One for Robert

All non-Go discussions should go here.
hyperpape
Tengen
Posts: 4382
Joined: Thu May 06, 2010 3:24 pm
Rank: AGA 3k
GD Posts: 65
OGS: Hyperpape 4k
Location: Caldas da Rainha, Portugal
Has thanked: 499 times
Been thanked: 727 times

One for Robert

Post by hyperpape »

"Windows is currently the most secure mainstream OS. I mean, we can’t stand _using_ it, but that doesn’t change the facts." --the grucq (exploits merchant, opsec expert).
DrStraw
Oza
Posts: 2180
Joined: Tue Apr 27, 2010 4:09 am
Rank: AGA 5d
GD Posts: 4312
Online playing schedule: Every tenth February 29th from 20:00-20:01 (if time permits)
Location: ʍoquıɐɹ ǝɥʇ ɹǝʌo 'ǝɹǝɥʍǝɯos
Has thanked: 237 times
Been thanked: 662 times
Contact:

Re: One for Robert

Post by DrStraw »

hyperpape wrote:"Windows is currently the most secure mainstream OS. I mean, we can’t stand _using_ it, but that doesn’t change the facts." --the grucq (exploits merchant, opsec expert).
Secure as in you cannot escape from it once it has you in its clutches.
Still officially AGA 5d but I play so irregularly these days that I am probably only 3d or 4d over the board (but hopefully still 5d in terms of knowledge, theory and the ability to contribute).
RobertJasiek
Judan
Posts: 6273
Joined: Tue Apr 27, 2010 8:54 pm
GD Posts: 0
Been thanked: 797 times
Contact:

Re: One for Robert

Post by RobertJasiek »

Windows and Linux can be configured the most securely. The degree of security depends on the Windows version. Windows 10 creates the subproblem to consider privacy violations by Windows itself. For out-of-the-box use, iOS might be the most secure in practice for careless users, however, other attack vectors, such as social engineering or state hackers breaking encryption thanks to too short pass codes, remain. The best security combines remote backups with separation from the internet.
longshanks
Dies with sente
Posts: 97
Joined: Sat Nov 22, 2014 1:51 am
GD Posts: 0
Been thanked: 14 times

Re: One for Robert

Post by longshanks »

hyperpape wrote:"Windows is currently the most secure mainstream OS. I mean, we can’t stand _using_ it, but that doesn’t change the facts." --the grucq (exploits merchant, opsec expert).
Most secure mainstream OS? This could be argued (Windows 10 is certainly the most secure *Windows* OS) though I'd like to see the rationale for it being strongest overall as it's weaker in many aspects such as privacy (thanks Cortana!).

Most secure non-mainstream OS? Nope. Not by a long way.
Bill Spight
Honinbo
Posts: 10905
Joined: Wed Apr 21, 2010 1:24 pm
Has thanked: 3651 times
Been thanked: 3373 times

Re: One for Robert

Post by Bill Spight »

RobertJasiek wrote:Windows 10 creates the subproblem to consider privacy violations by Windows itself.
I love Big Brother.
The Adkins Principle:
At some point, doesn't thinking have to go on?
— Winona Adkins

Visualize whirled peas.

Everything with love. Stay safe.
RobertJasiek
Judan
Posts: 6273
Joined: Tue Apr 27, 2010 8:54 pm
GD Posts: 0
Been thanked: 797 times
Contact:

Re: One for Robert

Post by RobertJasiek »

longshanks wrote:being strongest
There is no such thing as an OS always having the same security. It always depends on how it is configured and used.
longshanks
Dies with sente
Posts: 97
Joined: Sat Nov 22, 2014 1:51 am
GD Posts: 0
Been thanked: 14 times

Re: One for Robert

Post by longshanks »

Bill Spight wrote:
RobertJasiek wrote:Windows 10 creates the subproblem to consider privacy violations by Windows itself.
I love Big Brother.
Get yourself a Smartphone or just move to the UK then ;-)
longshanks
Dies with sente
Posts: 97
Joined: Sat Nov 22, 2014 1:51 am
GD Posts: 0
Been thanked: 14 times

Re: One for Robert

Post by longshanks »

RobertJasiek wrote:
longshanks wrote:being strongest
There is no such thing as an OS always having the same security. It always depends on how it is configured and used.
Some OSes come in different flavours. For e.g. Debian doesn't come very secure out of the box as it's general purpose (and some of its defaults are odd -- no firewall rules, all home directories readable by every user, sub-optimal config of for things like ssh etc.). Tails however, is a security-focused version of Debian. All of this is agreeing with what you wrote above. It's just the distro maintainer is doing the configuring for you. You can still come along and wreak it (install Flash, Java, change good defaults to bad ones..) but you have to be determined. Whereas with non-secure defaults you have to harden -- which people generally don't know how to do or know that they even need to do.

OpenBSD is an OS that is designed from the ground up with security in mind first. One remote exploit in ten years? Windows 10 might well be the most secure mainstream OS, but let's see how the CVEs tally at the end of 2016.. I know which one I want controlling my lift :)
hyperpape
Tengen
Posts: 4382
Joined: Thu May 06, 2010 3:24 pm
Rank: AGA 3k
GD Posts: 65
OGS: Hyperpape 4k
Location: Caldas da Rainha, Portugal
Has thanked: 499 times
Been thanked: 727 times

Re: One for Robert

Post by hyperpape »

As I get older, my sense of what's "now" spreads out. This talk was from 2012, so it's Windows 7, maybe 8 days. Pre-cortana and all that. And he mentions Linux critically before mentioning Windows but never mentions any of the BSD families.

