Vista Security The 'Longest Suicide Note in History'?
rar42 writes "The Inquirer is reporting on an analysis of Vista by Peter Gutmann — a medical imaging specialist. This isn't the usual anti-Microsoft story — just a professional looking at what is going to happen to his computer if it is upgraded to Microsoft Vista. From the article: 'Windows Vista includes an extensive reworking of core OS elements in order to provide content protection for so-called "premium content", typically HD data from Blu-Ray and HD-DVD sources. Providing this protection incurs considerable costs in terms of system performance, system stability, technical support overhead, and hardware and software cost,' says Gutmann."
From TFA:
At first, I shared some cognitive dissonance with Gutman; China, however, is governed by Chinese and for Chinese: they're allowed to act in their own best interests.
The U.S., on the other hand, is beholden to parasites and corporations; and compelled into an unnecessary decline.
You're not supposed to use a consumer grade OS for mission critical apps anyway. So if you went with a vendor that builds its apps on such an OS, then you are at fault.
Same story at http://it.slashdot.org/article.pl?sid=06/12/22/172 7245
Microsoft was legally forced to remove version numbers from Windows as the software they ship was technically no longer improved.
``This isn't the usual anti-Microsoft story just a professional looking at what is going to happen to his computer if it is upgraded to Microsoft Vista.''
Doesn't any professional investigation of Vista inevitably end up being an anti-Microsoft story?
(Just kidding. I actually think Microsoft put a lot of good things in Vista - although I'm not convinced it's a good product, and I'm definitely not dying to use it)
Please correct me if I got my facts wrong.
Here's a link to the actual paper referenced in the article.
I would post the entire paper, but it's too large. Here are some notable excerpts:
[100% ISO 646 Compliant]
SVM, ERGO MONSTRO.
Peter is a security guy. He's written widely used crypto software. He is not a medical imaging specialist. Where did /. get the idea that he's a medical imaging specialist???
>PS: Linux users are breaking the LAW every time they watch a DVD using their OS.
Untrue.
Distributors of some types of DVD decoding software may be doing so in violation of civil statutes in certain jurisdictions, but I must ask you to cite the specific prohibition you claimed in your PS:. Chapter and verse of the applicable law, please, don't waste our time with "DMCA". I know all about the DMCA, the DVD/CCA/CSS issues, etc.
-fb Everything not expressly forbidden is now mandatory.
Here's an interesting tidbit from the WINE folks:
Direct3D10, which will ship with Windows Vista in a few months, doesn't seem to be a large cause for concern. At first glance it appears to be more of an evolutionary change rather than revolutionary. New shader support will be needed, but extending ours once OpenGL supports it should be pretty easy. Stefan mentioned Microsoft is currently offering a lot of incentives for Windows developers who develop D3D10-only games since they'll only be usable on Vista - there's no plan to backport D3D10 to XP. Dan Kegel asked if that means we should port Wine's forthcoming D3D10 implementation to Windows, which would be relatively easy when we switch to WGL.
Without a doubt, Windows is still the most convenient platform for consumers. But the priority behind the design is not purely performance and flexibility, but protecting content and other commercial interests.
Houston; we have doublethink.
KFG
We sure know the priority isn't security either
In fact, if they only wasted the half of the time they wasted in DRM in security improvements...
I mean, if you read the DRM protection work...they completely redid everything that could break DRM, they break compatibility, they're even planning systems that need to re-do the hardware to require encryption on the *system*bus* just to keep hardware hackers from stealing contents at that place and hence making the DRM useless.....
If they had wasted all those efforts in improving security...vista would be the most secure consumer os available
Am I part of the core demographic for Swedish Fish?
Could someone please like, read....something before they post a summary? I found no indication that Gutmann is a medical imaging specialist from his web page or report. He's a computer scientist who specializes in compression and encryption, which actually makes him a little bit qualified to perform a professional review of the new operating system.
The only thing remotely medicine related here is a quote from 'Brad Steffler MD.', a surgeon who claims that Microsoft's restrictive DRM methodologies make it more difficult for him to do his job.
Many industrial and medical applications run on Windows. You forget that Windows NT was advertised as a high-security C3 operating system. Many applications were ported on this advertising. Some of the lock-down permissions in Windows NT were pretty draconian, and worked really well.
With Windows Vista, Microsoft appears to be completely abandoning any pretense of high-reliability.
Many industrial and medical applications have fairly high reliability requirements. Using commodity software and hardware has some cost and reliability advantages. It is easy to source replacement parts, and implement hardware redundancy. Being able to easily obtain replacement hardware is a big advantage if downtime costs are large.
The problem is that Microsoft appears to have abandoned the high-reliability sector. Windows XP has a continuous stream of rolling updates for both XP and the Anti-Virus packages. The result is that your high-reliability application can stop working for no apparent reason. From all indications, Windows Vista will make this worse.
Recently, I have been looking harder and harder at Linux. Linux offers a much more stable platform, and I can customize the installation to make it much more difficult to corrupt. The issue is that such a high software investment has been placed in specialized Windows solutions, that it is difficult to port everything to another operating system overnight.
Look at linux... its not like we have Linux 3.0 and Linux 4.0 where nothing old works.
Its still linux. 8 year old stuff still compiles mostly, its fluid.
If windows was so great, it would stay at one version XP forever, with unlimited updates forever, SP4 SP21. etc...
Just because they are forced by marketing to make a new version is admiting its core is crap and needs a rewrite.
They could just as easily update/replace portions of XP gradually, six monthly. And make sure each other component isnt
too tied to others. ie WMP shouldnt need IE7 or something else... it should be detect and use if available.
This whole idea of , lets stop current dev and all new dev is placed into a new 'version' edition is total marketing crap, and
old school stuff of the 80s. Modern complex systems should never have a major rebuild, its always small step updates, like real
biological evolution.
OSX is basically the same, but again its articially versionized because of just new components added, and the silly side effects like
newly compiled made software not working on old OSX's even if they use no new features, thats my biggest pet pieve of OSX. Sometimes
its only the result of the installer package, not the code it self which would work fine. If X library is less than version Y, then dont use
those features.
Btw does apple make the old OS10.1 and 10.2 upgrades from 10.0 FREE NOW? what about any one left in 10.2 land, do they get a free 10.3 upgrade
once 10.4 is widely installed? Having too many versions installed out there should be a worry for them, they should allow all 10.3 machines to upgrade
for free. It would surely be cheaper to have no support for pre 10.3 if you provide free upgrades.
Liberty freedom are no1, not dicks in suits.
The message is clear. They believe their monopoly can be best maintained by catering to producers, rather than to consumers. Consumer choice is not driving that market.
http://www.microsoft.com/about/legal/useterms/defa ult.aspx
this is a microsoft hosted page that you can pull up any EULA you want (MS products only of course)
Microsoft requires the right to DISABLE YOUR COMPUTER if it fails a validation check (WGA BOFH style anyone?)
Any person using FTFY or editing my postings agrees to a US$50.00 charge
I currently have a Chinese-made upconverting DVD player. Chinese made because the US and Japanese manufacturers have knuckled under to the demands of the entertainment industry that no DVD player will output HD content over component video cables. (Now think for a moment just how mind-numbingly stupid this restriction is. Upconverting DVD players don't actually output video in true HD, because the movie isn't on the DVD in HD in the first place, and no process can add more information that was there to begin with. All an upconverting DVD player does is interpolate. An upconverted signal is the absolute last thing that any pirate could want, because it massively increases the amount of data required to copy the signal, without adding any information. So the entertainment industry, out of sheer ignorance has added a completely useless restriction that imposes considerable inconvenience on the consumer. Many older HD TV's only have component inputs, and even newer ones typically have only one HDMI or DVI input. And HDMI/DVI switchboxes are much more expensive than component ones. So consumers end up switching cables, shelling out extra money for switchboxes--or doing what I did, and buying a Chinese DVD player that is oriented toward the consumer instead of sucking up to the content industry.
Consumer choice is not driving that market.
Consumer choice never drives the market in a monopoly situation. You get what I feel like producing, and you pay what I feel like charging. If you don't like it, tough.
Seven puppies were harmed during the making of this post.
The message is clear. They believe their monopoly can be best maintained by catering to producers, rather than to consumers. Consumer choice is not driving that market.
And it's going to hurt them. probably long term and big time.
Zune is a failure vs Ipod because consumers don't want to deal with DRM everytime they want to listen to something, especially when there are hundreds if not thousands of music players that will play non DRM files. Including the Ipod.
Vista will fail for similar reasons. Business is happy with XP and will support it until Microsoft doesn't, and maybe adopt Linux after that. Consumers will only upgrade when they buy a new PC, and will stay around even after support is killed. if Apple starts opening their mouth about vista DRM screwing their music experience, they might just buy a Mac next time. Hell I don't know why Apple hasn't done a "Buy a Mac and get an Ipod Free" deal as of yet. It would definitely get a mac in the door faster.
