Slashdot Mirror


Windows vs Mac Security

sdhorne writes "There is a good technical discussion over at InfoWorld on the merits of launchd and what is lacking in a comparable Windows secure solution. It is a throw back to the UNIX vs Windows security discussion that has been hashed out for many years." From the article: "it always traces back to Microsoft's untenable policy of maintaining gaps in Windows security to avoid competing with 3rd party vendors and certified partners. Apple's taking a different approach: What users need is in the box: Anti-virus, anti-spam, encryption, image backup and restore, offsite safe storage through .Mac, and launchd. Pretty soon any debate with Microsoft over security can be ended in one round when Apple stands up, says 'launchd', and sits back down."

23 of 513 comments (clear)

  1. slashdot this by RichMan · · Score: 4, Interesting

    Anyone notice the link at the bottom of the article?

    Links to slashdot submit article. http://slashdot.org/submit.pl

    Cute.

  2. Re:Well written, but by ackthpt · · Score: 4, Interesting

    I don't know if I'd go that far. OSX isn't 100% immune - it just has more common sense.

    In a nutshell, OS-X is built upon a known animal, whereas Windows is an animal which continues to be re-invented, like a leopard changing its spots to stripes, then plaid, then paisley, then something else. With such moving targets all the time it's small wonder they've got security issues. Some begin to be addressed with good programming practices (which Apple could certainly lapse at at any moment, and may well have and we haven't heard about) Another is to require tight control over interfaces between code from different departments. Microsoft going back to scratch time and again doesn't necessarily mean anything is getting better.

    --

    A feeling of having made the same mistake before: Deja Foobar
  3. UNIX and viruses by rice_burners_suck · · Score: 5, Interesting
    Viruses are definitely part of the umbrella concept we often call "security." I've heard it mentioned many times that Macs do not suffer from viruses because they have a smaller market share, and virus authors invest their time into attacking more dominant systems. People who say this generally go on to say that as the Mac gains a larger market share, the number of viruses available for it will grow. I think this is of little consequence.

    Macs are based on UNIX. It's not faked to appear like UNIX, it is actually UNIX. The permissions system means that a common virus could damage a user's home directory, but the system for the most part would remain unaffected, including other users. It is still possible to write root-kit style viruses that take advantages of subtle bugs in the operating system and other software to gain control of the system, but this is significantly more complicated to do, and IIRC it was Theo from the OpenBSD project who said that attacks like this require many steps that often must take advantage of many vulnerabilities to elevate priviledges, and by fixing even one bug, a whole category of vulnerabilities (even if other bugs remain) becomes inaccessible to a would-be attacker. This, in addition to much of the code underlying OS X being available for hacking up by anybody, in addition to other projects actually hacking on this code (improvements from projects like Samba, Apache, GCC, FreeBSD, even various Linux projects, make it into Darwin and OS X.... and most of all the fact that users don't run as administrators, all of these reasons make it much less likely that viruses could be as damaging as on Windows.

  4. This is MS-FUD no doubt by Anonymous Coward · · Score: 3, Interesting

    >[...]it always traces back to Microsoft's untenable policy of maintaining gaps in Windows security to avoid competing with 3rd party vendors and certified partners.[...]

    What bizarro-universe is the writer living in to write something so patently false?

    Microsoft's Standard Operational Procedure is to wait-and-see which niche is picking up enough importance (and we all agree security is a major one this decade, right?) and then cutting off that vendor(s) oxygen by coming up with their own "superior" (guffaw) solution which MS gives away for free, next to nothing or by marrying it to some essential O.S. component.

    Another piece of Microsoft-propaganda no doubt.

    Sell it elsewhere, chum. I'm not interested in reading anything else you've written if this quote is representative of the drivel you are putting forth. Thank you.

  5. the article may have some good points, but... by Anonymous Coward · · Score: 5, Interesting
    I have to take it with a large rock of salt when I see
    OS X has no user account with privileges exceeding root.

    being offered as a "reason why OS X is more secure than Windows."

    The article claims that Administrator on Windows is equivalent to root; and that SYSTEM is more powerful than Administrator (and by implication more powerful than root). This is nonsense.

