Xkcd Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 4 June 2010

Google vs Microsoft - What's In It For You

Posted on 09:02 by Unknown
Tech blogs are abuzz over Google's recent announcement that they are tossing Windows overboard due to security concerns.

Is this another example of blades of grass (us) suffering when elephants (them) tussle? I don't think so, but let's look at some background.

Google blames Microsoft for the Operation Aurora attacks in which Google systems were compromised and key data stolen, allegedly at the behest of Chinese government officials. In particular, a Microsoft Internet Explorer zero-day exploit was leveraged in the attacks, and Google spent much time and expense cleaning up and securing their environment after the incident.

Microsoft products enjoy a significant, if dwindling, saturation point among both home users and the enterprise. In fact, Google's launch of the Chrome browser and Android mobile platform, along with their upcoming operating system, will result  in Google snatching more market share from Microsoft than from Apple or Linux.

So it makes sense for Google to peel away from Microsoft for all sorts of business reasons outside of security concerns. Internet Explorer is eminently buggy and continually vulnerable, and its percentage of the browser market was dropping even before Chrome was released as users moved to alternatives like Firefox and Opera. Aside from Google developers keeping Internet Explorer around to ensure their products are compatible and render correctly for IE users, there's no compelling reason for anyone other than the coders to have it on their desktops.

The same rationale can be posited from an operating system perspective. If Google's upcoming OS is indeed ready for prime time, Google employees should be using it. Period. Call it the "school of eating your own dog food" if you like, but if you want to convince casual users, application developers, and large companies that your product is worthy of their dollars, you'd better be willing to be a living, breathing use-case.

Speaking as a security guy, there are two concerns I have with Google's announcement. First, the operating system is just one of a myriad of attack vectors available for hackers and exploit frameworks. Secondly, consolidating on a single platform for an enterprise makes life easier for the bad guys.

Let's examine the operating system angle Five years ago, targeting the OS was easy, because Microsoft had a 98% deployment share and, let's face it, their code had more holes in it than Swiss cheese.

As time went on and Microsoft slowly began to execute on their Trustworthy Computing initiative, it became a bit more difficult to penetrate the operating system directly. Part of the solution was the implementation of UAC in Vista and Windows 7 which segregated some of the core kernel functions from direct access, but the enforcement lacks some of the rigor of similar Linux-based controls, and users can dumb down UAC to the point where it isn't all that effective.

Coupled with weak UAC, attackers also stopped breaking down the door and started looking for unlocked windows, pardon the pun, and they found them in peripheral applications like Adobe Reader & Flash, QuickTime, and Microsoft Office. Since these apps also suffer from readily exploitable vulnerabilities and are available in versions that sit atop various operating systems, Google moving away from Windows on the desktop and server is a lesser security achievement than the folks in Palo Alto are trumpeting.

Given that the second most popular attack vector - after peripheral applications - is web-based applications vulnerable to cross-site scripting and SQL injection attacks, it's difficult to believe much protection is gained by switching. Again, regardless of the operating system, you're still at risk if you have poor application development practices that allow such attacks to succeed.

What about moving from a heterogeneous IT environment to a homogeneous shop? Well, there are downsides to that approach, too.

Single platform infrastructures can be a security and resiliency concern. Attackers typically use fingerprinting techniques to systemically profile an organization's IT blueprint. Over time, it becomes apparent what products and versions are in use, and what preventative and detective security controls are in place. This is much easier for attackers when everything is based off of the same underlying code.

Similarly, when a weakness is found, it can be leveraged across the whole enterprise. That can increase both the impact of any attack (or unanticipated failure) and the subsequent time and resources needed to recover and resume normal operations. Having a multi-platform environment lessens that risk, but increases the complexity of an enterprise infrastructure. Few organizations take the resources saved from an uncomplicated, homogeneous environment and pour them back into hardening the underlying backbone.

Google may be firing a marketing shot across Microsoft's bow with their announcement. From a technical perspective, Microsoft is playing catch-up, having lost the cool kids to Apple and Google already. Losing the enterprise customer would be the final nail in Redmond's coffin, and if Google can demonstrate to Fortune 500 companies that they can provide a cost-effective, feature-rich replacement for Windows and Office, they'll be happy to hand businesses the hammer.

