Or do you propose a solution that gives both freedom to the user while also not allowing something like this to happen?
Yes, there are whitelisting solutions (built into the OS by MS, btw), but they are a real pain in the ass to use - there's just too much stuff running on your machine at any given time.
I've thought about this for a while, and honestly, for desktops/notebooks/tablets? Yes. Maybe not just one App Store like iOS, but at least sandbox all possible non-os code similarly to ChromeOS, in a way that's on by default and requires a boot-time flag to disable (and users should be allowed to do this, but OEMs shouldn't.)
Recently my dad bought a new $300 toshiba laptop because his old machine was just "slow", as in he had so much spyware on his computer that it was easier to just buy a new one than going through the hassle of cleaning up his old one. Even though his old laptop was perfectly good and of a recent hardware generation.
I'm 100% positive he's going to have the same issues on his new laptop, and his response was that he uses his iPad so much that it doesn't matter anyway.
The role of the modern day OS has changed immensely over the years. Nowadays there's simply no reason for legitimate applications to have the level of access to the underlying system that they used to have. Apps really don't need arbitrary filesystem access. They don't need to be able to overwrite core system files. They should be run in a sandbox or a container with as restricted of a set of permissions as possible.
For servers and development workstations the story is a little bit different, but those are exceptions to the rule, and with the proper release hatches like boot-time enabling of un-sandboxed code it's a good tradeoff IMO.
Versign would by proxy, as one example. A certificate authorized to sign code was purchased from them. Samsung would directly, to prove that this shit software came from them.
Just like SSL/TLS. I could set up an SSL website that performs drive-by attacks, would Verisign sign that? Yes, yes they would.
Vericode isn't an gate keeper like Macs certificates are. It's designed to improve security: if I download a Samsung installer Windows will tell me that it is indeed from Samsung (during the UAC elevation) because the signature checks out. This means that I can be certain that unbeknownst malware won't be installed on my PC alongside the Samsung malware.
The story is different with WHDL (drivers), those are signed by Microsoft (in addition to yourself, I think).
Because the fact remains - computers have been a difficult thing for many people to use and maintain reliably. The "Windows has been historically shitty" point might be a reason this problem has been worse than it needed to, but it's hardly a compelling excuse.
When people—and not just Grandma—point out that their iPads don't have the same problem, then we should take that on board, rather than telling them that they're stupid for not listening.
And on Windows, this is the oldest trick in the book - in order to sell something people don't want, you first need to create the demand for it.
I don't understand. Why not just reinstall the operating system from blank media? If you get a new machine, you'll have to reinstall your user-applications and data anyway?
http://windows.microsoft.com/en-us/windows-8/create-reset-re...
As for the "it's not something most people know how to do": Buying a new computer also requires you to transfer files from the old to the new computer. And requires you to install your software. I'd say that both tasks aren't significantly harder to perform than clicking "next" on the Windows install dvd.
I'm hearing this argument from time to time. But I'd like to know what exactly changed. I can think of a dozen use-cases for which a shared, system-wide filesystem would be absolutely necessary (yes, especially with computer-illiterate friends and relatives, as "files" is pretty much the only abstraction besides "web" that is widely understood even outside of "geek"/"power user" circles).
So, what exactly has changed between then and now that made those use-cases legitimate in the bast but not anymore now?
Add the capability to do network communication and suddenly the all wolrd has access to $ HOME.
This is why in the container model of mobile OS and Windows/Mac OS X sandboxes, applications only get to see file handles to files choosen by the user.
Windows Update is a serious security requirement for any Windows install. Disabling it should clearly require explicit consent from the user.
That said, it's a difficult system to implement properly. Android went that route, and it almost works - almost. Android's available permissions are too plentiful, and yet certain permissions are too broad in scope. I wouldn't want a desktop application to have to ask for separate privileges for every little piece of functionality, but for certain critical actions it would be nice to have some clue as to what is going on.
Perhaps in another 20 years someone will finally invent a privilege escalation system that somehow manages to be both very specific and yet not time consuming for the customer to manage. What a dream. :)
Today, we have systems which are mostly single-user, but where the applications are incredibly untrustworthy. Hence the popularity of jails and app-store systems. You can't easily retrofit this on Windows because there is very little security between windows running on the same desktop, but what I think we'll end up with is each application having its own SID and a default-restricted view of the user profile.
But in this case it's a hostile OEM, and there really isn't much that can be done in software against that.
1. Right click on the taskbar.
2. Click "Startup".
3. Disable what you want.
4. Click "Services"
5. Disable what you want.
This omits "Scheduled Tasks" (cron jobs) which can be set to execute on user logon. This is the single one that Microsoft still need to address.
Does whichever operating system you are comparing to Windows have a one-top-shop for the vast majority of startup configuration? Of the "big 4" (Mac, Linux, BSD, Windows) as far as I know this is a unique feature.
Proof-of-point: I have a copy of Linux, without telling you what the distro is, tell me how to disable the firewall (just an example of background software on most Linux distros).
> no notification or authorization
Does that operating system of yours do this? Which of the "big 4" do? I know that Linux and BSD don't.
> Microsoft is responsible for allowing such software to run in the background
So Microsoft is responsible for everything every Microsoft-stack developer on earth does? Does that mean that RMS is responsible for closed source software because some of it is made with GCC?
This isn't comparing operating systems to operating systems. "Linux" could refer to a number of operating systems, such as Yellow Dog, Ubuntu and Fire OS. The Microsoft version of this question would be more like: "I have a copy of a Microsoft OS. Without telling you what version it is, tell me how to disable the firewall."
Google has a similar problem with Android. They solved it by having anyone who wants to include Google services to fall into line.
Apple goes to extremes on iOS to prevent things like this.