Symantec/EU succeed in making Vista insecure


Recommended Posts

"Oh, Vista is going to be so insecure because of Symantec." Does anyone actually have evidence that this PatchGuard move will actually reduce overall security?

As a rule, anything you open, can be used in an attack of some sort. Maybe it will be a big deal and may be it will not. Time will tell.

Of course, IMHO, there is no secure OS.

But I have a hard time believing all of your whining: "Oh, Vista is going to be so insecure because of Symantec." Does anyone actually have evidence that this PatchGuard move will actually reduce overall security? It doesn't sound like MS is just opening up the kernel to every 16-year-old with VBS knowledge. Don't be so critical until you know exactly what technical changes are being made and what the implications of those changes are.
I have tried making this point before. Few listen, because it is fashionable to bash Symantec.

Brandon, I know you work for Microsoft, and they supply your paycheck and all. But you are quite wrong on your points. Until SP2, XP security was a complete joke! All those ports open for automated worms to exploit. The default XP install still leaves the home user running as admin, fer-cryin'-out-loud! Compare Windows XP SP2 to, say, Ubuntu (perhaps the most popular distro, and weighing in at 1-CD, probably most comparable to a typical home user's XP install). Tell me, exactly, how you would compromize this so much easier than Windows?

You can compare default installs, if you like (would be an interesting for people with XP SP0 CDs!), or you can compare 'hardened' versions of each. Either way, you won't find XP coming out on top. At least with Vista, Windows is coming out with a comparable product...

Some quick points before bed...

Saying "this OS is more secure" means nothing. This is a far more nuanced discussion than that. Better questions are - which OS is more securable? Which OS is more commonly used in such a way as to be secure?

Some arguments I would make are:

-Windows (even XP Gold or 2000), Linux, and FreeBSD can all be made very, very secure.

-The standard desktop use of Linux / FreeBSD is far more secure than that of Windows 2000/XP.

-The standard desktop use of Linux / FreeBSD is also far less useful and user-friendly, partly because of its security measures.

-It's easier to discover holes in Open Source software.

-It's far more productive (for a malicious person) to spend their time discovering holes in Windows.

-The number of exploits or discovered vulnerabilites is absolutely no indication at all of how many total vulnerabilities exist in said codebase. Unless of course you believe that the same amount of effort has been exerted over the same period of time by the same people toward discovering those vulnerabilities.

-There are certain roles (like Web Server) where Windows (+ IIS 6) is leaps and bounds more secure than the most common OSS competitors (Linux+Apache). I would not doubt this for a second.

Finally, Windows Vista is taking risks in useability and compatibility in the name of security. You can very easily argue that steps Microsoft took when building Windows 2000 and XP later became detrimental to its security proposition for the average user. They certainly weren't taken lightly - but were taken in the name of useability and compatibility. Especially when it came to replacing DOS / 9x with an NT-based system on desktops as quickly as possible. However, I do not think you have any ground to argue that these choices were wrong. Why? Because now 5 years later Windows XP is more successful than ever. And what's more, it was undeniably a huge step forward in robustness, reliability, and even security - from the hugely successful Windows releases that came before (particularly those from the DOS / 9x line).

Nowadays we live in a different world, and customers have new and different demands. Microsoft responded to those demands while developing Server 2003, IIS 6, and most of all XP SP2. No software will ever be perfect - but I think the investment Microsoft has put into security over the last several years is really starting to pay off. And as I said before, I believe Vista is more secure than anything out there.

OK.. With all this arguing over PatchGuard in Vista x64 (I disagree that MS should open it up btw), I have to ask the question of WHY PatchGuard isn't in the x86 version of Vista? All I've found is something to do with backwards compatability, but what about people who aren't on x64 processors yet, but don't give a <bleep!> about older software? Can someone point me at a decent article explaining why, please?

I want PatchGuard on Vista x86 goddammit!

Some quick points before bed...

Saying "this OS is more secure" means nothing. This is a far more nuanced discussion than that. Better questions are - which OS is more securable? Which OS is more commonly used in such a way as to be secure?

So saying it means nothing, except when you say it, like in your earlier post:

... claiming Windows XP is inherently less secure than Linux is a load of crap - I can't think of any OS that's easier to compromise than Linux...