It's looking the same way for office2007 business wise. I know we look at it and say to ourselves "training nightmare". I'm sure we're not the only ones saying that especially since our business is Higher education. I can only imagine what a commercial business is saying.
Apple and Microsoft had the power. They had the power to give both AA's the finger and work directly with the artists. They had the power to ignore them completely and let the users rip until the cows come home. They had the power to screw these Hi-def DVD formats until they relaxed the standards to work with existing hardware and software. Unfortunately, Apple seems to be giving the RIAA the finger while somewhat bowing down to the MPAA's HD lockdown Schemes, and MS is asking both AA's which lower cheek to kiss in a futile attempt to gain some more exclusive content that Apple's going to get anyway because their the market leader. Even then, all MS is really going to get in the end is more demands from the AA's when they could have easily just stayed the course they were going and force the AA's to conform to the digital age or die.
If there is any time for Apple and Linux to start pushing themselves, now's the time.
In Soviet Russia, Trojan exploits YOU!
The world never had any entertainment before the dawn of DRM & copyright.
[sarcasm off]
--- Grow a pair, liberals... stop letting the Republicans bully you!
Live banjo music, played by relatives, close relatives. Very close relatives.
This issue is a bit more complicated than you think.
This is part of the subtext both of the original article, and of this most recent post, so I thought I'd share what I know about it. FWIW, I'm a radiologist--that is, an MD who interprets the results of imaging studies--and an informatics geek.
Images are created on whatever imaging device--CT scanner, MR scanner, ultrasound machine, digital X-ray machine--and manipulated by the device's controlling system to do simple annotations, reformatting, etc. This is typically a Unix-based system running custom software designed and maintained by the device's vendor. The images are not usually interpreted on these systems.
From there, the images are sent to the PACS (Picutre Archiving and Communication System), which is just a gigantic central image database. These also tend to be Unix-based systems.
There tend to be two front-ends for looking at images in the PACS database. The first is the radiologist's interface, which is a high-end video workstation dedicated to showing medical images with the greatest possible fidelity. Most systems I've seen are Windows-based (Windows 2000, in our case) and run software which was built by the the imaging system vendors in the late 1990's. Much is made of the "lossless" nature of the images which are displayed; for example, when you log into such a machine, you're warned about how "This is a medical device" and that you shouldn't mess with it. Much is also made of "diagnostic-quality monitors" and high-end video cards to drive the monitors. This is an artifact from the early days of digital imaging interpretation in radiology, when there was a great deal of concern about whether the quality of the digital images would be adequate for us to figure out what was going on in Grandma's chest X-ray if we weren't looking at a piece of acetate. Most of these concerns have died away, as the differences in resolution and dynamic range turned out to be relatively minor and the added conveniences of being able to manipulate the images digitally turned out to be huge. For example, the new LCDs I seen being put on PACS workstations are off-the-shelf Dell 22-inchers, as far as I can tell.
Finally, there are "non-diagnostic" interfaces to the PACS images, which do tend to be web-based. These are so non-radiologist doctors can look at the images, too. Some are IE-based, and use an ActiveX control to display the images, and some use a Java applet. These are displayed with lossy compression (since someone might want to look at them from off-site via a VPN), and officially are not allowed to be used for interpretation. And in fact, I wouldn't want to; it's a lot harder to see subtle things on them than on a full-blown PACS workstation. Part of that is just the interface (it's hard to use those stupid ActiveX/applet things) and part of it is crummy/mis-configured monitors, but I suppose compression artifacts could also play a role.
So, to review: you go see your doctor, Dr. Smith, in her office, and she orders a chest X-ray for you because you're coughing and have a fever. You come to the hospital, and the nice technologist takes frontal and lateral view of your chest on the digital X-ray machine. He then goes back to the X-ray control room, and sees that the images are pretty good, and so he sticks your name on them, and a marker of the date/time and his name, and so on, and then sends them to the hospital's PACS system. I (the radiologist) am working at my PACS workstation, going through the long list of all of the CT scans, MR scans, and X-rays taken in the hospital. I get to your chest X-ray and look at it; I don't seen any sign of pneumonia, so I write a report (the subject of a whole different set of informatics) that basically says "Clear lungs" and that gets entered into your electronic medical record. Then, Dr. Smith back in her office can see your X-ray via her Web-based interface. If she wonders about something she sees, she can call me up and say, "What's that stuff at the left ape
Happy Premise #3: Even though I feel like I might ignite, I probably won't.