Images via Wikimedia Commons
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Google, Microsoft | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Praying for a Big Dick
    Saturday Morning Breakfast Cereal
  • The Shame
    Oh, McRib. You are one saucy bitch.
  • Give Mom The Gift of Masturbation for Mother's Day
    Wow. I've heard of targeted marketing before, but the thought of giving your mother a DC-powered sex vibe is one forward-leaning way to ...
  • Chamber of Whores
    GRIT TV has put together a damning behind-the-scenes look at the U.S. Chamber of Commerce that details from where the money comes, and to wh...
  • Maslow's Hierarchy of Robot Needs
    Via lunchbreath's photostream on flickr
  • Matt Taibbi on Olbermann Suspension
    How Matt Taibbi is able to continually squeeze through the bullshit and come out crystal clear on the other side is beyond me, but his analy...
  • Who does Google know that you know? - Boing Boing
    It's unsettling to click a link and find that you're connected to thousands of people without your knowledge, even though that's...
  • Goodnight iPad
  • SMBC - Ass Acne
    Saturday Morning Breakfast Cereal
  • What's With All The Anal Sex Studies?
    The NYC Department of Health recently released a report entitled, "Women, Unprotected Anal Sex and HIV Risk", in which female resp...

Categories

  • activism
  • Adobe
  • advertising
  • Afghanistan
  • aging
  • airlines
  • Apple
  • Arizona
  • art
  • banking
  • Barack Obama
  • Barbie
  • blog
  • Bobblespeak Translation
  • business
  • charity
  • childhood
  • CNN
  • Colbert
  • Columbus
  • comic
  • commentary
  • compassion
  • computers
  • conservatives
  • crime
  • cyber security
  • DADT
  • data protection
  • David Letterman
  • death
  • democracy
  • dogs
  • Ebert
  • economy
  • education
  • EFF
  • energy
  • England
  • environment
  • evolution
  • exploit
  • Facebook
  • faith
  • feminism
  • finance
  • flowchart
  • food
  • football
  • Fox
  • fraud
  • gadget
  • gadgets
  • Gawker
  • gay
  • geek
  • Glenn Beck
  • Google
  • government
  • GraphJam
  • guns
  • hacking
  • history
  • holiday
  • humor
  • information security
  • iPhone
  • Japanese
  • Java
  • John Hodgman
  • Jon Stewart
  • journalism
  • law enforcement
  • legal
  • life
  • lunchbreath
  • mainstream media
  • malware
  • McCain
  • McDonald's
  • media
  • medicine
  • merchandise
  • Metasploit
  • Microsoft
  • military
  • movie
  • movies
  • MSNBC
  • Muppets
  • music
  • nature
  • New Orleans
  • news
  • newspapers
  • NFL
  • NY Times
  • Obama
  • odd
  • Oddly Specific
  • Ohio
  • Olbermann
  • parenting
  • Paul Krugman
  • pets
  • philosophy
  • photo
  • piracy
  • poetry
  • politics
  • prank
  • privacy
  • protest
  • psychology
  • Rachel Maddow
  • racism
  • radio
  • religion
  • Republicans
  • right-wing
  • robots
  • Sarah Palin
  • sarcasm
  • satire
  • Saturday Morning Breakfast Cereal
  • science
  • security
  • Seinfeld
  • sexism
  • sexy
  • SMBC
  • social networking
  • socialism
  • sports
  • Star Trek
  • Star Wars
  • Steelers
  • Stephen Colbert
  • Taibbi
  • taxes
  • tea bagging
  • technology
  • television
  • terrorism
  • The Daily Show
  • the internet
  • The Onion
  • threats
  • toys
  • veteran
  • video
  • video game
  • vulnerability
  • Wal Mart
  • xkcd.com

Blog Archive

  • ►  2013 (1)
    • ►  March (1)
  • ►  2011 (23)
    • ►  November (1)
    • ►  October (4)
    • ►  September (5)
    • ►  April (4)
    • ►  March (5)
    • ►  February (3)
    • ►  January (1)
  • ▼  2010 (476)
    • ►  December (8)
    • ►  November (7)
    • ►  October (24)
    • ►  September (10)
    • ►  August (28)
    • ►  July (44)
    • ▼  June (83)
      • Nude Woman Steals Cars, Probably Not Mormon
      • Replace Your Dog With An AT-AT
      • Robert Byrd - Pork Fritter
      • Fred Thompson, Sleazy Huckster
      • Sunday Morning Coffee in the Backyard Gazebo
      • Treme - A Good Man Slips Beneath The Water
      • Lewis Black on the Oil Spill
      • Megan Fox or Naked Mannequin - You Make The Call
      • Don't Try To Win A Staring Contest With A Muppet
      • Spinach Ick
      • Bobby Jindal Confuses Invocation With Reaction
      • Chris Dodd Is Happy About Something Or Other
      • Rachel Maddow's Gulf Oil Map
      • John Lee Hooker - The Healer
      • Sam Seder Calls Bullshit on Social Security Crisis
      • The Afterlife: So Long and Thanks For All The Fish
      • Gahanna Blues
      • Joe Biden Says What We're All Thinking About Barton
      • Energy Independence? When Pigs Fly
      • Real Time Mario Soundtrack By Violin
      • Mr. President, your flowery verbiage is opaque and...
      • Political Arm Twisting
      • Father's Day Marketing
      • Ball Waxing For Charity
      • Gay Blood is Icky?
      • How To Do A Political Apology
      • Norah Jones - Are You Lonesome Tonight?
      • Comic Sans Takes A Stand
      • Obama and TV and Oil (Oh My!)
      • Pac Man vs. Mario
      • The Johnny Cash Project
      • Sarah Palin - The Olive Oyl of Energy Policy
      • Is Obama Really Cartman?
      • Bobblespeak Translation of Obama's Oil Speech
      • You Clearly Don't Understand The Point of a Penis
      • Hunting Bin Laden With A Sword
      • Digby Has A New Rule
      • KT Tunstall - Other Side of the World
      • Arizona Politician Gets Schooled
      • Jeff Beck - Drown In My Own Tears
      • Drunk Ohio Woman Poops Pants During Traffic Stop, ...
      • Boehner Flip Flops on BP Liability Cap
      • I9 Avalon Bowl Flag Football Benefit
      • Billie Holiday - The Blues Are Brewin'
      • Classic Restaurant Restroom
      • B.B. King - Key to the Highway
      • Deleted Your Facebook Account? Think Again
      • Fire Tony Hayward, BP CEO
      • Marines in Marja and the Battles to Come
      • XKCD - Phobia
      • Sharron Angle - All Fringe, All The Time
      • Stevie Ray Vaughan - The Sky is Crying
      • Adobe Flash Player Update Fixes 32 Security Flaws
      • Alfred Hitchcock's 'That's What SHE Said'
      • Hot Banker Wants To Be 'Tits on a Stick'
      • Vulnerability in Microsoft Windows Help and Suppor...
      • BP Execs Clean Up Coffee Spill
      • Fabulous Thunderbirds - Tough Enough
      • XKCD - Swimsuit Issue
      • Jon Stewart - Ass Quest
      • Primary Election Wisdom
      • John Lee Hooker - Hobo Blues
      • Microsoft Security Bulletin for June 2010 Is A Doozy
      • Teaberry Ice Cream - A Taste of Summer
      • British Shin Kicking Championship
      • Tommy Castro - Guilty of Love
      • Harvey Danger - I'm Not Sick But I'm Not Well!
      • Will Brazilian Butt Dance Give Me A Broken Beak?
      • Thea Gilmore - Old Soul
      • Roger Ebert's Essay on the Arizona School Mural
      • We, The People, Want The Keys Back
      • Critical Adobe Flaw Being Exploited in the Wild - ...
      • Dog Day Afternoon
      • John Boehner - Embarrassing Ohio Since 1990
      • The Reoccurring Prop Newspaper Gag
      • Drunk Driving in Dallas
      • Rachel Maddow's Heartfelt Oil Spill Disgust
      • Evolutionary Psychology Bingo
      • Google vs Microsoft - What's In It For You
      • Lego My Earbuds
      • Bone Eating Snot Flower Worm
      • Blogging Takes Its Toll
      • Bo Diddley - Who Do You Love?
    • ►  May (147)
    • ►  April (125)
Powered by Blogger.

About Me

Unknown
View my complete profile