6 ms·
Lets be honest about the problem and this isn't some slashdot-esque rant: a) Windows is a piece of crap when it comes to staying clean. If it wasn't, Microsoft
by pling 12y ago
Lets be honest about the problem and this isn't some slashdot-esque rant:
a) Windows is a piece of crap when it comes to staying clean. If it wasn't, Microsoft wouldn't have to go after people like this. Not joking but I clean out a fair number of PCs every year and they are crawling with malware.
b) Users are dumb and install any old crap on kit if prompted to. Microsoft's SmartScreen did very little to prevent this.
In the fallout from this, people are getting hurt. End users are getting their PCs and data stuffed and companies like this lose their reputation and business because they are a convenient mule (as are the end users) for malware pushers who's job has been made easy.
And don't give me the crap about probability based on the sheer number of windows machines or the plain bullshit security statistics. They're a pretty easy target as the architecture of Windows is incredibly complicated and they're playing plug the holes rather than designing it properly to start with. For ref, I know the NT kernel, win32 and CLR inside out and no longer would I poke it with a stick.
So, there's nothing here that's unique to no-ip.com's case. The problem is that Microsoft spewed out crap for years and people are suffering because the only way they can contain it is to scorch the earth.
- wfjackson 12y ago>They're a pretty easy target as the architecture of Windows is incredibly complicated and they're playing plug the holes rather than designing it properly to start with. For ref, I know the NT kernel, win32 and CLR inside out and no longer would I poke it with a stick. Not sure what you mean by that. Does Linux have any protections beyond Windows to stop malware? Why does Android have a malware problem? This is the text of a post I made yesterday in reply to a similar comment: How can they patch it in their product without turning desktop Windows into something like iOS or Windows Phone/RT? Even Android has a ton of malware so the notion that Windows is somehow more hole ridden than other platforms stopped being true starting about 10 years ago with their Secure computing initiative. If the user can install Firefox, they can install malware. If Firefox doesn't need to get permission from MS for their next version, Windows cannot distinguish between Firefox.exe and Codec_Flash_Shady.exe. Sandboxing will disable system level utilities. MS is capable of making secure OSes. How many viruses and trojans do the 3 Xboxes, Windows Phone and RT have? Even Windows Server is pretty secure(atleast as secure as Linux) unless the admins start browsing on it. Malware is a real threat to any popular OS unless third party apps are entirely blocked or restricted by the use of a approval based App Store. Windows gives much more control to the user, which is why many users are able to stay away from infections. And it's ironic that you're blaming MS here instead of the folks that propagate it(including a YC company https://www.techdirt.com/articles/20130115/17343321692/why-are-y-combinator-andreessen-horowitz-backing-drive-by-toolbaradware-installer.shtml https://www.techdirt.com/articles/20130115/17343321692/why-a...) and people who install it(users). Remember the shitstorm that was raised against MS on here and elsewhere when they tried to secure users by preventing undetectable rootkits by enabling Secure Boot?
- Someone1234 12y ago> Not sure what you mean by that. Does Linux have any protections beyond Windows to stop malware? Why does Android have a malware problem? This is the key question that I'd like to hear the answer to. People often claim Linux/OS X/et al are more secure but they struggle to explain WHY. What technical mechanism is in place in those systems that is not in place in [current] Windows? A few years ago you could definitely name a few things (i.e. before UAC, and a few other things) but now? I'm certain something like SELinux or AppArmor makes for a more secure system, but last time I installed a consumer distro (namely Mint and Ubuntu) they weren't shipped as standard and often broke quite a lot of default packages upon their installation. As an aside: In my experience Windows has become less "malware ridden" since XP. Vista, 7, and 8 often survive much longer without anything bad happening. It does still happen, it just isn't as common as it used to be (e.g. 1/5 consumer PCs now instead of 3/5 or more).
- okasaki 12y agoUbuntu ships with AppArmor enabled. Fedora ships with SELinux. It's been that way for a long time. Other distributions like Arch come with packages for other frameworks, including grsecurity. But I think the primary "technical mechanism" that makes Linux more secure is the fact that users install software from distribution repositories, rather than from the web. The repos are basically impenetrable since packages are signed and contributor identities confirmed with WoT (I've never heard of there being malware in a major distribution) and security updates are deployed to everybody very quickly.
- wfjackson 12y ago>I've never heard of there being malware in a major distribution Not much to stop malware if desktop linux becomes more popular. http://www.zdnet.com/blog/hardware/how-much-more-malware-is-lurking-in-linux-official-repositories/8615 http://www.zdnet.com/blog/hardware/how-much-more-malware-is-...
- BitMastro 12y agoI'll give it a try: privilege separation and permission since the beginning only super user was allowed to install new software (simplifying) different distros and different versions created diversity making it difficult for an attack area to be widespread across all installations typing a password for additional privileges requires more attention than clicking a button apparmor has been enabled by default since a couple of years, it used to break some stuff but not anymore (simplifying) new files are not executable, and they don't rely on extensions to determine the associated program since linux is not the default it requires a learning curve that people using windows don't have, so users are more tech savvy since the source code is available, more people COULD have a look at security vulnerabilities, and in case of emergency the don't have to wait for someone else to provide a patched binary That said, I don't consider security on windows to be a disaster. It certainly is improving and in general they also pay a lot more attention to security.
- bagosm 12y agoThis reminds me of a friend of mine: "But mom! Why did you 'sudo sh LOVE-LETTER-FOR-YOU.txt.sh' in the first place? Didn't I tell you not to trust email?". Security's no1 problem is the user.
- pjmlp 12y ago> Windows is a piece of crap when it comes to staying clean. All operating systems at the face of the earth are a piece of crap when the users have admin rights and install every piece of sXXt they can put their hands on. There isn't a single one that does it better.
- anon1385 12y ago>Windows is a piece of crap when it comes to staying clean. If it wasn't, Microsoft wouldn't have to go after people like this. It doesn't help that Google is making money from infecting their users with malware. It's basically impossible for people to find popular Windows software though Google without begin directed to malware. For example if you do a Google search for 'firefox', usually the top result (actually an ad) , will be a link to a site that downloads a copy of Firefox bundled with malware. This is from a search I did a few moments ago: http://i.imgur.com/lzKU3FO.png http://i.imgur.com/lzKU3FO.png It would be trivial for Google to block these malware sites and Adwords accounts - a lot of the ads that show up look to be pointing to the same sites as they were 6 months ago. Adwords has manual review of ads and the sites they link to. There is just no way that they don't know about these heavily profitable Adwords accounts that are running on hugely popular keywords. This isn't a new problem, I've mentioned it time and time again: https://news.ycombinator.com/item?id=7101939 https://news.ycombinator.com/item?id=7101939 , https://news.ycombinator.com/item?id=7335401 https://news.ycombinator.com/item?id=7335401 , https://news.ycombinator.com/item?id=7089727 https://news.ycombinator.com/item?id=7089727
- pling 12y agoThat's a pretty scary thing really when you think about it. Thanks for outlining it. Good job I stick adblock on every machine I ship so these things don't even get seen.