Think Windows is insecure? You're wrong, says security firm Kaspersky.
blogs.computerworld.com
blogs.computerworld.com
From Windows 95 I was hooked on GUI's. I didn't like Microsoft but I liked Windows. I'd almost never care enough about Microsoft to say anything but when it came to Windows I always had an opinion I'd want to air and it was always in the spirit of wanting an improved product. Mac OS 9 felt like a joke and the various Linux distributions felt unfinished.
But eventually I changed to OS X when one of it's later "kitties" came out. Among my friends who have a Mac I'm pretty much the first to ever criticize Apple products but if you look at how much money I spend on the platform and how much time I invest learning about it you wouldn't think I was a critic. I don't have opinions about Windows beside wishing IE wasn't such a pain to design for.
Being critical does not equal being against something. When your critics no longer want to share their opinion of your product or service, that's when you should be truly scared. That is when you're in a really, really bad place.
Preston OTOH regularly writes critical MS articles, more often than he writes those that defend MS.
The author who refered to Preston as the equivalent of an MS PR firm doesn't know his history well.
My comment is merely meant as an insignificant resistance towards the uprising of the misunderstood reflector and doubter. Far too often are people promoting division with it's constant "us"-and-"them"-rhetoric and "Either you're with us or against us"-policy. It's healthy to doubt and question.
It's exactly how hacktivists such as Anonymous are alienated and how projects such as WikiLeaks is attempted to be criminalized. Whistleblowers are not the enemy nor the ones threatening the safety of the people.
This stuff is hard to pin down; for instance, there's a lot of hardening you can (but most people do not) do on Linux, and Lion changes the game on countermeasures for OS X. So it's a uniquely bad time to try to resolve this controversy decisively. But it's also hard to ignore the fact that much of what Lion is doing was pioneered in WinAPI.
(I'm an OS X user; also, I do systems software security).
Whether Windows (Vista+) is safer than Linux is up for debate. But safety and security are different concepts.
I did anti-terrorism in the military for awhile and I totally agree, but I would love to read the great tptacek's breakdown of the differences.
Imagine how much trouble could have been avoided if MS had used that model in the first place...!
The only problem is people refusing to upgrade from a decade old OS.
Also, we have several applications which, while they will run on Windows 7, they simply do not run well. From a business standpoint, it's really hard to justify an upgrade that results in reduced functionality in the name of security. I can clean up after malware pretty quickly - people working with outdated but business-critical applications lose hours of their days when software starts acting up because it wasn't written with a good security model in mind and it's being forced into that environment.
You can say Windows 7 solved the problem all you want, but there remain countless areas where Windows XP is required, and virtualization is not a magic bullet - networking is always tricky. And in any case, we do all that work of migration and what do we gain? Exactly what we have right now, except with hardware accelerated graphics that don't support all our hardware and some difficult to quantify reduction in malware attacks.
I'm not one of them, but I see them every day. Windows 7 does not solve the Windows XP problem. (The Windows XP problem will be solved when any given computer can run Windows 7 easily.)
The Android NDK is reliant on this - any application in Android can perform your arbitrary code execution, and it seems to be working out alright.
The Android thing works because you aren't just running arbitrary code, you are probably running code that you got from the Android Marketplace, which was probably screened to make sure it doesn't do something bad.
Also if you use sudo or su in X, they now have root thanks to the keylogger.
Security is hard.
I still see regular end users routinely made administrators of their computers for no good reason, or due to sloppy software (hello, Intuit).
Windows 7 is many orders more secure than OS X—just look at Pwn2Own, OS X is regularly the first to be eliminated.
Read this from the horse's mouth and see what you can infer from it. http://www.zdnet.com/blog/security/questions-for-pwn2own-hac...
http://www.macnn.com/articles/11/07/23/leapfrogs.windows.7.l...
In newer, less friendly but more tech oriented distros (these aren't opposing forces, but in Linux they're misunderstood to be) like Arch, a lot less.
Windows 7 especially does seem fairly safe and secure. The only time I've had a virus on my current computer is when I've actively downloaded files and run them without properly scanning them first (which is 100% my own fault of course; not a wise idea to download when rushing!)
I know some non-tech-savvy users who literally have 200+ programs installed and 3+ of those spammy toolbars on their IE installs. When you've got people who will download anything and everything they see, it's no surprise they get loads of viruses - and then blame Windows when thing go awry.
I agree that the architecture of Unix-based OSes is probably more secure than Windows 7 overall, although this doesn't mean that W7 is insecure.
This article is pointless imo, doesn't explain why is it any safer, only assumes it because some hacker HIRED by microsoft said so.
