Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Windows Vista still Rife with Insecure Code

Posted by Zonk on Tue Jul 18, 2006 12:24 PM
from the rife-i-say dept.
osxpetition writes "As noted in a News.com article, Symantec researchers have been testing the latest Microsoft Windows Vista build (Beta 2), and have found that the code is 'complete with new corner cases and defects' in the networking component. Symantec describes how Microsoft scrapped the old networking stack code from Windows XP in favour of newer, rewritten code. 'Microsoft has removed a large body of tried and tested code and replaced it with freshly written code.' Since January 2002, Microsoft has put a stronger emphasis on protecting PCs by attempting to implement stable, secure code into Windows XP and their new operating system. This latest report from Symantec brings attention to Microsoft's trustworthy computing campaign, and shows how it will be a long way before it is ready for the mainstream."
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • beta (Score:3, Insightful)

    It is still beta, right?
    • Re:beta (Score:4, Funny)

      by creimer (824291) on Tuesday July 18 2006, @12:35PM (#15738007)
      (http://www.creimer.ws/ | Last Journal: Friday January 26 2007, @12:40PM)
      No, it's the super-alpha-beta-gold-release-candidate build.
      [ Parent ]
      • Re:beta by edmicman (Score:2) Tuesday July 18 2006, @12:55PM
        • Re:beta by Da_Weasel (Score:1) Tuesday July 18 2006, @01:45PM
          • Re:beta (Score:4, Funny)

            by powerlord (28156) on Tuesday July 18 2006, @01:48PM (#15738644)
            I try to only use the Vista Vapourware-2005 Edition.

            Its the only one I've found to be compatible with Duke Nukem Forever RC1.
            [ Parent ]
    • Re:beta by Alkrun (Score:2) Tuesday July 18 2006, @01:23PM
      • Re:beta by RobertLTux (Score:2) Tuesday July 18 2006, @05:20PM
        • Re:beta by fbjon (Score:1) Wednesday July 19 2006, @06:46AM
      • Re:beta by kubevubin (Score:2) Tuesday July 18 2006, @05:35PM
        • Re:beta (Score:5, Insightful)

          by kimvette (919543) on Tuesday July 18 2006, @06:48PM (#15740417)
          (http://kim.biyn.com/)
          Linux users need to stop comparing their OS' state to that of a five-year-old version of Windows.


          Okay, compare it to the current release of Windows.

          Oh, what's that? The newest release is Windows XP OEM SR2? Essentially a five-year-old OS with a few patches?

          I guess it IS a fair comparison then, after all. Come make that same argument this same time next year if both:

          a) Vista has shipped
          AND
          b) Folks are comparing Linux to XP rather than Vista

          at that point. Until then, XP is the only valid comparison, unless you want to talk servers in which case Windows 2003 would be the logical comparison point.
          [ Parent ]
          • Re:beta by kubevubin (Score:2) Tuesday July 18 2006, @08:45PM
            • Re:beta by Jesus_666 (Score:2) Wednesday July 19 2006, @05:23AM
            • Re:beta by kubevubin (Score:2) Wednesday July 19 2006, @07:06PM
            • 2 replies beneath your current threshold.
          • 1 reply beneath your current threshold.
        • Re:beta by rblancarte (Score:3) Tuesday July 18 2006, @06:49PM
      • 3 replies beneath your current threshold.
    • Re:beta by jocknerd (Score:3) Tuesday July 18 2006, @01:38PM
      • Re:beta (Score:5, Informative)

        by CaymanIslandCarpedie (868408) on Tuesday July 18 2006, @02:59PM (#15739155)
        (Last Journal: Sunday July 01, @08:03AM)
        FTA:Symantec researchers put the networking technology in Vista under a magnifying glass to determine its exposure to external attacks. The team said it found several flaws in build 5270 of Vista and even more in earlier test versions. However, these were all fixed by Microsoft in build 5384, the version of the operating system that was publicly released in May as Beta 2.

