the other desktop apps they have).
I really hope that's quoted out of context (e.g. maybe it's really getting a second machine, regardless of OS, that requires CIO approval?).
I doubt we're getting the whole story here. I'm sure there are everyday tasks that can be done more effectively on Windows (I've been Linux-only for a couple of years now, so I can't imagine what they are, but I'm sure they exist). And "Windows isn't secure" is absurdly simplistic (particularly at a company which can presumably hire the best sysadmins in the business). Constraining your employees like that to save the IT department a little effort doesn't sound like a good tradeoff.
I'd speculate this is more about politics, or dogfooding. Maybe they're trying to move employees from Office to Google Apps, and that's easier if Office is no longer available.
(This is being downmodded, but it's really true, at least where I work. The IT system is set up for HR people and bank tellers, not programmers. So the programmers just have to deal, because the system isn't setup for "average joe" employees to do anything useful. The good news is, we bought some company that says they won't be able to continue doing business if this stuff doesn't change, and the company we bought is more prestigious than we are ;)
Agree on the dogfooding.
<speculation>I think Google is planning a major attack on Microsoft's business / office empire. They have made it so simple to set up a new business using Google apps that it's almost unthinkable to me that I would go out and do an exchange setup. But this is largely still in stealth mode because Google wants to bring its business apps up to the point where they are a alternative to Office for real tasks before they really play this hand. And that means they have to force their employees to live on them every day, for everything. If they can't do it, how can they expect their customers to? And the best way to make it happen is to take away Windows entirely. Otherwise people will continue to fall back to Office and find reasons to sneak it onto their computers.</speculation>
I doubt they are looking at chrome OS to be a replacement for a full osx like operating system at any time in the near future.
http://www.readwriteweb.com/archives/was_google_an_inside_jo...
Wouldn't it be easier to make their employees use chrome?
Also, are IT policies applied consistently throughout the world or different regions have a diff. IT policy?
I thought the number was higher. Wikipedia says 20,621 (2010)... still thought it was higher.
They could always do windows development and testing inside of VMs though.
I also see another possible angle on this.
What is the actual windows system usage at google currently? It might already be low enough to represent a serious time-sink for IT/security because it's already a serious minority?
It makes a lot of sense to maintain somewhat complex policies and management for a vast network of Windows based systems and servers. It is entirely different when you're looking at trying to keep a handful of systems in-line when they are not your primary focus.
Obviously this is purely speculative but trying to look at it from another perspective.
Also, any unauthorized copy of Windows is most likely never updated.
In specific ways, how is OS X's security architecture more sound than Vista or Windows 7?
Do you feel UAC has a worse security design than the privilege escalation mechanism on OS X?
Or - since you mention teaching end users - are you talking about a user education issue?
We agree, from a technical point of view. OTOH, applications are the system, from a user's point of view, and Windows has "taught" programmers to write applications which run under high privileges. A Windows program requiring administrative privileges to run is not seen as defective: just disable UAC and it works flawlessly ;-) I guess a similar behaving OS X or Linux program would not have it that easy.
> Do you feel UAC has a worse security design than the privilege escalation mechanism on OS X?
I don't know about OS X. Linux user here.
If we look at it as techies, UAC is sound. If we look at it as average users, it is not. It's an usability issue.
> Or - since you mention teaching end users - are you talking about a user education issue?
Exactly. I think that a safe usage of a Windows system requires too much education. That's it.
On Windows, they would have to report the vulnerability to Microsoft, and hope that it's patched soon. It probably would be, but that's still an extra step - and they wouldn't be able to locate it with reference to the code. Also, as another person mentioned, china has access to the Windows source code; Google doesn't. This evens the playing field.
The article doesn't contain much substance.
Google seems to be ignoring that advice, ditching an entire operating system and all the potentially cool stuff that comes with it because they're a company full of developers who don't particularly like Windows, and because they compete with Microsoft and therefore hold a bit of a grudge.
They're certainly within their rights to do this, and they can justify it to themselves as being for "security reasons", but in the end all it will do is weaken them a little bit.
They're saying "Windows has nothing to offer us, and there is no Windows software that our developers might want that justifies having Windows machines in our offices." If you work at Google and want to use, for example, CodeSmith, you have to get special permission from the CIO to build a Windows machine to install it on.
Clearly CodeSmith is a good tool that developers might want to use, but because of management's vague fear of "security concerns", it's now off the table for your average dev.
My understanding anyway is that Windows is allowed, if you can demonstrate a strong enough case for it.
Just run Windows in a VM. You could even rdp or vnc into a few test boxes.
...but they're (allegedly) banning Windows.
Seems like a decision taken in haste and more of a knee-jerk reaction.
Doesn't seem knee-jerk to me when you look at the security track record of the various platforms.
If you were a hacker and you wanted that data, it wouldn't have stopped you if the target used Mac OSX ... you could just target some other unpublicized exploit. I mean all you need is Flash to do some damage.
I'd provide a link to hard data, but for some reason Secunia's taken down their list of unpatched vulnerabilities in OS X (?!), even though they provide this data for most other operating systems, including Windows.
Case in point, OSX even had more security advisories published than windows for a while, yet the "experts" still mostly agree OSX is the safer platform;
http://news.cnet.com/8301-27080_3-10444561-245.html?tag=rtco...
There's a very simple reason: OSX has around 6% market share, Windows around 80%. Go figure which platform the kids are going to target for the time being. Also feel free to research on which platform the major, semi-automated botnets (Storm, Zeus) are running.
Let me guess - not Windows 7.
It says there were 48+ security fixes. Doesn't matter what the reality is. People just want to believe Apple is more secure.
Closed source software = USSR
Open source software = USA