Tampilkan postingan dengan label windows. Tampilkan semua postingan
Tampilkan postingan dengan label windows. Tampilkan semua postingan

Kamis, 12 Mei 2011

Linux vs. Windows Security Mystery

Of all the many winning advantages Linux has in its favor, security is surely one of the more widely known examples.

Why else, indeed, would we see security experts in mainstream publications recommending it over Windows for online banking purposes?

That, indeed, is part of the reason it was so disappointing to see Linux get completely ignored in a recent NSA report entitled "Best Practices for Keeping Your Home Network Secure."

The report is filled with various suggestions oriented toward Windows and Mac users -- just as one would expect, given that they're by far the majority today. What stands out, though, is that for Windows users, the NSA simply recommends upgrading to Windows 7 or Vista, making no mention at all of the far-more-secure Linux option that's available.

More than a few ripples were created in the waters of the Linux blogosphere.
'NSA Says No to Linux'

Some interpretations seemed truly bizarre.

"NSA Best Practices Recommend Windows Over Linux For Security" read one headline on ITProPortal, for example.

Similarly, "NSA says no to Linux in best practice advisory" read another on TechEye.

‎ This, despite the fact that Linux wasn't mentioned at all in the NSA report.
'What a Twist of Words'

Bloggers, as per their wont, made note of that fact quickly.

"Wow what a twist of words," wrote Ken in the comments on the ITProPortal story, for example. "The NSA article does not even mention Linux. What the NSA article says is this: 'Both Windows 7 and Vista provide substantial security enhancements over earlier Windows workstation operating systems such as XP.'

"So the NSA is really saying that the newer Windows is better than the old Windows. Duh!!!!" Ken added.

‎It wasn't long before PCWorld weighed in with an indignant, "Windows Vista for Better Security? I Don't Think So," and the conversation took off from there.

Down at the blogosphere's Punchy Penguin saloon, Linux Girl was bombarded with comments.
'Merely a Reflection of Reality'

"NSA recommending Vista for home security is merely a reflection of the reality of monopoly in the retail space," blogger Robert Pogson offered. "In the USA probably as few as 2 to 3 percent of users use GNU/Linux, so a recommendation is almost useless."

Those who are serious about security "are already aware of SELinux, a product of the NSA," Pogson added. "The NSA is merely recommending that folks move on from XP, a poor OS poorly supported by M$. Folks who would heed that advice probably do not even know GNU/Linux exists."

It is "possible that some of M$'s donations may also have suppressed mention of GNU/Linux," Pogson concluded. "But who knows?"
'The Security Swiss Cheese of XP'

Consultant and Slashdot blogger Gerhard Mack took a similar view.

"You can't knock them too badly," Mack agreed. "The best numbers I have seen show Linux at half the numbers of Apple (Nasdaq: AAPL) -- a small number to begin with."

The NSA "has sponsored Linux security projects in the past, so they are definitely not anti-Linux," he pointed out.

Vista, meanwhile, "brought along some features to allow more apps to run as non-administrator and some features (UAC) to annoy people who buy products from people who can't be bothered with good security patches," Mack added. "Win 7 is just a more stable/less annoying Vista, and I'll take either of them over the security swiss cheese of XP."

So, "I'm with the NSA on this one because the sooner XP is just a memory, the better off we all are," Mack concluded.
'You Need to Know What You're Doing'

"The problem with Linux is you really need to know what you're doing for it to be secure," asserted Slashdot blogger hairyfeet.

The NSA's recommendations, then, are "no surprise, as they know that 99.995 percent of the population is not CS grads or kernel hackers or programmers," hairyfeet opined. "These people will NEVER use CLI -- hell, Windows' control panel scares them. You honestly think they are gonna learn Bash?"

Hyperlogos blogger Martin Espinoza wasn't so sure.
'Irresponsible at Best'

"When I see the federal government recommend the products of one of its actual constituents, I am annoyed but not surprised," Espinoza told Linux Girl in a link-filled email. "Remember when Bush's boy Ashcroft gave Microsoft (Nasdaq: MSFT) a free pass after the DOJ found that they had illegally abused their monopoly position? (And have you noticed where Ashcroft is now?)

"It comes as no shock to see the NSA failing to promote Linux when the federal government is clearly a friend to Microsoft, and vice versa," he said.

"And let us not forget the well-foreshadowed speculation that Vista may contain an NSA back door," Espinoza pointed out. "Since there is no way for an independent reviewer to know that the code they are reviewing is what is actually being distributed with Windows or via Windows (or Microsoft) Update, clearly it is irresponsible at best to utilize Windows in any case where security is important."
'NSA - New Spending Authority'

Barbara Hudson, a blogger on Slashdot who goes by "Tom" on the site, wondered about the target audience for the NSA's report.

"Home users will never even see this, never mind read it," Hudson explained. "Business users? If they haven't switched by now, a pdf bearing the NSA's imprimatur isn't going to count for a hill of beans next to the considerations of software that can't be migrated from XP, or the costs and time of migrating desktop users to a new version.

"Besides, most of those installations will be taken care of over the next few years by simple attrition or migrating the users to tablets," she added.

"So who *was* the real target audience? I would have to say it's the boss of whoever at the NSA ordered this written, to 'show they're doing something' so they can justify their paycheck," Hudson suggested. "After all, haven't your tax dollars always been used for NSA -- New Spending Authority?

"Now please excuse me," she concluded, "while I go tell the neighbors that those black helicopters are just a coincidence."

Kamis, 17 Februari 2011

Coming Down on the Windows Era

"Being the largest OEM of PCs on the planet and pushing GNU/Linux -- albeit a distro shrouded in non-free layers -- HP can put the last nail in the coffin of M$'s monopoly," predicted blogger Robert Pogson. "Their product will not only be competitive with that other OS, but iOS/MacOS and Android/Linux as well."
If the human brain can be compared to a search engine, it seems fair to say that most of us tend to scan the news each day for search terms and phrases that support our existing point of view.

That, indeed, could explain why a recent post over at the Linux Foundation has drawn so much attention on the Linux blogs.

"HP to Put Linux in Printers and PCs: It's the End of an Era for Windows" was the title of Executive Director Jim Zemlin's post, and it was that last bit -- "end of an era for Windows" -- that fairly leapt off the virtual page for Linux Girl.
'That Has Got to Hurt'
"HP announced that it is going to ship WebOS not only in phones, tablets and printers, but in PCs as well," Zemlin wrote. "In doing so, the world's largest PC supplier is indicating that they are going to ship PCs without Windows.

"For Microsoft (Nasdaq: MSFT) -- who was nowhere at this event -- that has got to hurt," Zemlin added. "Perhaps this really IS the year of the Linux desktop."

Now, Linux Girl is in no hurry to get into another "year of" debate -- her bruises are still healing from the last one. But the idea of the Windows era coming to a close was an irresistibly intriguing one. She strapped on her snowshoes and headed down to the blogosphere's Broken Windows Lounge to learn more.
'Weaker and Weaker'

"It is one more indicator -- after Linux-based netbooks, Android-based phones, etc. -- that the end of the era is upon us," agreed Chris Travers, a Slashdot blogger who works on the LedgerSMB project.

Of course, "some of these sorts of things have not been sufficiently successful in the past, and so I remain a little skeptical that HP (NYSE: HPQ) will be able to bring WebOS to the mainstream," Travers added. "However, even if they fail, it will be one step closer to the fall of Microsoft's market power in this important market."

In fact, "Microsoft's monopoly is starting to look weaker and weaker," Travers opined. "The era will not end with a grand announcement or even a product release. It will be a slow process, but in the end, it is happening."
'Those 2 Million Windows Viruses'

Similarly, "Microsoft would like people to believe this is just the end of the beginning, but it really is the beginning of the end," concurred Barbara Hudson, a blogger on Slashdot who goes by "Tom" on the site. "HP sells a LOT of computers, and HP making a linux-based WebOS available on everything from smartphones to tablets to desktops is going to give it some decent 'shelf space.'"

It's significant that none of HP's new devices will run Microsoft Office, "the 'One True Cash Cow,'" Hudson pointed out. "And while Microsoft makes a big advertising Increase sales with VerticalResponse. Free trial. push about 'to the cloud,' this same net-centric model removes the need for MS Office compatibility, or even Windows, making WebOS a viable product."

Meanwhile, given the way Android is "crushing the competition" in the smartphone arena, "there's no reason to believe that tablets won't be a repeat," Hudson concluded. "And with WebOS, HP is going to be able to tell both businesses and consumers, 'You can have the same OS on all your devices.' The only difference is that OS will no longer be Windows."

On second thought, she added, "there is another big difference: even ordinary computer users who don't want to shell out for a Mac can ignore those 2 million Windows viruses."
'HP Will Try and Fail'

Slashdot blogger hairyfeet -- a self-proclaimed Windows fan -- saw it differently.

"The end of an era? No, it's not -- where has this guy been, under a rock?" hairyfeet began. "HP has ALWAYS been heavy into the workstation niche, and workstations require Linux support, end of story.

"It would be like announcing the end of an era because a company put out Linux drivers for their new server line. Duh!" hairyfeet exclaimed.

"The only way I see HP making a difference is if they put out one hell of a piece of kit at a crazy, Dell-like, barely-able-to-make-a-profit price point, and I just don't see that happening," he added.

