On Friday, December 31, 2004, at 02:28 PM, Rosie wrote:

I'll agree with 99% of what you said especially about the motives of AOL.
I'm not sure I'll agree with you about weather or OS X can be exploited?
However I'll agree with you it's very unlikely to be exploited. Short
version Mac's and OS X just aren't nearly as attractive a target. I think
the thing that makes Linux and OS X a great deal more secure is that when
security issues do arise solutions are quickly implemented.



I have *never, ever* stated that OS X cannot be exploited.

I'm sure there are a host of ways to break into an OSX system, and I'm entirely sure than many are known to people in the community. Plain old social engineering will work...a survey in England showed that a large majority of office workers were willing to surrender their passwords for a pen or a chocolate bar.

(what they don't say is how many of these were in fact the real passwords...if asked, I'd probably give them *a* password...damn straight I'd make something up for free chocolate. Social engineer the social engineers, so to speak)

However, it's just as wrong to keep stating that OS X is simply an 'unattractive target' as if that's the only reason we're not being exploited like Windows.

Believe it or not, Microsoft also quickly implements patches. EVERY one of the major exploits of security holes in Windows over the last few years has come *after* Microsoft has released a patch for the issue. The Code Red exploit had been patched *six months* prior to the release of the Code Red worm.

What is part of the problem is that the architecture of Windows means that code needing to be patched is in a half-dozen different .dll's all of which *do* the same thing, and worse, may even be called the same thing, but are slightly different because Microsoft tacitly, if not explicitly, encouraged developers to modify system libraries to suit their own needs, and by the end no one knows where all the vulnerable code is.

The is part and parcel of the '.DLL Hell' that is Windows, where you have such a spaghetti-like mass of code and interdependent .dlls that in many cases you can't patch things because you don't know what the patch will break. If your business is dependent on that software working, and a patch breaks it, you're in a world of hurt. I doubt this is the case in this example, but look at ComAir's recent meltdown. Imagine if it was because of a Windows update?

There was a Windows update run amok recently that caused an entire Ministry in England to suffer rolling shutdowns of their computer systems. Workers were forced to start managing records on scratch paper to keep their offices running.

A database system self-destructing like that is either due to criminal negligence on the part of the DBAs or reliance on Microsoft software, which I must confess, I also consider criminal negligence on the part of the DBAs. SQL Server is a bare step up from Access, which is the Fisher-Price "My First Database" of databases.

We got hit by SQL Slammer, not because our copy of SQL Server was unpatched (it was), but because our backup software had an embedded version of SQL Server that we didn't even know was *there*.

OS X is not as vulnerable because it is far simpler in architecture. While many programs depend on system services for their behavior, programs do NOT mess around with System software to alter that behavior. Those changes are confined to the program itself, and stored in the specialized folder structure that are programs packages in OS X.

This is why you can delete (or install) a Mac program by dragging it from the Applications folder the Trash.

Witness the notable exception to this behavior? Yep, Microsoft. You cannot uninstall Office X without running the uninstaller program, and dragging the Office X folder to Applications merely means that MS runs their 'installer' automatically when you run the program. Office under the Classic OS was even worse.

Office 6 damn near installed a complete copy of Windows in the System folder...for no good reason; there's no reason that MS had to patch the OS (which is what System extensions are) to run a word processor or spreadsheet.

Is there any doubt left that it is Microsoft's corporate culture that's at fault here?

--
"Wherever you go, there you are." - B. Banzai, Ph.D.
Bruce Johnson



--
PCI-PowerMacs is sponsored by <http://lowendmac.com/> and...

Small Dog Electronics    http://www.smalldog.com  | Refurbished Drives |
-- Sonnet & PowerLogix Upgrades - start at $169   |  & CDRWs on Sale!  |

     Support Low End Mac <http://lowendmac.com/lists/support.html>

PCI-PowerMacs list info: <http://lowendmac.com/lists/pci-powermacs.shtml>
 --> AOL users, remove "mailto:";
Send list messages to:   <mailto:[email protected]>
To unsubscribe, email:   <mailto:[EMAIL PROTECTED]>
For digest mode, email:  <mailto:[EMAIL PROTECTED]>
Subscription questions:  <mailto:[EMAIL PROTECTED]>
Archive:<http://www.mail-archive.com/pci-powermacs%40mail.maclaunch.com/>

iPod Accessories for Less
at 1-800-iPOD.COM
Fast Delivery, Low Price, Good Deal
www.1800ipod.com

Reply via email to