In most Linux distributions, the user is encouraged (by the design of the system) to, in almost all cases, either install cryptographically-signed software packages vetted and maintained by the vendor; or download a source package and compile it themselves. In Windows, the user is encouraged (by the design of the system) to download unsigned binaries from all over the Web and run them.
That's why I'll never consider Windows to be comparably secure to modern Linux distributions. Sure, you can keep a Windows system airtight, but the way the system is designed makes it require effort, so users, in general, don't.
curl get.pow.cx | sh
bash < <(curl -s https://rvm.beginrescueend.com/install/rvm)People want convenience over anything else. A computer has to be secure in spite of people downloading software from all over the web.
And considering the success of "app stores" and the general dislike of the traditional windows desktop computers by the general public (except if you are fool enough to help them for free doing all the busy work maintenance tasks that can't even exist on serious systems), I guess the centralized packaging and distribution model is also pretty convenient for the general public...
Yeah and so is everyone on XP, and there are a lot of them worldwide.
It would be like if I railed against Linux being usable by complaining about how bad the sound subsystem was...
This Usenix video from last year of Crispin Cowan going over improvements to Windows security was interesting:
I know that if a popup tells me I can get free cat screensavers at 'randomwebsitewitharandomname.com', it's most likely fake and might have a virus attached. I don't download it and my system is 'secure'. However, if I don't know it's fake (i.e., I'm not experienced with computers at all,) I might download it. Now my system is insecure. Whoopee.
You could say that a system is only secure if it can catch things like that before it's too late. The problem there is that Windows, like other OSes, does not come with any anti-virus program built into the system itself (I'm excluding security measures built into Windows as this doesn't fully protect it.) Windows is only secure from viruses when an antivirus program is used.
Of course, that doesn't make other systems safe. Just because Mac and GNU/Linux viruses are rare doesn't mean it's secure. This mentality is 'security by unpopularity'. The real argument is in how these systems would protect themselves from viruses that actually ran on them if those viruses were as prevalent as Windows viruses and the systems were used as much as Windows. On that, we can only speculate.
My point is that I'm only secure if I know what I'm doing; software is not built to replace common sense
That's an excellent and succinct statement of security; can I use that line?
When a machine gets compromised by just being connected to a network, that's pretty bad and I sure hope Windows 7 is a lot better.
Now, XP is first of all, not a great standard in security practices. But without any security updates, on a platform that hackers have had 10 years to find exploits to? If you installed that on an infected network, I'd be surprised if you didn't get compromised.
And I don't get why you're trying to justify this -- a fresh install should never get compromised by just being connected to a network.
Yes, I can install 10-year old versions of other operating systems just fine.
http://blogs.msdn.com/b/oldnewthing/archive/2007/03/30/19916...
I still think it's bad design b/c it fails to train the average user to avoid false privilege escalation dialog boxes.
1. Microsoft vendor says so.
2. Windows blogger says so.
3. Person *hired* by Microsoft says so.
That said, if Adobe can no longer say "hey, at least we're not as bad as the people who make the operating system", we may finally see some effort by them. More public shaming the better.Let us never forget that Microsoft Windows is responsible for, among much else, the transfer of critical trade secrets, diplomatic communications, and weapons technologies to our competitors and enemies. If China wins World War 3 in 50 years, Windows, albeit indirectly, will be significantly responsible.
Windows 7 may be more secure, but XP is still a major drain on society.
If you think Apple hardware is overpriced now, imagine if they didn't have any competition from Sony, Dell, HP, Acer, etc.
Back to your argument. Lets see:
http://www.nytimes.com/2011/06/02/technology/02google.html?p...
>She highlighted a fake document titled “Draft US-China Joint Statement” that was circulated among people with e-mail accounts at the State Department, the Defense Department, the Defense Intelligence Agency and Gmail. Clicking to download the document directed users instead to a fake Gmail log-in page that captured their passwords.
So that attack wouldn't have worked if the user was on an iPad or Droid or a Macbook Air or running the most hardened Linux computer. Right?
Zero days have been found in every browser/OS combo around. It's hard to see how OS X would fare better in a very targeted attack as Safari/OS X is usually one of the first to fall in PWN2OWN where the reward is a Macbook (not a win in a World War).
Stop getting your news only from places like Boyocott Novell, Groklaw,Slashdot, HN and the comments there. It warps your mind.
Almost every computer in China runs a pirated version of XP that can not be patched and is vulnerable and likely infected with some sort of botnet software. Many corporations and agencies in the US have been compromised in this way as well.