        For those too lazy to read the article all it really says is. We found a few issues in early releases of Vista. They've already all been fixed by Beta 2, but we are guessing there are probably more.
        [ Parent ]
    • Re:beta by Rethcir (Score:1) Tuesday July 18 2006, @02:24PM
    • Re:beta by NSIM (Score:1) Tuesday July 18 2006, @02:42PM
      • Re:beta by jlarocco (Score:2) Tuesday July 18 2006, @08:07PM
        • Re:beta by NSIM (Score:1) Wednesday July 19 2006, @05:47AM
    • Re:beta by DSW-128 (Score:1) Tuesday July 18 2006, @01:41PM
    • 1 reply beneath your current threshold.
  • Too secure! (Score:5, Funny)

    by eth00 (612841) on Tuesday July 18 2006, @12:27PM (#15737927)
    (http://www.eth0.us/)
    They figured out that the old network stack was starting to get too secure and not something they could live with! Not wanting to break the trend of security problems they went ahead and rewrote the code from scratch
    • You joke, but by Anonymous Coward (Score:1) Tuesday July 18 2006, @12:45PM
      • Re:You joke, but by Anonymous Coward (Score:3) Tuesday July 18 2006, @12:59PM
        • Re:You joke, but (Score:5, Interesting)

          by DroppedPacket (621464) on Tuesday July 18 2006, @02:03PM (#15738745)
          OK, I have to bite on this:
          In fact, I think it's the only way to explain how many security bugs are in Windows.

          I think you perhaps need to take some lessons in critical thinking. This is the equivelent of saying, "The only reason auto-manufactuers put problems into cars so they have to recall them is because the government makes them, which is why Japanese cars are better than American cars."

          Large monolithioc systems are inherently more complex that smaller componant built systems. (Although those have problems too along the boundary interfaces.) Auto-makers put lots of time and money into making a car that A) doesn't fall apart and B) doesn't require a multi-billion dollar recall effort. Microsoft puts lots of time and money into trying to make their software more secure.

          On the whole, I'd say the auto companies do a better job. :-) Thowing money at a problem very rarely solves the problem. The need to have an understanding of the problem, and how to fix the underlying problem is vital. I think that is where Microsoft fails. The systems they have in place (from what I hear) are more frustrating to the engineers than helpful.

          I also have problems believing MS engineers are really motivated these days. Many of Microsoft's security issues have stemmed from their own code interactions which they implemented as deliberate features. Many more have been from sloppy programming (such as buffer overruns).

          Trying to blame MS security issues on government mandated back doors smacks of plain political diatribe with a nice glossy veneer of ignorance on the top to give it a nice sheen.

          [ Parent ]
          • Re:You joke, but by cosmicj (Score:1) Tuesday July 18 2006, @03:28PM
          • Re:You joke, but (Score:4, Insightful)

            by causality (777677) on Tuesday July 18 2006, @03:56PM (#15739562)
            I think you perhaps need to take some lessons in critical thinking. This is the equivelent of saying, "The only reason auto-manufactuers put problems into cars so they have to recall them is because the government makes them, which is why Japanese cars are better than American cars."

            My critical thinking skills tell me that this is a false analogy because the government has no incentive to make automobile manufacturers issue recalls, and really the attorneys and enforcement and regulations involved would make this nothing but an expense for the government. When consumer protection laws are enforced, the governmental officials involved can at least claim that they are doing this to benefit the public, even when doing so does further someone's personal agenda.

            The situation as described by the A.C. is where the government requires backdoors so that its own governmental snoops (law enforcement and possibly more shady, less accountable organizations) can easily access systems that would otherwise be difficult to access due to security protections. This directly benefits the government because it makes their legitimate law enforcement job easier and it also makes less legitimate ventures (potential data mining, eavesdropping, etc) much easier and has the nice side-effect of eliminating some of the need to do old-fashioned police work. This scenario certainly does not benefit the users of Microsoft software and so the intent shown is nothing like your analogy. If this is actually happening, then this is a very dangerous precedent for two reasons: One, if the government can use such a backdoor, so can anyone else who learns of it; two, the job of law enforcement was not intended to be easy and efforts to make it an easy job immediately preceded the rise of most totalitarian states that existed during the 20th century (at the risk of invoking Godwin's Law, Nazi Germany and the USSR did not take place due to powerless and ill-informed police forces).

            Further, when speaking about Windows you are dealing with proprietary, closed-source software. You and I simply do not know with 100% certainty whether or not there actually is such a backdoor in any of the Windows code, nor do we know what agreements Microsoft has made with which governments. What you can know is that we are in an era where privacy is on the decline and law enforcement powers are increasing, and being able to easily access over 90% of all desktop computer systems does fit the stated purpose of programs that we do know about, such as the NSA wiretap program. To say that we already know about every possible threat to privacy and that the statists who desire this kind of surveillance are now satisfied and will not be seeking further powers is a lofty claim indeed. Study history and you will observe that the USA has a bad case of "it can't happen here" regarding foreseeable abuses of power.

