Re: Short List of Security Questions



I will float a baloon toward a partial response . . .

"dw85745" <dw85745_NOT@xxxxxxxxxxxxx> wrote in message
news:uvwH21tpGHA.516@xxxxxxxxxxxxxxxxxxxxxxx
As a Programmer and an End User one of my biggest frustrations is getting
"WHAT YOU SHOULD DO" Security Information related to Windows
I can write code all day long, but when it comes to securing Windows I
knock
my head against the wall.


And the code you write is defensively secure code ??
If so it is only so because you have done your homework over time.
Configuring a system has similar requirements.

A short list of my questions are:

For each OS (Win98 through XP) and each version (Home and Pro):

I take this to mean Windows 2000 Professional, and Windows XP (Home and
Pro).
Any DOS family OS is, intrinsicaly, not securable, and NT 4 and earlier are
not
capable of resisting what today's networked environment can throw at them.

1) Is default best?
Best? You mean better? Compared to??
One can always configure one of the OSs to which I have limited these
comments
better relative to their security stance than they are found in their
install default state.
This is largely because the install defaults must be a best guess of what
fits well for
99% of the reasonably sane use cases that exist. They are sort of a lowest
common
denominator, except one factored so that it does not lower the bar below
some
"its the right thing" or "it really is in your better interests" threshold.
What is better can only be determined relative to both the reference and the
usages that are to be made of the system. For example, if that XP Pro is to
act as
the house's little fileserver, then having the firewall on with no
exceptions is not right.
However, defining the defaults to be otherwise and allow unrestricted file
and print
sharing would not be right.

No matter what OS you use, where do you get a detailed explanation
regarding
what all the switches do in Internet Explorer and whether you should set
them or not. The #$%^% poor explanation you get when you right click on
the
checkbox is useless as far as I'm concerned.

Search for the Internet Exlorer Administration Kit if you want the detailed
docs.
Else, use something else.


2) How do you keep an installed program from having access to other
programs or other parts of the system in a standalone home computer (here
I
refer to file permissions and other security measures) ?


Programs (with specific exceptions now in the .Net runtime era) do not have
access to anything. The accounts running the programs have or are denied
the accesses, even when those accesses are done by the programs.
Hence, you segment the machine's resources based on the principals that
you want to segregate from one resource/capability and the other.

You need a plan based on what you want "protected" and what is a "don't
care" so that you may focus your effort on what is important. Then normally
one defines custom groups that are used to make grants (and sometimes
denials)
strategically in order to carve off areas of resource/capability to only
specific
groups of accounts. There is more that may be done, like software
restriction
policies, etc. but those measures are advanced and normally used to build
upon
an initial basis built with basic control via grants of permissions and
rights.

3) Win98 had a big problem with NetBEUI. Do other windows OSes have this
type of or similar issues?

I don't know, never used NetBEUI and always shut if off and uninstalled it
if I found it installed. In all versions of OS to which my comments are
limited
one has to go well out of one's way to install NetBEUI and I can think of no
good reason why one would do so.

4) After I go to Windows Update and download the security patches, what
changes have been made to my system ?

Today you get mostly incremental code that is patched into the binaries to
version them to the new, safe versions. One also gets updates to the client
end of autoupdate, the most recent malicious software remover, and lately
genuine Windows check code, . Beyond these you are offered non-critical,
non-security updates/upgrades (ex. the latest .Net frramework, the latest
MediaPlayer), and updated drivers for hardware from vendors that have
elected to participate in the means of distribution (that offer has also
been
made to software vendors, but until just recently I do not recall seeing any
releases for non-MS software).

5) What are the security differences between Home Edition and Pro
Editions
(IMHO MS needs to include all security capability in Home as well as Pro)?


Very little. The difference are more in configurability.
Home does not have EFS, does not let one shift out from "simple file
sharing" mode,
has a slightly more restricted amount of concurrent network connections
allowed,
does not allow for direct editing of the local group policy, has some of the
utilities
removed, etc. etc.
Under all of these differences the code is the same. Some defaults are
different,
and some of these cannot be made to be otherwise; some things are ripped
out,
but what code is there is the same in both versions.



--------------------------------------------------------------
If anyone knows of an EXCELLENT book or a website that explains this by
OS,
it would be appreciated.

Thanks
l




.



Relevant Pages

  • Re: Windows Update Error on XP 64bit: update is redirected from v6
    ... In order to enable AHCI without reinstalling windows I had to pull ... under 'Reset the default security provider in Windows XP '. ... was this a clean reinstall of XP or a Repair Install? ... Microsoft Windows 2000 Operating System Group Policy Result tool ...
    (microsoft.public.windowsupdate)
  • Re: Microsoft ME
    ... > I have just found out that the Microsoft ME operating ... > long on security to ME so I can keep people from using our ... How can I force people to use a login ID and password to log into my Windows ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.security)
  • Re: lets vote for better security
    ... : OE-related security vulnerabilities. ... But there is no requirement to install and update every 30 to 60 days on any ... your argument would require every Windows computer to ... and yet WSH is still a threat. ...
    (microsoft.public.security)
  • Re: Safe?
    ... Q1) I got an email from Microsoft about a security update. ... A1) No. Microsoft NEVER sends emails with security update attachments. ... pages where you can access Windows Update, download patches, or request ... Services to install Windows security updates or hotfixes. ...
    (microsoft.public.security)
  • Re: Will 839645 disable this?
    ... Check out the salary for Risk Analysis professionals. ... >> technology that is in those systems, still apply to Windows 2000. ... >> to install a security update in the offchance and likely remote ... Many security updates are NOT remote ...
    (microsoft.public.win2000.general)