...But in every technical way, I believe Vista is more secure than anything comparable (OS X, desktop Linux, etc).

...

You never did say how you would compromize that Linux box, since it seems you believe it to be trivial.

You other points:

-Windows (even XP Gold or 2000), Linux, and FreeBSD can all be made very, very secure. I agree and have made the same comments here on Neowin in the past. Even XP SP0 can be made secure.

-The standard desktop use of Linux / FreeBSD is far more secure than that of Windows 2000/XP. I agree, since you seem to be indicating the "default" standard installation (fresh from CD).

-The standard desktop use of Linux / FreeBSD is also far less useful and user-friendly, partly because of its security measures. That is a matter of opinion. My kids can use my Linux box without problem or special training. Less useful? Less user-friendly? Not to a user. There is some learning that must be done to administer it, and if you grew up on Windows, then Linux will seem more difficult to learn.

-It's easier to discover holes in Open Source software. True. Which is why so many get repaired. Looking at Secunia (for example) shows many more advisories opened and closed for Open Source projects such as Red Hat, Apache, etc. And it hasn't been too tough for malicious crackers to find holes in Microsoft's software, even though the source is not available to them. What is the conclusion to your "easier to discover holes" statement? Do you intend to plant seeds of Fear, Uncertainty and Doubt, or did you have a statement to make that Open Source was less secure because the source was available?

-It's far more productive (for a malicious person) to spend their time discovering holes in Windows. True. As owner of 90-95% of desktops, Windows is a prime target. Being a target, of itself, does not make the software any more or less secure. The code is the same, regardless of how many people try to attack it.

-The number of exploits or discovered vulnerabilites is absolutely no indication at all of how many total vulnerabilities exist in said codebase. Unless of course you believe that the same amount of effort has been exerted over the same period of time by the same people toward discovering those vulnerabilities. Agreed. People who merely compare the number of Linux vulnerabilities reported to the number of Windows vulnerabilities reported are looking at a very small part of the larger picture. Just in that data alone, there is also the "time to fix" metric and the "severity" (privelege escalation/code execution) and "vector" (remote/local) that ought to be looked at. Factor in poor infrastructure/administration and bad users... Well, it becomes a mess.

-There are certain roles (like Web Server) where Windows (+ IIS 6) is leaps and bounds more secure than the most common OSS competitors (Linux+Apache). I would not doubt this for a second. Here you go again, making that "more secure" claim that you just stated "means nothing". Now, IIS6, is a great product, and is well-maintained. Apache still has some open items that are not closed. IIS runs on the Windows platform only. And Windows has open items that are not closed. Compare to Red Hat (or SUSE, or look up your own enterprise-grade Linux) which shows that it is well-maintained for security issues and has no open advisories. I would call it much more even than you see it. Maybe Vista will come around and turn the Windows platform around a bit and we can all look forward to long periods where Windows has no open advisories on it...

thefonz,

you cant imagine how wrong you are, many use Norton os Symantec products. Of course few are on forums like this one, but we are talking about MILLIONS of regular users, that dont really care about all this stuff, they use computer for work ou fun but they dont really like to know whats behind the scenes!!!

That kind of user...

PS: i dont use it, and never will, cause i was using it till i installed kav, and then i realized that i had a virus nest inside LOOL

Really?

Oh.

I honestly thought that anyone with a minutae of websense would realise quickly how rubbish those two products are and move onto something better (nod32 or kaspersky).

I myself have managed to convert two people i work with to get rid of their installs.

Ah well, i guess until that glorious day happens where everyone becomes enlightened to the internet (past amazon and ebay) and what it has to offer the rest of us will have to suffer.

Saying that, i have no intention of upgrading to vista until microsoft completley stops supporting XP; which will be at least 2 years from now i guess.

I laugh at Symantec and Mcafee whining about Microsoft...I just saw this download:

Symantec AntiVirus Corporate Edition v.10.1.5 Build 5000 ISO 394,4Mb

wtf!..why don't they just hire an army to protect your computer..or...whats the next product goal..to be on a DVD.

In all honesty anyway; does anyone here USE macafee and symantec products?

No...

No? Try thousands of companies who trust big renown names like Norton antivirus despite the available competitors. You can't argue against the one who decided at a company to go with Norton. They get the license and you deal with their software and can't change their mind unless you can prove to them that it will be better, cost-effective and that the company will provide support as good or better than what they are currently using.

Such a thing will not make them switch.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • This could exactly be how our Sun ends but it's not as simple by Sayan Sen Image by Drew Rae via Pexels An international team led by Université de Montréal (University of Montreal) PhD student Érika Le Bourdais has found that the ancient white dwarf star LSPM J0207+3331 is still pulling in planetary debris, even though it has been cooling for about three billion years. White dwarfs are dense, Earth-sized stellar remnants left behind when Sun-like stars exhaust their nuclear fuel and shed their outer layers. The star, located 145 light-years away in the constellation Triangulum, is the oldest and coldest white dwarf known to have a surrounding disk of dust. The star was first spotted in 2019 by a citizen scientist through the Backyard Worlds: Planet 9 project. Its cool temperature immediately suggested that it was very old, since white dwarfs gradually lose heat over time. Using the W. M. Keck telescopes in Hawaii, astronomers later confirmed that the star shows infrared signals consistent with dust rings formed by asteroids breaking apart under its strong gravity. Such infrared excesses occur when a star emits more infrared light than expected, often because warm dust surrounding it absorbs and re-radiates energy. “This discovery challenges our understanding of planetary system evolution,” said Le Bourdais. “The fact that we still see planetary debris being accreted three billion years after the star became a white dwarf suggests that asteroids, comets, and even planets can remain in orbit around these stars for a very long time.” Spectroscopic analysis—a technique that studies light to identify the chemical elements present in an object—revealed thirteen heavy elements in the star’s atmosphere: sodium, magnesium, aluminium, silicon, calcium, titanium, chromium, manganese, iron, cobalt, nickel, copper, and strontium. Normally, heavy elements sink quickly in hydrogen-rich white dwarfs, making them hard to detect. “We expected to see only a few elements, but we found dozens!” explained Le Bourdais. The research paper adds more detail. The absence of carbon features suggests the debris came from a carbon-volatile-depleted source. The abundance pattern shows slight deficits of magnesium and silicon compared to iron but otherwise resembles Earth-like material. This points to a differentiated rocky body—one whose materials have separated into distinct layers such as a metallic core and rocky mantle—with a metallic core fraction higher than Earth’s. In other words, the star is accreting the remains of a large rocky object, similar in structure to Earth or the asteroid Vesta. “White dwarfs offer one of the only ways we can directly measure the composition of exoplanets,” said Patrick Dufour, co-author and professor at Université de Montréal. “When planetary debris come too close, they are torn apart by the star’s gravity and end up polluting its atmosphere, leaving a detailed chemical fingerprint of its composition.” The team also detected weak Ca II H & K line core emission, making this only the second known isolated polluted white dwarf to show this feature. These are specific spectral signatures produced by ionised calcium and can indicate unusual physical activity in a star’s upper atmosphere. The finding suggests that extra physical processes may be happening in or above the star’s upper atmosphere. The study stresses the importance of including heavy elements in model atmosphere calculations, since leaving them out can distort the inferred structure and lead to inaccurate stellar parameters. Earlier work suggested the star’s infrared excess came from two dust rings. The new analysis shows that a single silicate dust disk—a ring composed largely of rock-forming minerals rich in silicon and oxygen—can explain the observed signal at 11.6 μm, simplifying the picture of the system’s structure. The question of how debris ended up falling into the star so late remains open. One idea is that giant planets in the system slowly destabilised smaller bodies over billions of years. Another possibility is that a passing star disturbed the orbits of debris. “Future observations with the James Webb Space Telescope or archival data found in the European Space Agency’s Gaia mission could help distinguish between a planetary rearrangement and the gravitational effect of a close stellar encounter,” said John Debes, co-author and researcher at the Space Telescope Science Institute. Dufour noted that hydrogen-rich white dwarfs are the most common type, and the coolest among them are the oldest stars in the galaxy. “We didn't have the habit of looking for signs of accretion in them. This unique case motivates us to expand our search to more of these stars.” The findings show that even after billions of years, planetary systems can remain active and complex. Substantial accretion events—the gradual accumulation of surrounding material onto a celestial object—can still occur long after a star’s death, offering a rare window into the composition and fate of distant worlds. Source: University of Montreal, IOPScience This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing.
