Tech/Computer advice from me

T2j8uui.jpg
 
Microsoft has released the "FIX" for Internet Explorer's security vulnerability. Please go to windows update and perform an update. After you perform the update you will need to reboot, and your pc will be patched.

lets see how well this works.
 
Why would we pretend patch tuesday never happens? It's the biggest part that supports my argument...

looking at the # of vulnerabilities found and patched is not a good metric. it's too simple and leaves too much out.....

Apple has a track record of configuring their devices to lie about security implementations in place on the device in order to connect to services that require those security implementations. Because actually implementing the security was too hard to them, so they figured it was better to just lie about it.

You sure they're better than microsoft? You sure the lack of listed vulnerabilities is because they're better at security? Is that a claim you really want to stick to?

Because most legit criticism I've seen is that Apple hasn't had the market share to warrant the attention.

Look at the last few years... the rise in mac vulnerabilities. look at how Apple's responded. look at the iOS problems.

if I were starting a tech company today, i sure as shit wouldn't model my security model after apple. they lost a lot of credibility when they configured their iOS platform to lie about its security features. they've lost even more in the wake of increasing number of malicious software targeting mac - their response was to deny it and pretend it wasn't happening...

i'd definitely consider modeling it after microsoft.

again...show me the data. if you go to CWE or CVE...I can assure you which suite of vendor products has led the pack over the years.

if you chose to ignore the logic of simple bugs/flaws per line of code...again...that is your choice!

if you chose to ignore design issues...again your choice!

Patching endless vulnerabilities...it might escape your notice...is symptomatic of design and coding problems. it's a reactive practice.

surprised you haven't ventured into .net. your argument would be stronger in that environment.
 
I keep saying there's more to it, and you keep pointing to it as some sort of meaningful metric. There's a whole hell of a lot more to security than just having identified flaws - like how quick you fix them, how much time you put into finding them yourself, whether or not you support others finding them and reward them for their effort, how open and honest you are about those issues.

Microsoft is leading the pack in every regard on those issues, and other companies are modeling themselves after microsoft.

You criticize them for their Patch Tuesday model, which has been around for a long, long time, yet other companies are following it because it's a great model.

You want to count the number of bugs? Well Apple has significantly less bugs, yet their model consists of lying about their security to everyone else and denying the existence of bugs when they are reported. When they're put out in public and an apple customer contacts apple, apple's customer reps are INSTRUCTED TO DENY THE EXISTENCE OF THE ISSUE. So yes, Apple has less vulnerability counts - but how could they possible be a better product in terms of security? That's a joke, and anyone worth a crap in security recognizes that.

If you want to know how well microsoft is doing then I suggest you follow InfoSec mailing lists and the blogs/journals that considered to have some of the top authors in the field.

And your still ignoring the fact that microsoft has a market share, over a period of time, that no one else in the industry can rival. MS has been the biggest target of everyone for the last two decades - we're surprised a lot of problems are found? We're going to use that to declare them terrible when it comes to security?

MS is suffering mostly form a reputation from the past. They're not perfect, but they're further ahead of most of the other big tech companies.

And I do work in .Net - used to do a lot more, but I still find myself working in it from time to time and I certainly keep up on the platform due to my role.
 
The reason for MS having so many security issues is two fold IMO and pretty simple.

1. Their philosophy on releases involves allowing endusers and tech professionals to be a part of the refinement process, hence all the patches. It allows for earlier releases but makes for a buggier product initially. Some say that's good because it puts an army of techs on the job instead of just what the company has on staff. Others say it's crap and lazy and problem inducing for the less educated end users. Both perspectives are legit.

2. Having such a huge market share and having been such a successful company for so long they are targets of hackers to a rate that dwarfs all the other companies combined. IE is popular, that's why it's what over 90% of malware is written for, not because the other proggies are so outstanding.

Oh and you guys are arguing which tastes better, an apple or an Orange? I would ague both have some impressive characteristics but both have some amazing flaws that go to a fundamental level, so neither is the ideal business model. Plus Apple is just evil and I won't buy a product from them unless I'm forced to for business.
 
Hah, I actually like Apple :)

But when it comes to security they're a joke and the only reason they are secure at all is because they built on top of Unix. I have no problem with them as a personal machine, or even a dev machine (they rock for programming), but I wouldn't use their servers for businesses unless I had to (like managing other macs on the network...) and I certainly wouldn't trust their services to secure or protect any data. They're known and verified liars about security - their reputation in the industry is junk now in that regard.

I'm surprised their iOS devices are being approved at all for DOD/DSS/DHS/DOJ work (I can't remember if they were approved for military? maybe they fall under the other depts for that?). I'm curious how that process went, and whether there were any back door deals to get that through... I have a hard time believing a top security person responsible for such decisions would overlook Apple's recent screw ups in regards to security...
 
I am going to invest in my territory, training my photographers using podcasts. Anyone have any experience making or uploading them? Any advice?
 
I cannot help with that one :\

Best I could do is google how to make a podcast :(
 
The reason for MS having so many security issues is two fold IMO and pretty simple.

1. Their philosophy on releases involves allowing endusers and tech professionals to be a part of the refinement process, hence all the patches. It allows for earlier releases but makes for a buggier product initially. Some say that's good because it puts an army of techs on the job instead of just what the company has on staff. Others say it's crap and lazy and problem inducing for the less educated end users. Both perspectives are legit.

2. Having such a huge market share and having been such a successful company for so long they are targets of hackers to a rate that dwarfs all the other companies combined. IE is popular, that's why it's what over 90% of malware is written for, not because the other proggies are so outstanding.