            Also, unmotivated programmers and undocumented backdoors are not mutually exclusive. It is possible that they both contribute to the sad state of security in Microsoft's code. It is also possible that neither are true and that some third factor (such as program design being dominated by marketing and forcing otherwise good programmers to work within these parameters) can explain the lack of security. But to observe that the possible existence of unmotived programmers could explain the situation and then claim that this is a valid reason to dismiss other arguments out-of-hand does not fit the spirit of critical thinking that you mentioned earlier.

            But it does indicate that maybe, just maybe, you live in the USA and are in denial about the direction towards which it is headed.
            [ Parent ]
          • Re:You joke, but by eonlabs (Score:2) Tuesday July 18 2006, @10:10PM
          • Re:You joke, but by 10101001 10101001 (Score:1) Wednesday July 19 2006, @05:01AM
          • Re:You joke, but by heybo (Score:2) Wednesday July 19 2006, @09:34AM
          • 1 reply beneath your current threshold.
        • Re:You joke, but by juan2074 (Score:1) Tuesday July 18 2006, @02:16PM
        • Re:You joke, but by drsmithy (Score:2) Tuesday July 18 2006, @05:03PM
        • But what about Linux? by mcrbids (Score:2) Wednesday July 19 2006, @02:29AM
          • Straw man by ravenlock (Score:1) Wednesday July 19 2006, @08:37AM
      • Re:You joke, but (Score:4, Insightful)

        by HoboMaster (639861) on Tuesday July 18 2006, @12:59PM (#15738223)
        Jeez man, paranoid much? You really think Microsoft could care less about most of these countries? They won't respect their court rulings, but they allow not just one, but multiple, back doors to be programmed in? And why would they do that? What is Microsoft getting out of the deal?

        DA GUBBERMINT WANTS MAH TEEFS!!! RUUUN!
        [ Parent ]
        • Re:You joke, but (Score:4, Insightful)

          by Clover_Kicker (20761) <clover_kicker@yahoo.com> on Tuesday July 18 2006, @01:07PM (#15738281)
          > hey won't respect their court rulings, but they allow not just one, but
          > multiple, back doors to be programmed in? And why would they do that? What
          > is Microsoft getting out of the deal?

          (dons tinfoil hat)

          A free ride on the court rulings?

          [ Parent ]
        • Re:You joke, but by plantman-the-womb-st (Score:1) Tuesday July 18 2006, @01:40PM
        • 1 reply beneath your current threshold.
      • 1 reply beneath your current threshold.
    • Fun-factor by Valacosa (Score:3) Tuesday July 18 2006, @01:02PM
      • Re:Fun-factor (Score:5, Insightful)

        by cnettel (836611) on Tuesday July 18 2006, @02:00PM (#15738728)
        To be fair, the original design of NT networking was focused on IPX and NetBEUI. The bandwidth was 10 Mbit. If you routed in several steps, you didn't expect minimal latencies. You were also supposed to kind of trust the traffic on the network (no SYN attacks or stuff like that.) IPv6 on current Windows versions still has "it will kind of work" status. You don't start with MS-DOS and end up with XP. You end up with Me. Rewriting something because the old version is broken is highly unwise. Rewriting something because the old version is unappropriate for what you currently use it for might make sense. I remember the JWZ article and he talks about all the hidden assumptions you've found through hard work and how those are an essential value in the current codebase. If enough of those assumptions are not true anymore, it can make sense to rewrite something.
        [ Parent ]
        • Re:Fun-factor (Score:4, Interesting)

          by Foolhardy (664051) <[csmith32] [at] [gmail.com]> on Tuesday July 18 2006, @03:15PM (#15739275)
          Just to be clear, NT has always supported TCP/IP. In fact, KB article Q12823 [microsoft.com] compares available protocols circa NT 3.1 and 3.51.