Anyway, here's the presentation (http://www.slideshare.net/grugq/opsec-for-hackers). It just jumped out at me because I remember people being incredulous that Robert is very concerned about security, but used Windows.
User avatar
Bantari
Gosei
Posts: 1639
Joined: Sun Dec 06, 2009 6:34 pm
GD Posts: 0
Universal go server handle: Bantari
Location: Ponte Vedra
Has thanked: 642 times
Been thanked: 490 times

Re: One for Robert

Post by Bantari »

I think that "security" is a very wide subject, and we need to specify what exactly it means in this context. Below are a few examples of what I am talking about:

- prevention of targeted hacking
- prevention of adware, malware, and viruses
- data safety and persistence
- overall system stability
- etc.

In each of the cases "security" means something slightly different, and the system might have to be configured differently depending on what we mean. Some configurations which might help one issue, might damage another one, so it is important we know what we want. For example, data persistence can be helped by off-site storage (cloud?) but this might lower the hacking resilience.

Generally, I would not trust Windows very much, Win10 or any other flavor. Not because it is so bad necessarily (I think Win10 is OK for a Win OS) - but because it is by far the most popular platform, and so most hacking, addware, malware, and viruses will be targeted at it, and the most effort will be done to circumvent any security on it. Its just common sense - the most bang for the buck! Why target a 2% system if you can target a 90% system? Win10 is still relatively new, so it might be secure now, but just give it some time...

So, which kind of security do we mean? Or all of it?
- Bantari
______________________________________________
WARNING: This post might contain Opinions!!
User avatar
Bantari
Gosei
Posts: 1639
Joined: Sun Dec 06, 2009 6:34 pm
GD Posts: 0
Universal go server handle: Bantari
Location: Ponte Vedra
Has thanked: 642 times
Been thanked: 490 times

Re: One for Robert

Post by Bantari »

DrStraw wrote:Secure as in you cannot escape from it once it has you in its clutches.
Heh... There is more truth to that than most people think.

As a gamer, I desperately tried to avoid Windows for years.
But finally, I had to give in and buy me a Win laptop. <head hanging in shame>
- Bantari
______________________________________________
WARNING: This post might contain Opinions!!
RobertJasiek
Judan
Posts: 6273
Joined: Tue Apr 27, 2010 8:54 pm
GD Posts: 0
Been thanked: 797 times
Contact:

Re: One for Robert

Post by RobertJasiek »

Bantari, percentage of tried attacks means very little. What matters is frequency of successful attacks for a given OS, configuration and use. E.g., a very frequent kind of attack is email attachments. By, e.g., never automatically or manually opening any attachment, zero such attacks are successful.
sybob
Lives in gote
Posts: 422
Joined: Thu Oct 02, 2014 1:56 pm
GD Posts: 0
KGS: captslow
Online playing schedule: irregular and by appointment
Has thanked: 269 times
Been thanked: 129 times

Re: One for Robert

Post by sybob »

RobertJasiek wrote:Bantari, percentage of tried attacks means very little. What matters is frequency of successful attacks for a given OS, configuration and use. E.g., a very frequent kind of attack is email attachments. By, e.g., never automatically or manually opening any attachment, zero such attacks are successful.
Humans are still the biggest risk factor.
User avatar
Bantari
Gosei
Posts: 1639
Joined: Sun Dec 06, 2009 6:34 pm
GD Posts: 0
Universal go server handle: Bantari
Location: Ponte Vedra
Has thanked: 642 times
Been thanked: 490 times

Re: One for Robert

Post by Bantari »

RobertJasiek wrote:Bantari, percentage of tried attacks means very little. What matters is frequency of successful attacks for a given OS, configuration and use.
You misunderstood. I was not talking about percentages of attack, although this is certainly part of it as a logical consequence.

My point was this:
Windows users are the biggest target. Therefore, the most time and the most resources are invested in breaching Windows security. Therefore, its security is breached the most. Therefore, it is by definition a less secure system - even if in feature-by-feature comparison it might hold its own. This is all I am saying.

Or, in other words, there are not as many viruses written for Ubuntu as there are for Windows. And this will hold in the future indefinitely, I think.
E.g., a very frequent kind of attack is email attachments. By, e.g., never automatically or manually opening any attachment, zero such attacks are successful.
This is a trivial example, not sure what you wish to illustrate.
By the same token you can say that you can avoid absolutely all attacks if you never turn your computer on.
- Bantari
______________________________________________
WARNING: This post might contain Opinions!!
User avatar
Fedya
Lives in gote
Posts: 603
Joined: Tue Apr 20, 2010 8:21 pm
Rank: 6-7k KGS
GD Posts: 0
Has thanked: 43 times
Been thanked: 139 times

Re: One for Robert

Post by Fedya »

Image

(They should, of course, just guess "correcthorsebatterystaple" for his password.)
Post Reply