Slashdot interview with a Microsoft dope

Hey drop us a line about the show. Feel free to ask questions, provide feedback and criticism, or just ramble on about anything your little heart desires.

Moderators: snarkout, Patrick, dann

Post Reply
Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Slashdot interview with a Microsoft dope

Post by Tsuroerusu » Thu Jan 26, 2006 11:08 am

http://interviews.slashdot.org/article. ... /26/131246
"(12)
OpenBSD
by hahiss

How is it that OpenBSD is able to be so secure by design with so few resources and yet all of Microsoft's resources cannot stem the tide of security problems that impact everyone, including those of us who do not use Microsoft programs?

Nash: First, I should say that OpenBSD includes a relatively small subset of the functionality that is included in Windows. You could argue that Microsoft should follow the same model for Windows that the OpenBSD Org follows for their OS. The problem is that users really want an OS that includes support for rich media content and for hardware devices, etc. So while OpenBSD has done a good job of hardening their kernel, they don't seem to also audit important software that are used commonly by customers, such as PHP, Perl, etc. for security vulnerabilities. At Microsoft we're focusing on the entire software stack, from the Hardware Abstraction Layer in Windows, all the way through the memory manager, network stack, file systems, UI and shell, Internet Explorer, Internet Information Services, compilers (C/C++, .NET), Microsoft Exchange, Microsoft Office, Microsoft SQL Server and much, much more. If a software company's goal is to secure customers, you have to secure the entire stack. Simply hardening one component, regardless of how important it is, does not solve real customer problems.

Second, it is not completely accurate to say that OpenBSD is more secure. If you compare vulnerability counts just from the last 3 months, OpenBSD had 79 for November, December and January compared to 11 for Microsoft (and that includes one each for Office and Exchange - so really 9 for all versions of Windows). I encourage you to look at the numbers reported at the OpenBSD site to verify that this is true. "


Disturbingly real interview of how stupid Microsoft is.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
Gomer_X
Posts: 901
Joined: Fri Jun 03, 2005 1:31 pm
Location: Cincinnati, Ohio, USA
Contact:

Re: Slashdot interview with a Microsoft dope

Post by Gomer_X » Fri Jan 27, 2006 9:16 am

Tsuroerusu wrote: OpenBSD
by hahiss

How is it that OpenBSD is able to be so secure by design with so few resources and yet all of Microsoft's resources cannot stem the tide of security problems that impact everyone, including those of us who do not use Microsoft programs?
.
.
.
Second, it is not completely accurate to say that OpenBSD is more secure. If you compare vulnerability counts just from the last 3 months, OpenBSD had 79 for November, December and January compared to 11 for Microsoft (and that includes one each for Office and Exchange - so really 9 for all versions of Windows). I encourage you to look at the numbers reported at the OpenBSD site to verify that this is true. "


Disturbingly real interview of how stupid Microsoft is.
I think the question is stupid. Who realisitically believes that Windows and OpenBSD are aimed at the same target audience?

Microsoft's answer is reasonable. There will always be a trade-off between security and freedom. Security is restrictive, and most Windows users would rather be insecure. I don't make the same choice, so I don't run Windows unless I have to, and then I work to secure it.

The last part, however, is just crap. The number of vulnerabilities in Windows is only lower because they don't report their vulnerabilites in the same way. Unfortunately, if Microsoft says it enough people will believe it.

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Re: Slashdot interview with a Microsoft dope

Post by Tsuroerusu » Fri Jan 27, 2006 9:35 am

Gomer_X wrote:I think the question is stupid. Who realisitically believes that Windows and OpenBSD are aimed at the same target audience?
Well, Windows Server 2003 is aimed servers, OpenBSD is aiming for servers. I've tried Windows Server 2003, and it's not that different from XP, except it has some more advanced login stuff, for server apps built in.

Gomer_X wrote:Microsoft's answer is reasonable. There will always be a trade-off between security and freedom. Security is restrictive, and most Windows users would rather be insecure. I don't make the same choice, so I don't run Windows unless I have to, and then I work to secure it.
I agree thing about them *trying* to secure the entire stack is reasonable, but I still they don't understand really good security by making Windows XP run as root by default, and making it difficult not to run as root.

Gomer_X wrote:The last part, however, is just crap. The number of vulnerabilities in Windows is only lower because they don't report their vulnerabilites in the same way. Unfortunately, if Microsoft says it enough people will believe it.
Yeah, Microsoft is very good at brainwashing people.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

Post Reply