lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
Order Openwall GNU/*/Linux 2.0 on a CD with delivery worldwide
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
From: dfs at roaringpenguin.com (David F. Skoll)
Subject: Counseling not to use Windows (was Re: Anonymous
 surfing my ass\!)

On Mon, 15 Jul 2002, hellNbak wrote:

> So many of my clients would fire you on the spot for reccomending that
> they just stop running MS products.

Fine; that's their choice.

> If you truly are a security
> professional -- you would know better.

I think this is a very bad attitude.  Trying to secure Windows on the
desktop is fundamentally impossible because of design flaws.

Sure, UNIX boxes can be owned, no question about it.  They can be
owned because of bugs such as buffer overflows, tempfile races, etc.
which are implementation problems.

Windows boxes are fundamentally insecure because of bad design, not only
because of programming errors.  Encoding metadata such as "executableness"
in a filename, for example, is a fundamental design flaw, and one that's
impossible to correct without changing Windows' design.

So no, I don't refuse to deal with clients who use Outlook.  But yes,
I recommend they switch anyway, because to do less is an abdication
of my responsibility.

--
David.


Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux