Sunday, May 03, 2009

Busting your Bubble: Security is on the rise...

...perhaps because us niche Geeks are demanding it.

In a quiet and understated expose my long time Internet friend and verbal jousting opponent, Mr. Steven Hodson, in his rambling diatribe, Whining about a secure Windows, took me to task for asking "Why?" Why we can't get a secure copy of Windows XP.

He states and I agreed that Microsoft has provided a product for 'Joe Average' who "... just want[s] to be able to turn on the machine and do their stuff." Security down through the Windows ages, says the Crankster, ...

wasn’t high on anyone’s priority list.

Microsoft paid heavily for this and continues to pay for it to this day. Unfortunately though Microsoft suffered from another major problem – it was too popular. While it may have had made billions from this popularity they did it by appealing to everyone and their proverbial brother. They weren’t in the market to cater to niche type users.

Yeah, well, I guess I am just a niche guy looking for a secure OS. Now, here is the rub - as the Cranky Old Fart was so very gracious to point out - I am a network administrator. I am the guy that people call when their instance of Windows XP doesn't allow them to blithely "do their thing and not worry about all that ‘other stuff’."

I am the 'Computer Police'. I am the policy enforcer who has to employ all the cobbled together bits and after-thought pieces that Microsoft finally acknowledged as necessary security "fixes". And yes, my 'Joe&Jane Average' users complain mightily when they encounter the cold hard edges of Administrator imposed limits. But you should hear how LOUD they complain when their WinXP won't allow them to work at all because of some "harmless" visit to You2CanWinMillions.com.

I do not disagree that the majority of Windows XP users just want to be able to turn on their PC and do what ever they do without having to jump through a huge number of hoops. I do not however believe that just because the average user has no more PC savvy than the plastic mouse they so delicately fondle while surfing God know where that this is a valid excuse for knowingly fielding the height of OS mediocrity.

Now, lets take a brief moment to check in on some 'average' friends of mine, XP users. On average their PC is delivered to Dave-the-PC-Guy three times a year for a Format-n-Reload. Why? Because my friends Jim&Jill Average are the typical users you described. AND... Microsoft Windows XP is sooooo vulnerable - UNLESS - you jump through all.those.freaking.pesky.hoops.

Yeah, I am the niche guy complaining loudly about security. Yeah, I am the niche guy who adopted Slackware Linux early. Yeah, I am the niche guy who has to worry about all the issues that Joe&Jane and Jim&Jill just simply ignore. Yeah, and then I read the last paragraph of the article that I quoted from earlier about the USAF...
Gilligan also said that he hopes that this project marks the beginning of the end of companies arrogantly resisting locking down their products. "They're still in the model that they want to give all the features enabled to clients," he said, "But I think we've reached a point where that model is one that is no longer effective. I'm of the opinion that all products ought to be configured with these locked-down configurations, and if the customer decides they want to undo them, then they can do that. They cannot continue fielding products where the cost that is being borne by the consumer in terms of having to maintain configurations and deal with attacks is so high." [Link to original article.]


P.S. Related Article

MCRC Blog - 2009

Apr 22, 2009

How a cybergang operates a network of 1.9 million infected computers

Today we announced our recent discovery of a network of 1.9 million infected computers controlled by cybercriminals. This is one of the largest bot networks controlled by a single team of cybercriminals (or cybergang) that we found this year. In this blog post we will provide you with additional details about this network, the malware in use and how the operators are using it to make money – after all, this is the main drive for cybercrime today.


Yeah, 1.9 million infected computers running Microsoft OSs.

No comments:

Post a Comment

. . .