          From the October 2000 MSDN magazine, "Windows Sockets 2.0: Write Scalable Winsock Apps Using Completion Ports" [microsoft.com]
          Unlike some other operating systems, the Windows NT and Windows 2000 transport protocols do not have a sockets-style interface which applications can use to talk to them directly. Instead, they implement a much more general API called the Transport Driver Interface (TDI). The generality of this API keeps the subsystems of Windows NT from being tied to a particular flavor-of-the-decade network programming interface. The Winsock kernel mode driver provides the sockets emulation (currently implemented in AFD.SYS). This driver is responsible for the connection and buffer management needed to provide a sockets-style interface to an application. AFD.SYS, in turn, uses TDI to talk to the transport protocol driver.
          Ironically, it's TDI that's being replaced for something more sockets-like.

          I think this is yet another example of Microsoft not understanding code that was previously written by someone no longer available, causing the new developers to misunderstand the original design, who then feel the only option is a rewrite. I've yet to hear any technical comparisons between TDI and "Next Generation TCP/IP", showing how the TDI architecture could never do those things. I bet TDI can support these new features with some new code, but it just wouldn't be as glamorus that way.

          To adapt an old saying about LISP and UNIX, "Those who fail to understand NT are doomed to reimplement it. Poorly"
          [ Parent ]
          • Re:Fun-factor by cnettel (Score:2) Wednesday July 19 2006, @02:57AM
            • Re:Fun-factor by Foolhardy (Score:2) Wednesday July 19 2006, @08:41PM
        • Re:Fun-factor by ComputerSlicer23 (Score:2) Tuesday July 18 2006, @09:30PM
          • Re:Fun-factor by cnettel (Score:1) Wednesday July 19 2006, @02:48AM
      • Re:Fun-factor by Simon Garlick (Score:2) Wednesday July 19 2006, @12:44AM
    • 2 replies beneath your current threshold.
  • And we... (Score:4, Insightful)

    by vwjeff (709903) on Tuesday July 18 2006, @12:27PM (#15737930)
    have a solution that will "protect" you.
    • Re:And we... by Elektroschock (Score:2) Tuesday July 18 2006, @01:34PM
    • Re:And we... by jellomizer (Score:2) Tuesday July 18 2006, @03:20PM
    • 1 reply beneath your current threshold.
  • I would like to know by giorgiofr (Score:2) Tuesday July 18 2006, @12:27PM
    • Re:I would like to know (Score:5, Informative)

      by kevin_conaway (585204) on Tuesday July 18 2006, @12:34PM (#15738002)
      (http://pyscrabble.sf.net/)
      I would like to know If the so-called shatter attack still works in Vista. If it does, no amount of privilege limitation can help you.

      Since you didn't provide any useful context to your question, allow me. From here [biznix.org]:

      Chris Paget says there is an irreparable hole in Win32. Any application can send a message to any window on the same desktop regardless of whether or not the window is owned by the application, and there is no authentication mechanism to prevent this from happening. Paget has published a white paper describing a "shatter attack" which allows an attacker to gain control of a system by elevating his or her privileges. Microsoft says this does not fit their criteria/definition of a security vulnerability.
      [ Parent ]
    • Re:I would like to know (Score:5, Informative)

      by NutscrapeSucks (446616) on Tuesday July 18 2006, @12:38PM (#15738049)
      Shatter attack are a configuration error, not a OS issue. They are roughly similar to running xterm as root on Unix and then complaining that users can execute root commands.

      But apparently Vista has entirely removed the idea of an "interactive service", so they won't work. Info here: http://blogs.msdn.com/larryosterman/archive/2005/0 9/14/466175.aspx [msdn.com]
      [ Parent ]
    • Shatter attack (Score:5, Informative)

      I had never heard of such a thing before (actually, initially I thought you were just punning on Windows + 'shattering', har har).

      It would seem that Vista allegedly fixes the design flaw that allows for the attack, by not running system services in the same session as the user. At least, that seems to be what the Wikipedia article on the topic [wikipedia.org] is suggesting.

      The key to shatter attacks is that Windows allows processes running in the same session to pass messages between each other, the result of which is that via code injection, any process can escalate up to the level of the highest process also running in its session. MS is quoted in the article as saying "[This is not] a flaw in Windows. In reality, the flaw lies in the specific, highly privileged service. By design, all services within the interactive desktop are peers, and can levy requests upon each other. As a result, all services in the interactive desktop effectively have privileges commensurate with the most highly privileged service there." (Which is amusingly doublespeak-ish; they're saying "this isn't a design flaw, we designed it that way!")