    Administrator is indeed less powerful than SYSTEM. However, Administrator is equivalent to a user on the sudoers list and/or with group write access to system directories. SYSTEM is the correct equivalent to root.

    We may quibble about how well Administrator accounts are protected from trojans; or whether non-Administrator accounts on Windows are of much use; those are valid arguments. However, claiming that, somehow, SYSTEM on Windows is magically more capable than root is ridiculous.

    If anything, Windows has a somewhat better design in that it is possible to set up privileged accounts with a specific power that only root has on UNIX, yet not have any of the other root powers. However, this capability is quite underutilized, and in many ways is undermined by other (unfortunate) decisions that Microsoft made.
    1. Re:the article may have some good points, but... by 99BottlesOfBeerInMyF · · Score: 4, Interesting

      If anything, Windows has a somewhat better design in that it is possible to set up privileged accounts with a specific power that only root has on UNIX, yet not have any of the other root powers.

      I don't want to quibble about nomenclature and real differences between security layers or accounts or whatever between platforms, but I think you're a little mistaken here. One of the reasons LaunchD is being applauded in this article is because it allows you to run a given process with very specific permissions without going to hassle of trying to create a special user account and while also integrating the scheduling and resource allocation in one, nice, neat, hopefully secure package. It obviates the need for straining the "user" metaphor as is so common. I don't exactly think it is really appropriate to claim it as the security benefactor, however, when what we're really talking about is that services aren't written to require unneeded permissions as much as on Windows.

  6. Re:But what if Microsoft offered it all together? by CastrTroy · · Score: 5, Interesting

    It depends on how they offered it. If they made it impossible to uninstall, then yes, we would yell monopoly. However, if they made these features able to be uninstalled (or never installed in the first place) and easily replaced by third party tools, then I don't think we would have anything to complain about. I don't have any problems with MS including IE with the operating system, I just wish it could be removed from the system.

    --

    Anthropic principle: We see the universe the way it is because if it were different we would not be here to see it.
  7. Interoperability is a threat by 140Mandak262Jamuna · · Score: 4, Interesting
    When you own 90% of the market, not being interoperable with others is a commercial advantage. Yes, security is compromised, but it (MS) has trained corporations and individuals it is THEIR (I mean user's) responsibility to install and update "critical" security updates and install firewalls and antivirus software and keep them up to date. Now MS is going to sell anti-virus products. It is going to profit from the shoddiness of its own product. It is a great scam if you can get into it.

    As long as corporations confuse interoperability with "windows compatibility" the scam will go on. Only when the commercial user who forks over billions of dollars to MS every year demand true interoperability and injects real competition, it will end. There is no advantage in being the first among the users pushing for it. Pepsi will not care as long as Coke is also spending relatively the same amount of money for similar services. But someday somewhere some corp will bite the bullet and spend what it takes to break the vendor-lock in, and only after that the security situation will improve.

    --
    sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
  8. Re:in fairness to microsoft by MECC · · Score: 3, Interesting

    Maybe with apple incorporating it they have the green light to go ahead with it.

    Apple doesn't incorporate anti-virus/anti-malware into their OS. They incorporated good security, and made good use of it.

    MS could easily do the same even more with their more featurefull security model, if they wanted to, without incorporating any anti-virus/anti-malware into their operating system. Odd that instead of fixing their security problems, they just opted to compete with anti-virus/anti-malware vendors.

    --
    "We are all geniuses when we dream"
    - E.M. Cioran
  9. Re:Well written, but by ackthpt · · Score: 5, Interesting

    I'm not sure that 're-invented' is how I'd describe windows, or their efforts at security.

    In the past Microsoft have commented that they have completely ditched the code Windows was written with and re-written from ground up, to try to address myriad flaws. That's pretty drastic. I've done it with small projects which simply grew too large and unwieldy because they were never expected to scale to newer demands* Microsoft is effectively doing this with Vista and yet... there still appear to be security flaws. Something wrong with that picture. Could be they're just a victim of their success and such a massive undertaking of code is approaching the event horizon just before the black hole.

