[Full-Disclosure] Re: Full-Disclosure] Anti-MS drivel

From: martin f krafft (madduck_at_madduck.net)
Date: 01/25/04

  • Next message: Georgi Guninski: "Re: [Full-Disclosure] Full-Disclosure] Anti-MS drivel"
    To: full-disclosure@lists.netsys.com
    Date: Sun, 25 Jan 2004 22:02:04 +0100
    
    
    

    [flame-bait ahead]

    also sprach Helmut Hauser <helmut_hauser@hotmail.com> [2004.01.23.2154 +0100]:
    > Sometimes it?s to blame us administrators for not installing patches -
    > slammer and blaster patches were released way BEFORE the outbreak(s) occured
    > but most admins did not patch,
    > simply they dont?t even know that there is a patch available ! Could you
    > blame Microsoft on that ? Simply no, cause as admin I have to know about
    > patches/releases, I have to be on the MS security mailinglist and so on.

    when i patch a windows system, i encounter downtime and possibly
    a whole set of new problems. been there many times.

    when there is a security hazard in linux, i can fix it over ssh from
    a beach in malibu in 98% of the cases, requiring a restart of
    a single service.

    > e.g. I had to help out one large organisation (the famous infected notebook
    > thingy) to patch the whole IT, what a nightshift ...
    >
    > *nix admins patch regulary but some (so called) windows admins) don?t -
    > cause they did not realize that there is something to patch ...

    the source of this difference is deeper: (a) UNIX admins know
    computers and networks; windows admins know where the control panel
    is. (b) unix is modular; windoze is monolithic.

    flames -> /dev/null

    > I recommend the MS SUS server, it?s free, you can test patches
    > before approving them and it is inexpensive compared to SMS

    i recommend linux. it's free and it works.

    > - Change the behavior of XP Home (everyone is admin) - create an
    > own install account with warning background - SuSE like with bombs

    windows won't properly operate in all cases without admin rights,
    unless you spend hours tweaking it. remember: NT's help and print
    system did not work if you made c:\winnt read-only to everyone.

    > - Software vendors - change your installers - most games run only
    > as admin in WinXP ...

    little they can do with a flawed operating system. while in unix,
    security is being worked into the core, in the windoze world,
    security is a band aid you shuff on top of the other 100 you already
    stuck on.

    -- 
    martin;              (greetings from the heart of the sun.)
      \____ echo mailto: !#^."<*>"|tr "<*> mailto:" net@madduck
     
    invalid/expired pgp subkeys? use subkeys.pgp.net as keyserver!
     
    i'm currently out trying to find myself.
    If I should get back before i return,
    please keep me here.
    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Georgi Guninski: "Re: [Full-Disclosure] Full-Disclosure] Anti-MS drivel"

    Relevant Pages

    • RE: Releasing patches is bad for security
      ... The new patch model for longhorn will not require reboots. ... functionality over security. ... Current patches are getting smaller as with large enterprises bandwidth can ... > MS posted a patch and some 300ish days later the worm hit. ...
      (Incidents)
    • RE: Releasing patches is bad for security
      ... posted a patch and some 300ish days later the worm hit. ... The problem then is how to release patches ... specifically focused on finding security flaws in all of their software. ... Releasing patches is bad for security ...
      (Incidents)
    • Re: [Full-Disclosure] Gates: You dont need perfect code for good security
      ... the blaster worm preceded the patch so this argument is DOA ... you do not have to pay for RHN to get redhat patches. ... I run Astaro Security Linux here at the house..blaster ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] DCOM RPC exploit (dcom.c)
      ... But you'd still patch either way, ... of home users who don't even know what a security patch *IS*, ... But how many organisations firewall off internal servers from ... administrators have the time to watch the IDS given the number of patches they ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] Re: Re: <to various comments>EEYE: Microsoft ASN.1 ...
      ... My personal prejudice is that I subscribe to the school of "security by ... I said why release them all on day 0 of the patch release. ... We use the details to create signatures for our vulnerability ... >>these signatures and use them to check for patches or to protect systems ...
      (Full-Disclosure)