Comments on: Expert: Flaw still dogs Windows patch
An antivirus firm says Microsoft overlooked a potential exploit in its last Windows fixes. The software giant disagrees.
An antivirus firm says Microsoft overlooked a potential exploit in its last Windows fixes. The software giant disagrees.
December 30, 2009 4:00 AM PST
December 29, 2009 8:30 PM PST
December 29, 2009 3:53 PM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
all the effort expended on this stuff, why can't they fix it? This is
a truely innocent question from a non-programmer.
Seems as if Mac OS X can stop most of these threats by the very
nature of its BSD unerpinnings (needing permissions to do stuff,
etc.), why can't Windows require such permission before some
malicious code executes?
And don't give me the whole, "Macs only represent 2%...." stuff.
If a cracker wanted fame for his work, he would crack Mac OS X
and not be one of 70,000 plus getting into Windows. Anyway,
millions of Macs are sold every quarter and so there are tens of
milions of them out there to target.
Can anyone tell me why a company that has more money than
God canot patch the holes in the seive it calls an OS? Anyone?
Even so, you discount the whole market share to easily. Viruses and Trojans work well for one reason. If they find a host that they can send from then there is a 90%+ chance that the receiver will be a Windows OS, and thus for a virus to work well it has to rely on that. I can see a virus/trojan working if it supported Windows plus Linux/MacOS, but not if it relies on MacOS. Their just isn't enough compatable hosts out there.
Incindently, this story was not about Macs. Can't you keep these comments to one of the many Mac stories? Furthermore, as the story says, Microsoft has fixed the problem. I find it funny how Mac only just got a decent OS (Cooperative multi-tasking is garbage) but that doesn't stop the zealots coming out with the same "Windows Sux" comment every day. MacOS X looks great to me (I haven't used it much unfortunatly, but I did use System 7 a lot and I did not like it) but I have not heard of one original feature in it. Anyone?
http://secunia.com/internet_explorer_cross-site_scripting_vulnerability_test/
My Mac is better.
My Windows is better.
Okay, let's get the facts straight here:
1) Worms and Viruses are written to wreak MAXIMUM HAVOC. You can't do that by taking down 2% of the internet's computers - that won't earn these people their bragging rights.
2) User Education is a phallacy. There is only so much you can do to train people - assuming they want to change their ways. Stupid users will always outnumber the smarter ones - Mac or PC.
3) A tool is only as good as the person who uses it. This means that a Windows Box in the hands of an expert will always be more secure than Mac OSX in the hands of a novice.
4) Microsoft has to WORK HARDER AND SMARTER to address these security issues. Several security alerts a month is inexcuseable, and the times it takes them to issue a code fix is even more unacceptable.
5) Despite the fallacy if innovation, Apple really didn't innovate at much as people think they did. The GUI and mouse were stolen from PARC Xerox. Multi-threading and Protected Memory showed up in Windows NT 3.5 before it ever did on the Mac. In fact, it wasn't until OSX did Apple have a true multi-tasking, multi-threading, protected.
6) Microsoft is like Apple. They take other's ideas and improve them. The difference is that Apple has the magic touch to make them look cool!
7) Application availability on the PC is at least a hundred times greater than that on the Mac. People do not buy computers for the OS, they buy it to perform tasks. Until Apple can get more "killer apps" it will remain at 2% of the market share.
7a) Linux is an exception. It is growing because many companies are porting their software over to Linux as well. But why not to OSX? Simple. Linux is "free". OSX costs $$, and has to run on a more expensive and proprietary hardware.
This isn't supposed to be a "My OS is better than yours" forum - it should be a FIND THE SOLUTION forum.
Here's one for the Windows Users. Set IE's security to HIGH, install Firefox 1.0 and do most of your browsing with it instead.
http://members.fortunecity.com/pcmuseum/windows.htm
Apple didn't steal anything other than the concept of a gui from xerox. If you are going to argue that apple stole the gui from xerox then you have to argue that they all did including microsoft.
In my opinion it doesn't really matter because the end result is os options. I suppose that if xerox owned the patent to gui interface and had sued for licence fees and royalties the os would probably not be were it is today. However, for what ever reason they didn't so you have the os of today.
They only way they are ever going to better secure software is to first have a language that does it's best to stop holes to begin with. Programmers are going to have to be more careful (like this will ever happen). Third, build tools that can analize code better for holes or possible security problems.
That would cause some serious, real havok. Not writing a virus that effects a million idiot AOL users that have nothing important on their machines anyway.
- Problem was addressed a year ago
- by jv January 26, 2005 9:35 AM PST
- Proper security for IE when set to "high" has always been able to block this kind of attack. SP@ goes further to protect against this and works even with the Internet Zone set to "medium". Other browsers may be unafected because they do not support ActiveX. This is fine except in a corporate environment where ActiveX is still the most used method for customizing Intranet web content.
- Like this Reply to this comment
-
-
- Gimme a break...
- by loose_screw January 26, 2005 11:24 AM PST
- On the same token, I could argue that all computer viruses were fixed 20 years ago: simply don't use one!
- Like this
-
(22 Comments)You should NEVER download a control or allow a java applet to run from any site that you are not COMPLETELY familiar with. Browser hijacking and rogue code downloads can affect all modern browsers. Unfortunately the hackers pick on the most used browser beceause they get the most bang for their buck. FireFox has already posted numerous holes and fixes and continues to become a new favorite of hackers.
Users need to take on more of the responsibility for secure web surfing.
C'mon, yes--users *should* take some accountability for responsible usage of their machines, but what happened to making software user friendly and easy to use?
The fact is, most non-IT end users have no clue what javascript and ActiveX are. They turn on their store purchased PC, and expect things to work. And frankly, it shouldn't be their job to research what obscure vulnerabilities exist, and the needed hidden configuration changes to prevent exploitation.
If the fix for IE is to disable ActiveX, then Microsoft should include that in a security update IMO. Don't just create a security bulletin and say it's now the user's responsibility. That's just BS.