Oh and you guys are arguing which tastes better, an apple or an Orange? I would ague both have some impressive characteristics but both have some amazing flaws that go to a fundamental level, so neither is the ideal business model. Plus Apple is just evil and I won't buy a product from them unless I'm forced to for business.

intelligent response....but you're looking at the wrong metric.

the vulnerabilities are in the design and the code itself. that is a fact. IIS has been bug ridden for a long time also. professionals in the field who do real malware analysis/secure software development will tell you the same. MS security has gotten better - a lot better. And why not? The bottom line was being threatened after a point an market share no longer insulated them from serving customer interests other than new features. The dirty secret is that, until recently, most sw developers (all companies) were not trained in writing secure code and most companies didn't see the return. Viega, McGraw et al were writing outstanding books on all of this by the mid 2000s.

to fend off one retort: the whole point of the open source movement (e.g., Linux) is that it achieves a critical mass of "eyeballs on tgt" that, among other things, uncover security vulnerabilities faster. As for Apple...anyone seriously believe the Mandiants of the world (not to mention OS competitors) aren't looking for xploitable vulnerabilities? that cyber criminals aren't pushing the underground in the same direction?

as an addendum to other conversations: I did a quick look-up on the recent IE bug (not Heartbleed). As mentioned...one has to look at it as a memory management problem. turns out....

Use-after-free vulnerability in VGX.DLL in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2014.

anywho...TO BE VERY CLEAR...lotta superb tech folks in this thread. not belittling anyone. it's a team sport and any info sharing makes us all better armed. I have learned plenty in this thread from Mr T and others.
 
Last edited by a moderator:
As a web designer who put a lot of time into Flash study I have a major personal beef with Apple the Company. Their product on an engineering level is outstanding but their open source issues along with their business practices make them the evil empire in my world.
 
I'm a little skeptical of the argument that the open source community's projects carry some inherent level of security.

Open SSL was one of their projects :)
 
anywho...TO BE VERY CLEAR...lotta superb tech folks in this thread. not belittling anyone. it's a team sport and any info sharing makes us all better armed. I have learned plenty in this thread from Mr T and others.
Same here. :cheers:
 
As a web designer who put a lot of time into Flash study I have a major personal beef with Apple the Company. Their product on an engineering level is outstanding but their open source issues along with their business practices make them the evil empire in my world.

Ha! I happen to like my Apple MacBook Pro a good deal more than the MS products I have used. But there are plenty of design issues I don't care for and the company has exercised its power in curious ways at times. My mission statement isn't to glorify Apple!!
 
Apple is light years ahead of Microsoft when it comes to user experience in my opinion.

MS is much more free-wheeling to use though. Which can be good or bad, depends ;)
 
Al, CT, or anyone else working in the field (I know there's a few of us in various roles...)

Do you guys work with IPSec or DNSSec? If so I'm curious your general feelings about its reliability, usability, end user problems, roll out, etc.

Right now the default stance of my boss is 'not worth the effort (problems with end users) given the data on the network'

He's right... but eventually this is going to be the default configuration for a network (i'd think...) so I'm trying to get a jump on it...
 
a final thought: if one looks at the full complex of browser and related standards/non-stndards and various browser implementations you quickly see it is all over the map. aside from basic interoperability issues...there are significant implications for security. don't want to march through a tutorial.....but it is very complex. Parsers, rendering, accepted encoding schemes, embedded HTTP calls, allowed protocols, etc, etc......all over the map. then you get to plugins/extensions/3rd party sw.....various OS handler registration checks (or lack thereof).....again all over the map.

golden rule in security: the more complexity...the greater the likelihood for security flaws and bugs.
 
T:

- haven't worked a DNSSec implementation though I follow the literature

- as for IPSec. Lotta experience but with a specific set of DoD specifications. Like any technology it has pros and cons. Like any technology the utility function is driven (in part) by the environment it is employed in. Decisions have to me made up front which layer of the stack one wants security functions applied (e.g., IP layer for IPSec, Application layer for TLS/SSL). These decisions are driven by a lot of operational, management, security factors. With IPSec you have to be careful to state which mode is being applied. For obvious reasons...DoD prefers transport mode in which the orig IP packet is encrypted. This creates problems in certain contexts (e.g., satellite links that need to see type of service settings; security devices that need to see packet payloads). When employed enclave to enclave (rather than host to host) there is a problem of routing if the outer and inner IP addresses come from different spaces (for security purposes): how do you map the outer (VPN) routing domain to the inner routing domain? There are also bandwidth issues because of all the added headers but this can be addressed in many ways. There are also some issues with how devices are built for handling IPSec VPNs - some have been built not to pass control plane traffic - that obviously makes running a network more complex!

There are larger issues one gets into with all these technologies (at least for transport security): scalability of key management, ability of a key generating system to support dynamic/ad hoc connections, tie-ins to public key infrastructure and its management/trust/cost burdens, the range of policy enforcement capabilities a technology is capable of supporting.

As always: you need a set of requirements that is organized along priorities. then you wicker in the soundness of any one technology's overall security approach. then you do the risk/trade-off/BIA kinds of analyses.

Will give DNS more thought (focused elsewhere right now). It is obviously a key part of the whole complex - and subject to routine manipulations (e.g., IP fluxing, Domain fluxing, etc.). The International community appears to be moving toward DNSSec implementation....but slowly. You know, just like with our browser discussion: there are standards...and then there is how all these vendors implement the standards!
 
Last edited by a moderator:

Users Who Are Viewing This Thread (Total: 1, Members: 0, Guests: 1)

Help Users

You haven't joined any rooms.

    You haven't joined any rooms.
    Top