In the mobile arena, then, "my prediction is that, like in the past, MSFT will pull a 'me too!' and lower the price of Windows, and the fact that OEMs can buy WinPhone but not iOS will give MSFT share by default," hairyfeet concluded. "HP will try and fail, and no rules will burn Google (Nasdaq: GOOG) and Android in a year, maybe less."
'An Era That Never Really Began'

That point of view, however, was far from unanimous.

"How do you end an era that never really began?" consultant and Slashdot blogger Gerhard Mack asked. "Microsoft has never been all that good at PDAs or smartphones, and the only 'embedded' they were good at were places where you could put a PC in a funny case for a single task application."

HP's move, meanwhile, "is much bigger than Dell (Nasdaq: DELL) dipping its toes in the lake of GNU/Linux," blogger Robert Pogson opined. "With the investment of huge sums, manpower and vision, HP will make a difference."
'The Last Nail in the Coffin'

In fact, "being the largest OEM of PCs on the planet and pushing GNU/Linux -- albeit a distro shrouded in non-free layers -- HP can put the last nail in the coffin of M$'s monopoly," Pogson predicted. "Their product will not only be competitive with that other OS, but iOS/MacOS and Android/Linux as well.

"Competition is good, and this will make every participant in IT make choices and best efforts to give us what we deserve: IT that works for us, not against us," he explained.

Pogson's only reservations are that "HP appears not to be open with development, and they do not provide low-cost IT," he told Linux Girl. "I hope they do open the platform, and I hope they have the vision to make this technology available to all. That will maximize their return in the long run."

Meanwhile, the move "clearly sets the bar high for Apple (Nasdaq: AAPL), M$ and GNU/Linux or Android/Linux," Pogson observed. "With this much competition, choice will be everywhere and monopoly will be ended within a year or so."

Sabtu, 22 Januari 2011

how to protect windows 7

It was a notable accomplishment when Windows 7 was not impacted in any way by the vulnerabilities addressed in the six Security Bulletins released by Microsoft for the November Patch Tuesday. It would be even more impressive if Windows 7 proved invulnerable to the zero day exploit that hit the next day.

This newly found bug was discovered by Laurent Gaffie and details were posted on the Full Disclosure mailing list. Microsoft is investigating the reported flaw which basically crashes a Windows 7 system when exploited. The issue is in the SMB (Server Message Block) protocol that forms the backbone of Windows file sharing. When triggered, the flaw results in an infinite loop which renders the computer useless.

Tyler Reguly, Lead Security Research Engineer with nCircle, explains "Exploitation of this vulnerability occurs when a user attempts to browse to Windows Share hosted on the malicious server. On Windows 7, the DoS (denial of service) will occur as soon as you type '\\\' in the search box. "

Microsoft Windows 7 tool rips off open source code, says blogger | Microsoft left Windows 7 open to hackers, says Sophos | Putting the finishing touches on your Windows 7 migration | Window 7's XP Mode and other computer networks

The vulnerability actually impacts both Windows 7 and Windows Server 2008 R2. There are currently a couple different proof of concept exploits circulating, but there are no reported attacks in the wild at this point. Because the flaw only enables an attacker to crash the system, and doesn't provide any unauthorised remote access that could lead to compromising information or performing other malicious activities, the odds of the exploit being actively used by attackers is fairly slim.

With some SMB-based bugs, you can minimise the risk of exposure by blocking SMB traffic at the router or firewall, essentially making sure that no outside source would be able to attack systems on your network. Blocking TCP ports 135 through 139 and port 445 will prevent outside SMB traffic from entering the network.

* Login Login | Register
* Follow us on Twitter
* Get Widget
* Newsletter Subscribe to Techworld newsletters

With the firewall blocked, the threat still exists internally, but ostensibly the systems on the internal network should be more trusted than those on the Internet and hopefully nobody on the internal network would intentionally launch such an attack. You could block those ports on the internal network as well, but then systems would be unable to access file and folder shares on the network.

With this particular bug though, the firewall will not protect you completely from outside attacks. Reguly says "There is an Internet Explorer-based attack vector. By including a file stored on a share in the HTML of the web page the flaw can be triggered. But, once again the result is a denial of service."

Until Microsoft completes its investigation of the issue and releases a patch, you will just have to be vigilant about avoiding suspicious or malicious links on web pages. Because of the limited value of a DoS for the attackers, odds are good you won't see any attacks from this.

Microsoft has described Windows 7 as the most secure operating system it has yet developed but 'most secure' doesn't mean impervious. Windows 7 is still significantly more secure than Windows XP, but news of the Windows 7 vulnerability certainly overshadows the fact that Windows 7 wasn't impacted on Patch Tuesday.