    *You know the type.. you develop some nifty little tool to summarise information for your own use and someone sees it and says, "Hey! That thing does in seconds what I spend a week doing! I need it, set me up with it!" Next thing you know your little tool has to be user friendly, go to printers, be in colour, etc. Continually piling in changes makes it fragile so you step back, figure what it all needs to do and how to achieve the goals and then recode, with an eye toward more scalibility and unforeseen features later.

    --

    A feeling of having made the same mistake before: Deja Foobar
  10. Re:But what if Microsoft offered it all together? by Gryffin · · Score: 4, Interesting
    Apple's taking a different approach: What users need is in the box: Anti-virus, anti-spam, encryption, image backup and restore, offsite safe storage through.
    Don't you think that if Microsoft offered this that everyone would cry monopoly?

    Microsoft has been declared a monopoly in Federal court, and found guilty of anti-trust offenses related to abusing that monopoly in violation of the Sherman Anti-Trust Act.

    Apple, on the other hand, is not a monopoly, and hence it would be perfectly legal for them to bundle anything they damn well felt like bundling.

    Why is this so difficult to understand? Microsoft, because of their market position, is held to a different legal standard. End of story.

    --
    Learn from the mistakes of others. You won't live long enough to make them all yourself.
  11. Re:But what if Microsoft offered it all together? by KillerDeathRobot · · Score: 4, Interesting

    Why is this so difficult to understand? Microsoft, because of their market position, is held to a different legal standard. End of story.

    It's not difficult to understand; it's annoying because it's the wrong argument, and it really muddies the debate. We don't need to hold Microsoft and Apple to different standards to show that one is better than the other. There is nothing wrong with MS bundling software with their OS. What was wrong was that they were forcing companies like Dell NOT to include competing software (such as Netscape).

    It's a moot point any way though, because in this case we aren't even talking about the right thing. As someone else mentioned, we're talking about a system that is built to resist viruses and such, not virus scanning software bundled with the OS.

    --
    Thinkin' Lincoln - a web comic of presidential proportions
  12. Re:But what if Microsoft offered it all together? by Overly+Critical+Guy · · Score: 4, Interesting

    I haven't seen anyone cry "monopoly" over that. I've just seen people cry that Microsoft is selling services to fix problems in its own OS, like with OneCare, instead of fixing the problems in Windows to begin with. And guess what, despite Vista's security enhancements, it's still based on Win32, still based on a registry, and is basically just a bunch of new APIs and rewritten subsystems on top of the same old code.

    Also, there's a difference since in the Apple world, there isn't an antivirus or antispyware market, but in the Windows world, there is a huge market that's been around for over a decade, so it's a big deal when Microsoft starts bundling its own versions of these services.

    For the record, OS X ships with no antivirus software. Not needed.

    --
    "Sufferin' succotash."
  13. Microsoft wouldn't need to offer it all together by BearRanger · · Score: 3, Interesting

    ...if Windows were designed securely in the first place. This isn't a troll, just an observation.

    In a sense everyone is trying to argue that Microsoft can't include additional security tools because they'd be accused of leveraging their monopoly. The enitire antivirus industry likely wouldn't exist, and this would be a moot point, if Windows were designed securely from the start.

    What we seem to have now is pressure on Microsoft not to make things *too* much better because they would wipe out a lucrative business niche occupied by third parties. Microsoft is a slave to backwards compatibility, so they won't scrap everything and start from scratch. But they can't win because if they offer an antivirus solution they're leveraging their monopoly unfairly. Or they're an extortionist because they failed to secure Windows properly, but are getting more money from customers by forcing them to purchase their anti-malware solution.

    OSX is better than Windows in terms of security. But Microsoft only have themselves to blame. They should break with backwards compatibility, buy themselves and Linux distro and layer the Windows GUI and APIs on top of it. Do it right and their security problems will be a thing of the past.

  14. Re:But what if Microsoft offered it all together? by LWATCDR · · Score: 3, Interesting

    The guy that wrote the article didn't get it.
    It has nothing to do with Microsoft not offering anti-virus, anti-spam, encryption....
    The problem has everything to do with Microsoft having to keep backwards compatibility!
    Windows wasn't designed to be used on a totally open network. It was meant to be a single user OS that ended up being used as a server and then being hung on an insecure network we call the Internet.
    Running windows with less than administrator rights is a pain.
    Installing software without administrator rights is impossible.

    The problem with Windows security is the same problem that Microsoft has with IE7 not following standards.
    They refuse to give up on backwards compatibility to fix fundamental flaws.

    The reason that people keep using Windows is because their old software works. That is Microsoft's big advantage in the market place. They are not going to loose that to fix security issues.

    --
    See my blog http://ilovecookes.blogspot.com/ for light hearted technical information.
  15. Re:Well written, but by Buran · · Score: 5, Interesting

    But at the same time Apple gets applauded for rolling EVERY SINGLE LITTLE POSSIBLE THING into their OS?

    Because they don't force you to use any of it. You can delete any of the utilities that you want. Don't want ichat? Trash it.

    On the other hand, good luck getting rid of Windows Messenger. It's even hidden in Add/Remove Programs and fixing that requires a hack well beyond most users.

    Don't want to use Safari? Make it go poof.

    On the other hand, you CANNOT get rid of Internet Explorer. And that's bad. IE is full of security holes and you can't get rid of it. Safari is far safer, and you can get rid of it.

    What hypocrisy was that, again? There's a damn good reason MS gets blasted and Apple doesn't. (Well, it does, but nowhere near as much, and I just explained why.)

  16. Re:But what if Microsoft offered it all together? by soft_guy · · Score: 3, Interesting

    How many times has this happened? Once. And as soon as Bush got in, he ordered DOJ to fall on their sword and they did. Microsoft can get away with pretty much anything they want.

    --
    Avoid Missing Ball for High Score
  17. Total crap by jiushao · · Score: 3, Interesting

    It is not that hard to argue for OSX security over Windows security due to the track-records, but this article is total crap. A few of the points:

    • All Windows background processes/daemons are spawned from a single hyper-privileged process and referred to as services.: Right, just like how OSX daemons are launched by launchd, what is the point here?
    • By default, Windows launches all services with SYSTEM-level privileges: This is plain false, you have to give a user account that the service should run as, and at that point the extremely comprehensive NT security model kicks in.
    • SYSTEM is a pseudo-user (LocalSystem) that trumps Administrator (like UNIX's root) in privileges. SYSTEM cannot be used to log in, but it also has no password, no login script, no shell and no environment, therefore the activity of SYSTEM is next to impossible to control or log: Right. I don't see the problem. This is akin to the classic "you should not always run as root", it is counter-intuitive to people used to the UNIX security model of course, but it is not by any means a bad idea. There is no reason to have ridicolously powerful login accounts when such priviliges are better brokered by daemons. If needed you can of course still elevate the permissions though, but it should not be needed.
    • Windows buries most privileged software, service executables and configuration files in a single, unstructured massive directory (SYSTEM32) that is frequently used by third parties. Windows will notify you on an attempt to overwrite one of its own system files stored here, but does not try to protect privileged software: This is an odd complaint, of course the NT security model applies to system32, set any permissions you feel like. Massive usntructured directory? In comparison to the fine old let's-dump-it-in-/usr UNIX tradition? :)
    • Microsoft does not sign or document the name and purpose of the files it places in SYSTEM32: Right click on any dll/exe in system32, click properties, click version and you get a short description of what the file is for.
    • Windows requires extraordinary effort to extract the path to, and the files and TCP/UDP ports opened by, running services, and to certify that they are valid: Granted the builtin stuff is weak, which is why every sane Windows user quickly downloads Process Explorer (recently bought by Microsoft actually, keep your fingers crossed that it becomes standard). At any rate, pretending that this is an inherent property of the operating system is plain wrong.
    • Access to the massive, arcane, nearly unstructured, non-human-readable Windows Registry, which was to be obsolete by now, remains the only resource a Windows attacker needs to analyze and control a Windows system: Massive sure. "Arcane"? How so? Seems quite similar to Mac plists actually. "Nearly unstructured"? This is just bullshit, it is extremely well-structured. "non-human-readable"? Well, use regedit, not unlike needing a utility to read binary property lists on Mac. The core of the complain appears to be "if we hide settings all over the place they'll be hard to find for the bad people!" which is the worst attempt at security-through-obscurity I have ever heard.
    • Another trick that attackers learned from Microsoft is that Registry entries can be made read-only even to the Administrator, so you can find an exploit and be blocked from disarming it and Malicious code or data can be concealed in NTFS files' secondary streams. These are similar to HFS forks, but so few would think to look at these: "Once executed with administrator priviliges exploits can do hard-to-recover harm to your system, the horror!". These are idiotic complaints.

