If they favor OS X over Windows that is completely fine, but I think they are implying something that isn't true in regards to security. If someone exploits OS X on them, is everyone moving to Linux next?
If they favor OS X over Windows that is completely fine, but I think they are implying something that isn't true in regards to security. If someone exploits OS X on them, is everyone moving to Linux next?
The ideal contest wold take a reasonably permissive system that's 3 months out of date and see how long that lasts under normal usage.
Where are virus writers going to put most of their effort?
Windows being as secure as Mac wouldn't help make it safer because a lot more implemented exploits are going to exist in the wild.
In other words, with open source Google is on a more level playing field against potential attackers.
Think about what you're saying, you're saying Google is going to sit there and review all of the source code, and all patches and new releases to that source code. Really? Do you actually believe this...
As per China having the source, do you really think it matters? If someone wants to break in, they're going to get in... (regardless if its Windows/Linux/Mac) why... because that's their job and they are going to spend every minute of every day until they figure it out, and that's what makes them better than you. Majority of the time the issue is not software itself, but the policies in place. Hell, why even break in technically, when I can probably call one of these 10,000 employees up and they'll give me their password. Duh.
If you believe security is 1-dimensional, then you are bound to fail. History has shown this time and time again, just read a book / biography in regards to this topic.
Considering the difficulty of patching security holes in proprietary software versus patching holes in open software, Google indeed would hugely benefit by drastically reducing the difference between the cost of defense and the cost of cracking.
It's not so much levelling the playing field, as removing Harrison Bergeron's buckshot-filled equality harness.
[1] http://www.zdnet.com/blog/security/apple-fixes-old-java-for-... [2] http://www.dailytech.com/Charlie+Miller+to+Unveil+20+Zeroday... [3] http://en.wikipedia.org/wiki/Charlie_Miller_(security_resear... [4] http://www.forbes.com/forbes/2010/0412/technology-apple-hack...
It's not crazy to pay someone on their security teams to review checkins to OSS apps they use. Saying 'OH MY GOD' loudly and repetitively doesn't consitute an argument and is rude to the parent poster. Be civil.
Maybe not Google by itself, but the sum total of everyone reviewing all the source code and sharing what they know is that it's far easier to develop a more complete security profile for Linux than it is for a proprietary system we can only study by reverse engineering.
Meanwhile, most bugs aren't discovered in careful source code review or by static analysis tools. Instead, we write programs to exercise the code, either by sending random dumb buffers to the target or by working out the expected format and varying messages until we cover every basic block in the target. You can do this with or without any source code.
I think you would have a hard time finding a professional to say that they trust Mac OS X dramatically more than they trust WinAPI in 2010, and I say this as a full-time Mac user.
There aren't many mansions where I live, yet they seem to need the most security.
Software != hardware literally.
1> Very few Macs are running anti virus/spyware software, as the users generally believe their systems to be immune to malware
2> The malware authors are probably already targeting Windows, why not do Macs as well? The sites I work with are up to 25% Mac usage now. That is significant.
3> As Mac browsers have not been attacked as often and scrutinized as carefully by attackers, it appears Apple and other browser vendors have not taken as much care to harden the Mac browsers and OS.
4> Is having a Mac a weak financial signal? I wonder what data is there is out there about the affluence of the Mac-owning audience. Apple isn't targeting the low end of the market, that's for sure.
So, in summary: it might be relatively easy, plus, why not.
I answer: Because for the same amount of effort you can make an order of magnitude more money.
The same logic works out for normal ('voluntary') software applications, doesn't it? Most companies decide to focus their efforts on producing software for Windows, based on the idea that the market is much larger. Companies nevertheless do decide to produce software for Macs, for various reasons.
This is why homogeneity is dangerous. The more diversity an ecosystem has, the less vulnerable it is to viri, whether we're talking about crops or computer networks.
The reason was, to put it bluntly, that IIS was designed without any regard to real security, whereas Apache had _some_ regard to security.
That's also the case for Windows through its history; it has been making leaps recently, but doing things more securely requires it to become less convenient / not backwards compatible, and therefore it is still, relatively speaking, way more vulnerable when used by your average user.
I'm not up-to-date, but up until 2007 or so, a significant number of web browser vulnerabilities were directly or indirectly a result of Windows and Explorer's love of executing files after wrongly identifying them as e.g. wav or doc files.
The single Unix design decision that a file must have an executable flag out-of-band, and the convention that by default this flag is off, both of which date back to 1970, have kept Unix safe from these kinds of bugs. Sane default permissions on system directories are another decision; the latter has been adopted by Windows in XP SP2 IIRC, the former still hasn't.
There had been security audits of the apache code base since its early dates (as NCSA Web Server), whereas IIS didn't (or, judging from its track record, if it did have they were done by incompetents who didn't notice the strcpy(host_field, ...) would overflow with a host name > 1024 bytes.
IIS had everything in the same process, meaning every thing exploitable somewhere would bring the whole server with it. Apache used a worse-performing but better compartmentalized process-per-request model.
Just to be clear, apache at the time was NOT a beacon of security or good design or anything. But it did follow standard Unix practices, which put it a significantly better place than the IIS of the time (which was written like a Windows desktop program). At the time, IIS exploits were being found at a rate of 4 remote roots per month, with worms actively exploiting them, whereas apache had one of these every several months, usually only exploitable if you knew the exact O/S version it was running on.
For herd immunity to apply in this case, we'd be assuming that OS X users are more likely to take proper measures to ensure that their system is not compromised (which may or may not be the case).
Then again, Jeff Goldblum was able to write a virus on his Mac that he used to infect the alien mothership, so maybe they're not so secure after all...
Did Google roll their own Linux? Which kernel do you target? which apps?