      This blog post by a member of the IE7 team [msdn.com] would confirm that they've at least tried to address this in Vista (but of course that's what you'd expect them to say). It says: "User Interface Privilege Isolation (UIPI) blocks lower-integrity from accessing higher-integrity processes. For example, a lower-integrity process cannot send window messages or hook or attach to higher priority processes This helps protect against "shatter attacks." A shatter attack is when one process tries to elevate privileges by injecting code into another process using windows messages."

      Yet another nice legacy "feature" from the single-user-OS days.
      [ Parent ]
    • Re:I would like to know (Score:5, Interesting)

      by ThinkFr33ly (902481) on Tuesday July 18 2006, @01:16PM (#15738363)
      This "shatter attack" has been known about and acknolwedge for MANY YEARS. (Long before the 2002 paper cited in this thread.) Every once in a while people will bring it up as proof that Windows has design flaws.

      This was a design decision with known trade-offs. Attaching security tokens to window messages would result in MAJOR overhead that would, even on today's beefy hardware, kill performance. Having to do a permissions check every time the mouse is moved is not feasible.

      So Microsoft decided that they would rely on "best practices" information as apposed to enforced security in the OS to prevent "shatter attacks". The best practices are pretty simple: If your service/application is running with elevated permissions (such as SYSTEM), do not display a GUI on a desktop owned by a lower privledged user.

      There have been examples of applications, in particular some poorly written anti-virus applications, that liked to display GUIs to the user despite the fact they were running as SYSTEM. For the most part, however, very few major applications exist today that have this issue.

      Applications that run with high privs that need to display a GUI typically launch their GUI with the privs of the user, or display the GUI on a secure desktop. (Like Winlogon.exe.)

      This is really a non-issue and hasn't been for a very long time. Please, ignore the FUD.
      [ Parent ]
    • Re:I would like to know by Keeper (Score:1) Tuesday July 18 2006, @01:47PM
    • Re:I would like to know by man_of_mr_e (Score:2) Tuesday July 18 2006, @02:15PM
    • 1 reply beneath your current threshold.
  • I wish I could mod this story -1 Redundant. by BlackCobra43 (Score:2) Tuesday July 18 2006, @12:28PM
  • And the solution? by Anonymous Coward (Score:2) Tuesday July 18 2006, @12:28PM
  • Is this news? (Score:3, Insightful)

    by brennz (715237) on Tuesday July 18 2006, @12:28PM (#15737941)
    Marketing deadlines always trumps everything else, except for OpenBSD and maybe Linux kernels. Curiously, both have dominant but benevolent personalities in charge......
  • However (Score:5, Insightful)

    by also-rr (980579) on Tuesday July 18 2006, @12:30PM (#15737958)
    (http://www.revis.co.uk/)
    This may not be a bad thing.

    I am much happier with well laid out, structured and simple code that has X rate of defects than well polished over the years, old, cruddy and complex with X rate of defects because with the former:

    Fixes will be faster.
    Fixes will be easier/cheaper.
    Fixes will be possible!
    Bug fixes will have less chance of introducing new bugs.

    Given time we can then be sure that we will end up with... err well polished over the years, old, cruddy and complex. But it probably won't be as bad as if the process never happened in the first place.
    • Re:However (Score:4, Informative)

      by Goalie_Ca (584234) on Tuesday July 18 2006, @12:33PM (#15737993)
      (http://www.sfu.ca/~rdickie)
      Because IT's much easier to fix a square wheel than a round one!
      [ Parent ]
    • Re:However (Score:5, Insightful)

      by Yohimbe (17439) on Tuesday July 18 2006, @12:43PM (#15738085)
      (http://userfriendly.org/static)
      Actually the old code might be better. And I don't defend blindly.

      It has been my repeated experience that "Cruddy and complex" code is that way because the problem space is cruddy and complex and thats what bugfixes do to code.

      You throw out that complexity and you throw out accumulated knowledge. I have yet to see a second system or third or fourth that managed to keep the bugfixes of the previous system. These issues return and they are accompanied by new ones.

      In this case there might be a reason to thow out this particular baby with this particular bathwater: the only thing that new code gives you is resident experts on the new code. If you have staff turnover (Which MS always does), they may have already lost the resident experts on the previous design.

      So that brings up the next point: MS may now be jumping its proverbial code shark: They've not increased in price in 3 years: stock options are worthless, they're losing people, and the hardware vendors are saying "When are you going to get us a decent 64 bit system?". They can't seem to ship secure code and now they throw out working subsystems, possibly because they've got a brain drain. MS owns the office market, but they're starting to really fall behind in shipping modern security at the OS level.
      [ Parent ]
  • So (Score:3, Insightful)

    by kevin_conaway (585204) on Tuesday July 18 2006, @12:31PM (#15737966)
    (http://pyscrabble.sf.net/)

    So they're saying that beta software still has bugs in it?

    I don't think its particuarly fair to be making these public accusations at this time. I'm sure the developers appreciate the testing, but an article to CNET seems a little too much

    • Re:So by Anonymous Coward (Score:1) Tuesday July 18 2006, @12:59PM
      • Re:So by LocoMan (Score:2) Tuesday July 18 2006, @03:55PM
    • Re:So by Jugalator (Score:2) Tuesday July 18 2006, @05:17PM
      • Re:So by Jugalator (Score:2) Tuesday July 18 2006, @05:25PM
  • Mistake? by Billosaur (Score:2) Tuesday July 18 2006, @12:31PM
  • Outrage! (Score:5, Funny)

    by Kesch (943326) on Tuesday July 18 2006, @12:31PM (#15737970)
    'Microsoft has removed a large body of tried and tested code and replaced it with freshly written code.'

    How dare they! Just when I know all the exploits in the old code, they make me go and have to discover all new bugs in their new code. Being a hacker is hard some days...
    • Re:Outrage! by Frightening (Score:1) Tuesday July 18 2006, @03:04PM
    • Re:Outrage! by Gleng (Score:2) Wednesday July 19 2006, @04:30AM
  • The new windows anti-virus protection by Sweeman (Score:1) Tuesday July 18 2006, @12:32PM
  • As evidenced by... by Cherita Chen (Score:1) Tuesday July 18 2006, @12:36PM
  • Sometimes its easier by ingenuit (Score:1) Tuesday July 18 2006, @12:36PM
  • Conflict of Interest (Score:5, Insightful)

    by Ryan C. (159039) on Tuesday July 18 2006, @12:37PM (#15738031)
    OK, so Symantec makes money selling products that patch up problems with Windows OSes. Microsoft trying to put them out of a job. I'm not saying Vista is really achieving this goal, but what sort of report did you expect from Symantec? "Wow, this Vista really makes our products unnecssary"!

    FUD. At least they learned Microsoft's greatest marketing strategy.

  • Another way of saying it by Aqua_boy17 (Score:2) Tuesday July 18 2006, @12:37PM
  • by Bill_the_Engineer (772575) on Tuesday July 18 2006, @12:38PM (#15738046)

    Isn't it to Semantecs best interest to generate demand for their product by creating uncertainty when it comes to OS security. They did this to linux too...

    Granted Microsoft may be using new code, but that doesn't necessarily mean it's more insecure than the current network stack.

    Let's see what the non-beta software looks like, and see what a independent lab reports.

    Bill

  • Two of the funniest sentences today. by rowama (Score:1) Tuesday July 18 2006, @12:40PM
  • Put up or shut up by Fefe (Score:2) Tuesday July 18 2006, @12:42PM
  • Windows Defender anyone? by DoubleRing (Score:2) Tuesday July 18 2006, @12:47PM
  • 2008 by Nom du Keyboard (Score:1) Tuesday July 18 2006, @12:48PM
  • Did you also notice? by Spiked_Three (Score:2) Tuesday July 18 2006, @12:48PM
  • DOA for sure. by fuego451 (Score:1) Tuesday July 18 2006, @12:49PM
  • Slashdot...biased?! Never! by crerwin (Score:1) Tuesday July 18 2006, @12:50PM
  • Maybe it'll finally work by Draconnery (Score:1) Tuesday July 18 2006, @12:52PM
  • So they kicked out the BSD code by guruevi (Score:2) Tuesday July 18 2006, @12:54PM
  • Is this that fucking hard? by bhima (Score:2) Tuesday July 18 2006, @12:55PM
  • Turned upside down by Opportunist (Score:2) Tuesday July 18 2006, @12:57PM
  • Vista has been improving... (Score:4, Informative)

    by PurifyYourMind (776223) on Tuesday July 18 2006, @12:59PM (#15738216)
    (http://trollchat.org/)
    I work as a tester at a large, well-known tech company. I started using Vista back in February of this year, and I've used one of the latest versions, 5474, recently. Here are the changes I've seen:
    • Improved graphics (more complete icon set, fancier installation and login graphics, nicer titlebar look on non-3D capable systems)
    • More stability in general (some blue screen bugs I've reported have gone away with later versions)
    • More gadgets in the sidebar
    • A bit faster for file copies, file searches work a lot better -- file searching wasn't working at all at one point
    So... I'm still skeptical of their early 2007 predicted time frame, but it's definitely been getting more polished over the months.
  • Convenient omissions by grassh0pper (Score:1) Tuesday July 18 2006, @01:01PM
  • Best Quote from TFA... (Score:5, Funny)

    by SloppyElvis (450156) on Tuesday July 18 2006, @01:01PM (#15738235)

    people should understand the ramifications of a virgin network stack

    Oh man! I can't even begin to think of a joke worthy of that setup...
  • Shortening the credits by 93 Escort Wagon (Score:2) Tuesday July 18 2006, @01:03PM
  • Bye Bye Corporations (Score:3, Insightful)

    by nbannerman (974715) on Tuesday July 18 2006, @01:03PM (#15738250)
    Ok, I run a network in education, but I can imagine Network Mangers banging their heads into walls already. I think I've got my network locked down enough to cover most of the bases, but seriously, can anyone really say they are looking forward to rolling out Vista across an entire network? I understand network / computer security companies have a vested interest in showing there is a need for their product, but they are not the only ones suggesting Vista is going to be a nightmare.
  • And? by ms1234 (Score:1) Tuesday July 18 2006, @01:06PM
    • 1 reply beneath your current threshold.
  • Windows Vista still Rife with Insecure Code by kpang (Score:2) Tuesday July 18 2006, @01:06PM
  • Somewhat OT - keyboard shortcuts? by PurifyYourMind (Score:2) Tuesday July 18 2006, @01:07PM
  • And In Other News... by fobbman (Score:1) Tuesday July 18 2006, @01:19PM
  • More Symantec Propoganda; a new stack is better by postbigbang (Score:2) Tuesday July 18 2006, @01:19PM
    • Re:More Symantec Propoganda; a new stack is better by smokeslikeapoet (Score:2) Tuesday July 18 2006, @01:51PM
      • It's part of the bigger picture (Score:4, Interesting)

        by postbigbang (761081) on Tuesday July 18 2006, @02:07PM (#15738763)
        There are a myriad companies that Microsoft has bought, then put to good use. Some were then thrown off a cliff (like McAfee does/did with Network General and OilChange) while others made them smarter. They need the brains. And they need a new authentication methodology, a new networking stack, and a new registry protection mechanism not made of tissue paper. That doesn't mean they'll get it. So many people have blown up Vista (yes, I know it's not RC+ yet) that Microsoft must be rattled to their very core (yes, Bill-- you, you crummy half-assed programmer) before they'll believe their customers. It's a classic case of Sales Department Rules (Ballmer) and everything else drools. Hit the sales department in the wallet, and things change. Look for a big change from Microsoft soon when they report that XP sales are down and that Windows 2003 server's recent sales peak has now hit the skids, and the X360's are costing a fortune. Mark these words.
        [ Parent ]
    • Re:More Symantec Propoganda; a new stack is better by drsmithy (Score:2) Tuesday July 18 2006, @06:48PM
  • They wouldn't want to make Vista too secure... by thewils (Score:1) Tuesday July 18 2006, @01:20PM
  • Emphasis by tonyr1988 (Score:2) Tuesday July 18 2006, @01:26PM
  • NEWSFLASH! by darcling (Score:1) Tuesday July 18 2006, @01:30PM
  • Beta Crashes by Bizzeh (Score:1) Tuesday July 18 2006, @01:31PM
  • And in a related story... by daskrabs (Score:1) Tuesday July 18 2006, @01:39PM
  • Three things... by multimediavt (Score:1) Tuesday July 18 2006, @01:43PM
  • Hasta La Vista Windows Vista by Orion Blastar (Score:2) Tuesday July 18 2006, @02:08PM
  • "Building from the ground up" months before ship? by dpbsmith (Score:2) Tuesday July 18 2006, @02:20PM
  • In other news by McGiraf (Score:2) Tuesday July 18 2006, @02:37PM
  • "tried and tested"? by The MAZZTer (Score:2) Tuesday July 18 2006, @02:39PM
  • Wait... windows is insecure? by Mr. Freeman (Score:2) Tuesday July 18 2006, @02:55PM
  • Didn't we see this from McAfee regarding linux? by alpinerod (Score:1) Tuesday July 18 2006, @03:00PM
  • Insecure By Design: IPV6 Tunneling by Prototerm (Score:2) Tuesday July 18 2006, @03:02PM
  • A long ways away from mainstream...hmmm by Mulielo (Score:1) Tuesday July 18 2006, @03:22PM
  • Symantec biting the hand the feeds them? by grolschie (Score:2) Tuesday July 18 2006, @04:50PM
  • How to secure windows by Sathias (Score:1) Tuesday July 18 2006, @05:05PM
  • That new stack... by GeorgeFitch3 (Score:1) Tuesday July 18 2006, @05:07PM
  • FUD? (Score:3, Insightful)

