Bruce Schneier Joins Startup Co3 Systems
threatpost.com
threatpost.com
I suppose it's good to bear in mind that Schneier now has a dog in the race any time he writes about incident response. But then, he had one about managed security services while he worked at Counterpane and BT. It didn't seem to impact his writing much.
As far as I know, Schneier remains a fellow at Berkman at Harvard, which is presumably where most of the stuff he does that is actually interesting will be done.
(I worked with and very much some other people on the management team at Co3 in a previous life; I've got nothing bad to say about it, just some perspective.)
(Keep in mind a break-in doesn't have to have been targeted specifically at you to cause damage or to be classified as a break-in.)
45% of all retail companies DETECTED at least one serious information systems breach in 2013. (Many more would have experienced a breach without knowing.)
According to Trustwave's 2013 Global Security Report, the top 5 most breached industries are 1. Retail 2. Food & Beverage 3. Hospitality 4. Financial Services and 5 Non-Profits, followed by High-Tech.
The Trustwave report doesn't break things down by company size. But you can be sure that large retail companies (Macy's, GoDaddy, Microsoft, Goodyear, Betty Crocker, etc) have many many incident response teams who follow up on multiple incidents each day. Most aren't serious, of course. But they all need to be handled thoroughly because one mishandled serious breach is all it takes to cost a company as much as hundreds of millions of dollars in damages.
A quick LinkedIn search shows 150,000 people working in incident response positions in the U.S. A good bit of those work for incident response service providers like Mandiant https://www.mandiant.com/services/incident-response/ Most companies under ~300 employees aren't going to have in-house IR teams (many do though). They'll hire companies like Mandiant to respond to serious incidents while letting insurance handle the less serious incidents.
This is not to excuse Microsoft, they could certainly do better. But so could Apple and Debian.
I think there's a lot to be said for those who practice what they preach rather than sticking with a lesser option out of convenience.
I'd suggest that by using a platform that he knows how to make secure rather than one he's unfamiliar with, he is acting in the best way to ensure the security of his device.
Against the US? I doubt it. Countries sometimes fail to treat actual armed intrusions without local consent by the US as casus belli because of the imbalance in military power, and you want me to believe that there are "a lot" of countries that will treat a backdoor in Windows as an excuse for war?
The second suggestion being they (the NSA) have a (likely lengthy) list of exploits found in common OSes (and/or firmware or CPU microcode) that they have never divulged and that they have discovered like any external security research would have (albeit one with a very large budget and a very strong incentive to find such control vectors).
I prefer to assume that both are true.
Also there are very good reasons for using windows - dogfooding your own security solutions, fact that a lot of threats are targeting windows machines and the fact that he is not a high profile target (or wasn't before the NSA stuff) so no one will waste undisclosed zero day on him.