Chrome and Windows Exploit: Security Beyond Bug Fixes
alexgaynor.net
alexgaynor.net
Using a ten year old operating system just isn't justifiable in today's threat environment. Use Windows 10 or switch to Mac or Linux.
Only if "fewer known bugs" means "more secure".
I mean...
I'm sorry you find it irritating. The fact remains that we have experienced far more downtime due to Microsoft than due to malicious attackers, consistently, over many years now. Moreover, the only actual data loss we have experienced was also due to Microsoft, and the only attempted data exfiltration that we have detected has been due to software telemetry, with by far the worst offender being Microsoft.
Microsoft's behaviour in trying to promote an OS that forces updates even if they are broken, forces reboots even if you're in the middle of a long job, and requires uploading any sort of data of any kind to Microsoft without your meaningful consent is literally indistinguishable from malware. On an objective risk analysis, based on consistent patterns of actual behaviour over an extended period and known information about the behaviour of and intent behind Windows 10, I'll take my ten-year-old OS (where, by the way, we still have the option to not install either telemetry or non-security updates) over your antifeature-laden junk any day.
If you think I'm being unreasonable here, ask yourself why Windows 10 Enterprise doesn't require any of those antifeatures to be used.
From my personal experience, almost all of Windows 10's annoyances are relatively trivial to manage in a domain environment (if you've ever had a forced reboot on a domain, you just don't know how to manage a domain, Enterprise licensing is not required to manage updates fully) and I would say our overall system stability has gone up probably tenfold since shifting to a fully Windows 10 environment, alongside switching to solid state drives.
Small businesses and independent professionals typically don't have that option. This is the traditional market for Pro editions of Windows, but unlike previous versions, Windows 10 Pro is more like Windows 10 Home plus a bit than Windows 10 Enterprise minus a bit.
If Microsoft released a version of Windows 10 Pro that was actually aimed at professionals and treated us as such, we'd have no problem upgrading. As long as Microsoft presumes to have more control of our equipment than us, we'll continue with our programme of phasing out Windows and migrating to other platforms wherever possible.
The technical improvements in 10 are not in dispute, but the analogy of making a house perfectly secure by removing all the doors and windows comes to mind.
Also, note that I do maintain an environment with Pro licensing, not Enterprise. So I am both aware of the limitations, and the steps needed to mitigate them.
If you know how to mitigate the antifeatures like forced updates, reboots and telemetry in Windows 10 Pro in a supported and future-proof way, please share. I'm sure a lot of people would like to know!
And no, for those with massive Steam libraries and other Windows only software "just switch to Linux/Mac" isn't a viable or acceptable alternative.
Also, a surprisingly large percentage of your Steam library will work on Linux. And you can always use a VM for those that don't.
Straw-manning arguments does not make your case more convincing. Trying to make NT10 a reasonable platform (rip out the dumb preloaded junk, neuter most of the spyware, make updates give the user some choice in when they're applied) takes a massive amount of effort and is a constant game of cat-and-mouse against MS.
It is / was an extremely popular game, they probably figured:
* We can make some money
* Users love this garbage anyways
I haven't been a Windows user for years, but Windows 10 looks fairly impressive - especially from a security standpoint.
As for updates force rebooting, they only do so during designated non-active hours, which I set from 2AM to 5AM and leave my laptop on. By the next morning, its updated and ready to use.
One thing I don't like about 10 is how updates tend to uninstall my hardware manufacturer's drivers and replace them with vanilla Windows ones and I have to go through the tedious process of re-installing them. Happens most often with webcam and sound drivers.
Oh, and I don't use any hack software like ShutUp10 etc. This is just stock Windows.
This presumes that any hours can reasonably be designated non-active. For some professionals, and for that matter some home users if they work shifts or the like, that simply won't be the case.
Is windows cable tv?
But I have 4 Windows 10 PCs in my house and dozens at work and I never had this problem. I see people on HN complaining about it every time a story about Windows 10 comes up though.
It's not a complaint that I've ever heard in real life either, ever, from anyone that I know that uses Windows 10 (that's a ton of people at my company.) It's also not a complaint that I hear outside of this kind of tech circle online very much.
I wonder if people who "know what they're doing" with computers take some drastic unnecessary action in Windows 10 that causes this problem?
I don't care about the App Store, I just want the security updates with stable features.
I did a job for a small (5 employee) tax/accounting firm that paid us to disable windows update on all of their windows 7 machines to avoid the windows 10 update after it brought down their entire office on a february monday by updating overnight.
I asked him about upgrading to enterprise versions of windows so things like that can't happen while still having updates, and his response was "I shouldn't have to pay microsoft more to gain control over my machine, so I'd rather pay you more to remove their control."
He's not wrong, neither are you. So the question becomes, who should give way? The user? or the corporation?
As far as I know, he is still on update disabled windows 7 for his office.
Users don't care about security, they care about usability, and when security gets in the way, users will bypass it, even if it means paying somebody to bypass it for them.
The current trend is to solve this by making security unbypassable by the device owner, but thats not sustainable, nor is it ethical.
Ideally we'd move away from the situation where these are the only choices. This could happen in many ways: Some new runtime which is not platform-dependent and becomes popular. (maybe even dotnet core + gui?) Software vendors getting more interested in macs. ReactOS becoming stable/popular enough for office environments.
The current situation is broken. Either side giving way is a "meh" solution for the current situation.
Where real incentives are in the "they'll be fined" or "users have better choices" categories mostly.
For the above reasons, Windows 10 is not secure enough for me. I still use windows 7 and have not experienced any security issues. Windows 10 has the potential to be more secure, but sadly MS choses to treat its users with contempt.
But that's a bit of a mouthful.