The headline of the article I've linked below is spot-on. Security isn't about measures taken by the operating system any longer, it's about measures taken by users themselves.
For instance, as an IT professional with a good knowledge of computer security practices, if I wanted to I could work every day with Windows and remain malware-free just by being conscientious about what I do with the computer. Windows is certainly an unstable house of cards in that regard, but if you know how to use it you can be just as safe as anyone else, even without anti-malware software installed.
Even OS X has recently had an outbreak of malware, but it requires unwary users to install unverified software in order to infect machines. I still maintain that it requires a much less watchful eye on system processes to keep a Mac clean, but it is by no means immune.
However, I do take issue with the final paragraphs of the linked article. It's true that Microsoft is still the biggest target, and that very fact makes exploitation more lucrative and therefore more likely to be attempted. However, the underpinnings of the operating system still rely on legacy code with a much more relaxed security model. The Unix architecture on which OS X is based is by far a much more stable design.
Windows isn't attacked day and night merely because it's got larger market share; while that's a contributing factor, it's also got many more exploitable attack vectors. And, as John Gruber has pointed out in the past, OS X isn't "utterly impervious to attack because it’s protected by magic leprechauns." It's just better.
But, to reiterate the main point here, either one is only as secure as its users, who have to be quite a bit more fastidious if they've got a Windows machine on their desk.
When it comes to security, it's the user, not the OS | Macworld
Thursday, June 3
Security: Not the fault of the OS anymore
Posted by augmentedfourth at 11:01 AM 0 responses
tags: computer, daringfireball, osx, security, windows
Sunday, February 28
Geek code - why do I do this, again?
So, it was pointed out to me today that my current Geek Code, shown at the bottom of every page of this blog, is significantly out of date. As I always mention when publishing these updates, version 3.12 of the Code was formulated in 1996, so my available options for the various categories aren't particularly reflective of how things really work in the world these days.
In any case, here's my new Code:
-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GIT/MU d+@ s:+>: a->+++ C++> ULXB++++$ L+++ M++ w--() !O !V P++ E--- W+++
N o++ K? PS PE+ Y+ PGP++ t !5 X- R- tv+@ b++ DI++++ D--- G++ e*++ h r? y?
------END GEEK CODE BLOCK------
If you really care about knowing what that all means, you either know the code already, or you can get it decoded for you here.
Thursday, January 8
Windows is officially irrelevant
In a NYT piece this morning, Microsoft CEO Steve Ballmer argues that the upcoming "Windows 7" will be important. However, this paragraph from the article just made me laugh:
He added, however, that Windows 7 should not have the same sort of problems with compatibility with devices and programs that Vista did. While some of underlying architecture of Vista changed from earlier versions of Windows, Windows 7 is built on Vista’s underlying structure.
That means that users upgrading from Vista to Windows 7 won't experience any problems. However, anyone that didn't upgrade to Vista because of the compatibility problems will still face the exact same roadblocks if they try to use Windows 7.
He's assuming that all his customers are using the latest version and just might just have had some problems getting it to work. But in my lab, I still have all the workstations running Windows XP. I was hoping the next version of Windows would respond to criticism from the cautious and provide a cleaner upgrade path from XP, but based on this report of Ballmer's CES keynote I'm no longer optimistic.
Thankfully, our use of XP is just a fallback measure for a few pieces of software that aren't cross-platform; Linux is our main operating system and will continue to be for the foreseeable future.
Ballmer: Windows Is Still Relevant - Bits Blog - NYTimes.com
Posted by augmentedfourth at 10:36 AM 2 responses
Tuesday, January 1
OS Virtualization on a Mac: Parallels vs. VMWare
Now that Apple's computers use Intel processors like the rest of the desktop computing world, it's become easy for Mac users to run other operating systems in tandem with OS X. Sure, PowerPC Macs can dual-boot certain Linux distributions that distribute a compatible version, but a lot of Linux software packages are written only for Intel's x86 platform.
With the change in processor architecture, a Mac can run all the mainstream desktop operating systems... including Windows, if you want. In fact, you no longer even have to reboot the computer to switch the running OS; virtualization software is now available to let you boot a virtual "guest" system within your OS X "host."
The two competing commercial programs for virtualization within OS X are Parallels Desktop and VMWare Fusion. (There are a few free-software alternatives, but I haven't successfully used any of them.) It seems that VMWare and Parallels are both very good at what they do, and they seem to be playing a constant game of leapfrog such that "who's better" is constantly switching sides.
It was really hard to make a distinction between the two, but after reading an intense comparison on MacTech.com I discovered that:
- Parallels is a little bit faster than VMWare
- However, the faster the "host" Mac, the less speed difference there is between them
- VMWare is much better at virtualizing operating systems other than Windows (i.e. Linux)
Since I have a fast, recent Mac, and I plan to run a lot of Linux virtual machines, that clinched it for me. In fact, I ran into a poll on MacResearch.org that showed that people virtualizing Windows tend to go for Parallels those running Linux VMs tend to go for VMWare. Since my primary application will be Linux virtualization, I bought VMWare. I tested it before I bought it, and it's been running the latest version of Fedora (one of my favorite Linux distributions) just great. It also looks like I'll have plenty of cool features whenever I decide to start virtualizing Windows.
And, since I bought in 2007 (December 31, but it counts), it looks like I'll be able to take advantage of a $20 VMWare rebate as well. The website says it'll take a few days for my order to be fully processed and for my rebate eligibility to be verified, but it looks like it will go through.
Tuesday, November 21
Computer Security: Is Windows Worth It?
I recently read an article in USA Today about the measures people take to secure their Windows PCs. Since switching to the Mac a few years ago, I can't help but shudder when I remember the attention I had to pay just to keep the machine running smoothly. Just keeping up with Microsoft's security updates on my wife's Windows laptop (she needed it for work) is difficult.
There are so many options: you can shell out money for anti-malware utilities ("malware" is a term that encompasses all malicious software, from viruses to worms to spyware), or you can find comparable software for free if you know where to look. But even once the software has been installed, you still need to diligently check the Internet for updates; otherwise, your money and/or effort is rendered useless.
And then I look at my Mac. It's a great machine: it does almost anything you would require right out of the box (aside from a few small shareware and donationware products, the only Mac software I've purchased is Microsoft Office), and it's got an inherently better security system than the one found in Windows.
As the linked article testifies, I don't mean to imply that Macs are somehow immune to intrusion. As John Gruber puts it:
The explanation that makes sense is the obvious one: that Mac OS X really is more secure and better designed. Not that it’s totally secure. Not that it’s perfectly designed. Not that it is utterly impervious to attack because it’s protected by magic leprechauns. Just that it’s better.As disheartened as I am by the state of Windows security, I can say that there really is a better option for the average user. (The fact that it's also a really cool option for advanced users is an added benefit.) Mac OS X really does make a home computer easy to operate, easy to maintain, and-- thanks to its thoughtful design-- pretty darn easy on the eyes as well.
Links mentioned in this post:
As far as PC security, Goldilocks got it just right (USA Today)
Jackass of the Week: Larry Seltzer (Daring Fireball)
This work is licensed under a Creative Commons Attribution-
The Geek Code desperately needs updating, but in any case here's mine (as of 2010-02-28):
-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GIT/MU d+(-) s:+>: a C++> ULXB++++$ L+++ M++ w--() !O !V P+ E---
W+++ N o++ K? PS PE++ Y+ PGP t !5 X- R- tv+@ b++ DI++++ D--- e*++
h--- r+++ y+++ G+
------END GEEK CODE BLOCK------
If you really care about knowing what that all means, you either know the code already, or you can get it decoded for you here.