    • Doesn't DDG mainly use Bing?
    • Given the hefty price tag this thing will likely have I doubt many everyday home users will be in the market for one especially given the current climate.
    • ESET 19.1.14 by Razvan Serea NOD32 for Windows is the best choice for protection of your personal computer. Almost 20 years of technological development enabled ESET to create state-of-the-art antivirus system able to protect you from all sorts of Internet threats. ESET Internet Security boasts a large array of security features, usability enhancements and scanning technology improvements in defense of your your online life. ESET Internet Security ESET Internet Security keeps your computer or laptop safe with intelligent multi-layered protection combining proven antivirus, antispyware, firewall, anti-rootkit and antispam capabilities. Based on ESET NOD32 Antivirus, it protects you from viruses, worms, spyware, and all Internet threats. It conserves resources and improves computer speed. You are protected at the highest level while you work, social network, play online games or plug in removable media. ESET NOD32 Antivirus Your best defense against viruses, trojans and other forms of malware—and the top choice for IT professionals. Powered by the ThreatSense® engine with advanced heuristics, which blocks far more unknown threats than the competition. The latest generation of the legendary ESET NOD32 Antivirus takes your security to a whole new level. Built for a low footprint, fast scanning, it packs security features and customization options for consistent and personalized security online or off. ESET Smart Security Ultimate protection for everyday web users, thanks to ESET’s trademark best balance of detection, speed and usability. Stay safe from viruses and spyware. Stay protected from ransomware - Blocks malware that tries to lock you out of your own data. Receive free support by email or telephone in your local language, wherever you are. Bank and shop online more safely - automatically secures transactions on internet banking sites, and helps to protect you on online payment gateways. Stop hackers from accessing your PC - Personal Firewall prevents hackers from gaining access to your computer and keeps you invisible when you use public Wi-Fi. Keep your kids safe online - block unwanted internet content by categories or individual websites and keep your kids safe online with Parental Control. Safer webcam and home router - Get an alert when anyone tries to access your webcam, and check your home router for vulnerabilities. Safely store passwords, and encrypt your data. Safely store, generate and prefill your passwords, and encrypt your files and removable media (USB keys). Includes protection for smartphones and tablets. Protect all of your devices - mix and match security protection for up to 3 or 5 devices. ESET Security Ultimate ESET Security Ultimate offers all-in-one protection with antivirus, anti-malware, and anti-phishing features. It includes a personal firewall, secure online banking, and a password manager for enhanced security. Parental controls and data encryption keep family and sensitive information safe. It also provides regular updates to ensure you're always protected against the latest threats. It's user-friendly and ensures comprehensive digital security, perfect for those seeking reliable protection without complexity. ESET 19.1.14.0 changelog: Fixed: GUI crahes Fixed: IPM issues Download: ESET NOD32 Antivirus 64-bit | NOD32 Antivirus 32-bit | ARM 64 | ~ 80.0 MB (Free Trial) Download: ESET Internet Security 64-bit | ESET Internet Security 32-bit Download: Eset Smart Security Premium 64-bit | Eset Smart Security Premium 32-bit Download: ESET Security Ultimate 64-bit | ESET Security Ultimate 32-bit ARM64: Antivirus | Internet Security | Smart Security | ESET Security Ultimate Link: ESET Home Page Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • +1 for Rufus. I bought NTLite a few years ago to scrape all the bloat out of Windows 11. It is not a perfect solution as there is a steep learning curve if you don't really know what you are doing (me included). I have finally got a Windows install that just works. I only keep things I use and nothing else.
  • Recent Achievements

    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
    • Week One Done
      oliviaexpo earned a badge
      Week One Done
    • Week One Done
      eurospharma62 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      491
    2. 2
      PsYcHoKiLLa
      227
    3. 3
      Skyfrog
      66
    4. 4
      Nick H.
      56
    5. 5
      monterxz
      56
  • Tell a friend

    Love Neowin? Tell a friend!