    by Jugalator (259273) on Tuesday July 18 2006, @05:11PM (#15739971)
    (Last Journal: Monday February 13 2006, @07:11PM)
    Windows Vista still Rife with Insecure Code

    So, point me to the place in the article which says something is still rife with insecure code?

    Well, of course, there'll be securite holes in Vista too, like most other OS's, but I'm not sure that's what the article means? It seems someone somewhere have come to the conclusion that there are still major problems with it and I just, darned as much as I try, can't find the place in the article.

    It seems to me Symantec only speculates, as Vista will have a new network stack?

    But then, Symantec themselves say:
    "We're not saying that Vista's network stack is going to be inherently insecure when it is released," Oliver Friedrichs, director of emerging technologies at Symantec Security Response, said in an interview Monday.

    So, which is it, and is the article just spun like this on Slashdot because it's Slashdot?
    • 1 reply beneath your current threshold.
  • Vista & VISTA dictionary definitions by Tandoori Haggis (Score:2) Tuesday July 18 2006, @05:31PM
  • Corner cases? by DrXym (Score:2) Tuesday July 18 2006, @05:47PM
  • Trustworthy Computing by HTH NE1 (Score:2) Tuesday July 18 2006, @05:54PM
  • No problem, it comes with Windows Defender by VGfort (Score:1) Tuesday July 18 2006, @05:57PM
  • What else is new ? by Sohil (Score:1) Tuesday July 18 2006, @06:01PM
  • Sounds to me like... by Phraghg (Score:2) Tuesday July 18 2006, @07:53PM
  • What about the LSPs.. by 2phar (Score:1) Tuesday July 18 2006, @09:21PM
  • Re:Before the MSFT bashing commences by TrappedByMyself (Score:1) Tuesday July 18 2006, @12:35PM
  • Re:Before the MSFT bashing commences by Timesprout (Score:2) Tuesday July 18 2006, @12:36PM
  • Re:Before the MSFT bashing commences by pilgrim23 (Score:2) Tuesday July 18 2006, @12:58PM
  • Except this should be perfect. (Score:4, Insightful)

    by kinglink (195330) on Tuesday July 18 2006, @01:39PM (#15738567)
    This isn't Beta code, this is a public beta, the current name for what was originally called "Gamma". Aka, the stuff right before release.

    This isn't a problem if the problem you find is a minor thing where if you click on a button it crashes only if you have a ATI card that was made in June 2005.

    This is a problem if the majority of code, that has been rewritten from near scratch has major flaws that would take another full rewrite to get rid of (or years of critical updates). Vista is supposed to be the reinvention of Microsoft security, however this isn't secure. This isn't a "we're still adding features" problem this is a critical flaw at the core of the system.
    [ Parent ]
  • Re:Before the MSFT bashing commences (Score:4, Insightful)

    by Cal Paterson (881180) on Tuesday July 18 2006, @01:50PM (#15738657)
    You idiot. You do not rewrite a whole networking stack in the time between beta and release. The whole "it's only beta!" excuse only holds up for fixing trivial mistakes, not poor design concepts.

    Please THINK before you post.
    [ Parent ]
  • 20 replies beneath your current threshold.