    With all that said I can easily see people going to OSX to improve security, that does not make that article anything but deeply flawed however.

  18. Re:Well written, but by samkass · · Score: 4, Interesting

    If you remove things like IE

    But IE is part of the OS... just ask Microsoft. Seriously, though, back when my previous company had to deal with IIS before moving to a more secure/sane server, one of the server bugs was fixed by upgrading IE on the server, so IE-is-fundamental-to-the-OS is frighteningly close to actual truth with Windows.

    Also, I'd like to see the statistics you cite that say that Windows hasn't been hit statistically more than MacOS. There are no MacOS-specific worms or viruses "in the wild", so it's hard to come up with the sigmas for what would be "expected" for what a comparable OS should expect.

    --
    E pluribus unum
  19. Re:well, by cyber-vandal · · Score: 4, Interesting

    The very successful worms of the early 21st century were all about causing as much aggravation as possible. The creator of the ILOVEYOU virus didn't make any money from disrupting corporate email servers but he did get to cause a lot of aggravation. You think there are no virus writers wanting to stick it to smug Mac/Linux users? You think no-one would take the time and effort to annoy them? You don't understand human nature too well if you believe it's merely marketshare that's keeping malware away from OS X and Linux.

  20. Re:Well written, but by skiflyer · · Score: 4, Interesting

    Ok, I agree with most of your post, but ...

    The purpose of most of the DLLs in SYSTEM32 is documented, just look at the summary tab in Explorer, the problem is that with any complex operating system it's trivial to make up fake names that sound plausible

    I just looked at the summary tab on a dozen random DLLs in my system32 directory (most from microsoft, some from 3rd parties), and there was no information in any of them. Why can't 3rd parties use a different location than MS... at least that would help a little (would help me anyway, if not the actual problem being discussed)

    Windows requires users to use Administrator to install software? No, buggy software requires that. Historically a few Mac programs have had the same requirements ... iTunes springs to mind. Anyway, the Apple solution to buggy software requiring elevated privileges is "you can't run that software" - not very helpful if you need it.

    "buggy" software? I think you mean to say legacy OR poorly coded... this is one of those side effects that windows carries from version to version (like the registry) because MS refuses to leave customers high and dry for old software. Back in the old days this was the right way to do things, store configs in programdirectory/conf... we didn't have an appdata directory like we do now. Same with registry hives, they weren't setup in the same way they are now where certain users could do certain things. Calling it buggy implies the software is behaving contrary to design, it's not, it's just that the target has moved and the software hasn't all moved with it.

  21. Re:OS X is better,but... by TeknoHog · · Score: 3, Interesting
    I'm sure OS X is more secure then windows but give me a real unix operating system,os x is so hacked up and different it doesent even feel like a real unix operating system.You cant even mount ext2/3 in os x,whats up with that?

    On the other hand, OS X doesn't have all the legacy cruft of ye olde unix. I think one of the main strengths of Apple systems is that they do a clean start every now and then. Quite contrary to the Windows style of supporting everything since the DOS days.

    Personally I prefer Linux for the sheer amount of control. But the Apple way might have some benefits compared to more traditional unices. In any case I believe it's much more secure and sane than any Windows. I've recently convinced a friend to get a Macbook, since it's pretty much the only way to get a real OS preinstalled.

    --
    Escher was the first MC and Giger invented the HR department.
  22. Re:Well written, but by drerwk · · Score: 3, Interesting

    "they basically abandoned their own collection of pre-security era software" Not sure I understand. I am able to run software I wrote still have from 1990 (OS 6) on my Mac today (OS X). No problem, except for the serial port...