[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: What GSE-Reactive Really Needs to Make



Sean Fahey wrote:
Michael J. Mahon wrote:

It's hard to know how much more secure OS X is than Windows XP.  To make
a real comparison you'd have to normalize to the number of attempts.

Since Mac OS is a small target, it is attacked *very* much less than
Windows platforms (like Linux).


That -sounds- logical enough, but having attended a few DefCons, I can assure you that it isn't the entire case and a bit misleading. It's more and more about psychology and the percieved rewards.

Attacks on all flavors of Unix/Linux/BSD combined outnumber Windows attacks. *nix exploits tend to be malicious, attempting to cause damage, or open the system to unauthorized access to data.

Windows exploits tend to be either malicious, or more recently, for lucrative gain of the hacker - either because he's set up a bot-net, a spam relay network or whatever. It's all about making money.

Agreed.  *nix attracts the "advanced" hackers, while most Windows
attacks are scripted repeats of a few "master" attacks.

I used to work with a commercial Unix product, and its source
(derived from BSD) was just as riddled with uncounted "move string
until null" loops as all other C source I've seen.  (A *really*
insecure approach to strings!)  Every one of these that works on
externally supplied data is a buffer overflow attack waiting to be
exploited.

I failed to convince folks that the solution was to enclose *all*
string copies at interfaces within *counted* loops with a null escape.
Oh, well...  ;-(

Of course, if you want to hack a commercial server, you have to
deal with folks who are expecting you, monitoring you, and actively
repelling you.  That makes it more of a game.  ;-)

Windows is a tempting target not just because it's the most prevalent operating system - it's because it's generally the biggest installed base of poorly secured systems out there that make it a target of opportunity. It's the low hanging fruit. Microsoft didn't make security a priority for their platform until rather late (Windows 2000) - not until after several very public, humiliating incidents. Also, Microsoft users are not security coucious generally - until bitten.

The latter point is perhaps the most significant issue.  Almost all
recent (last two years) attacks have had patches available before
things got out of hand--but many systems are not automatically updated
(sometimes for good reason, but often out of negligence) so there was
still lots of fertile ground for the wave of scripted attacks.

To make Windows more mainstream, user friendly, MS chucked security out all together in some instances, so security since then has been tacked on, cobbled together. We have patches for security patches.

This was true in the past--they held onto their idea of a *personal*
computer even as they were all getting internetworked.  And, as you
know, security is a *design* property, not a retrofit.

So they've been busy for the last several years redesigning and
rewriting millions of lines of code for security, which will be
largely complete in time for:

Windows Vista will be easier and more appropriate to compare the OS X security. Especially since Apple and Microsoft have been reading/ripping from each other's feature list for the last two years.

Right.  But even XP, properly updated, is much more secure than the
reputation that older versions received.  My system has never been
infected, and I surf and download a lot--but circumspectly.

People who like to click on flashing buttons and open unrecognized
downloads will always have a harder life.

The ultimate solution to this problem is to devise a networking system
so that anything more complex than text can be traced to its sender.
Some people will never act responsibly until they are held responsible.

Just because my front door is strong enough not to break when someone
throws a brick at it doesn't mean that they shouldn't be punished for
trying.

-michael

Music synthesis for 8-bit Apple II's!
Home page:  http://members.aol.com/MJMahon/

"The wastebasket is our most important design
tool--and it is seriously underused."