back

by rbanffy·18y ago·view on hn ↗
NT could be made really solid and really secure.

The main problems here are the deep hooks into the OS that Windows Explorer and Internet Explorer (and all software that requires parts of both to function) had built into them.

The other problem is that far too much of the system runs as "system". I read this has improved a lot in the 2003 and 2008 server editions. But most of it was improved by having additional software bolted on top of the holes instead of just getting rid of them.

1 comments
What absolute nonsense. Microsoft has spent more money on source code audit, software pentesting, and SDLC than any other four of the top 10 ISVs combined. All they do is find and remove holes.

Find one credible professional security person --- almost all of whom run OSX and Linux, by the way --- that thinks you're right, and MSFT is just bolting security on.

A "professional security person" running OSX or Linux would seem to say something about the security of Windows and how Microsoft practices security, or at least the perception of it.
How is that anything other than a superficial cheap shot? I don't like to use Windows, but I respect the work that goes into securing it.
I'm just pointing out an oddity in your choice to point out what security professionals use. There would have been nothing odd if you had decided not to list their OS choices.
It's definitely a lot more fun to code security tools on Unix than on Windows --- though I'm having a lot of luck with Ruby on Windows for debugging and anti-reversing work.

You're right, it is odd. But it's not a testament to Windows security. If security is what counted, we'd be using Linux or FreeBSD. We're not; we're using an OS that ships with SUIDs that run commands as root for you. We use it because we like it.

No, we'd be using MVS, VMS, Nonstop, and their competition, not UNIX or Linux if security were important enough to us... or at least those of us who are well-informed enough to know the difference.
that's pretty rich, coming from the MASTER of cheap shots. you can't tell people that their arguments are "absolute nonsense" and expect to have a nice, reasonable conversation with them.

your posting history indicates you might have something interesting to contribute, but you really need to work on your manners.

I don't care how the argument was put. I just care that it's wrong.
Ok, you two have now descended to mere reiteration. Let's call it a tie.