<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Should you swap out Windows for better security?</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=801" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=801</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=801&#038;cpage=1#comment-935</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Fri, 16 Oct 2009 16:55:32 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/?p=801#comment-935</guid>
		<description><![CDATA[@Kurt -

Thanks for pointing out my mistake - I agree that the live CD option isn&#039;t bad and have updated my post accordingly.

Pete]]></description>
		<content:encoded><![CDATA[<p>@Kurt -</p>
<p>Thanks for pointing out my mistake &#8211; I agree that the live CD option isn&#8217;t bad and have updated my post accordingly.</p>
<p>Pete</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kurt wismer</title>
		<link>http://spiresecurity.com/?p=801&#038;cpage=1#comment-934</link>
		<dc:creator>kurt wismer</dc:creator>
		<pubDate>Fri, 16 Oct 2009 16:10:47 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/?p=801#comment-934</guid>
		<description><![CDATA[sorry to rain on everyone&#039;s parade, but this is a strawman.

krebs&#039; advice was not to switch to linux. krebs&#039; advice was to boot from a livecd when you wanted to do your online banking.

there&#039;s virtually no training involved because browsers operate the same in that environment as they do on windows (the biggest change is that the OS&#039;s GUI will look slightly different, but that&#039;s only an issue up until you launch the browser).

there&#039;s no concomitant shift to attacks against the new platform because it&#039;s on read-only memory and cannot be persistently compromised. and if it&#039;s used only for online banking the chances of a non-persistent compromise prior to entering your credentials are next to nothing (the banking website itself would have to be serving malware in order for you to get compromised).

phishing is a red-herring since no technological measure has any effect against a purely social engineering based attack. that said, technologically assisted phishing (being directed to a false banking page that loads credential stealing malware) is largely foiled AND if you ONLY do your online banking through the livecd it becomes very difficult follow banking related phishing links because the contents of your clipboard don&#039;t survive a reboot.]]></description>
		<content:encoded><![CDATA[<p>sorry to rain on everyone&#8217;s parade, but this is a strawman.</p>
<p>krebs&#8217; advice was not to switch to linux. krebs&#8217; advice was to boot from a livecd when you wanted to do your online banking.</p>
<p>there&#8217;s virtually no training involved because browsers operate the same in that environment as they do on windows (the biggest change is that the OS&#8217;s GUI will look slightly different, but that&#8217;s only an issue up until you launch the browser).</p>
<p>there&#8217;s no concomitant shift to attacks against the new platform because it&#8217;s on read-only memory and cannot be persistently compromised. and if it&#8217;s used only for online banking the chances of a non-persistent compromise prior to entering your credentials are next to nothing (the banking website itself would have to be serving malware in order for you to get compromised).</p>
<p>phishing is a red-herring since no technological measure has any effect against a purely social engineering based attack. that said, technologically assisted phishing (being directed to a false banking page that loads credential stealing malware) is largely foiled AND if you ONLY do your online banking through the livecd it becomes very difficult follow banking related phishing links because the contents of your clipboard don&#8217;t survive a reboot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=801&#038;cpage=1#comment-933</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Fri, 16 Oct 2009 15:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/?p=801#comment-933</guid>
		<description><![CDATA[@Peter -

I had a different experience with Vista, but more importantly are the Office apps. I do agree that Macs are viable alternatives, at least for smaller companies, but I suspect that they are not &quot;cost effective&quot;. I think people have a tendency to oversimplify costs and worry about the long-term viability of a switch like that described.

Perhaps even more importantly - I am not convinced it is a particularly effective strategy.

Thanks for the note about the design - I am still working on some details so look for more changes.]]></description>
		<content:encoded><![CDATA[<p>@Peter -</p>
<p>I had a different experience with Vista, but more importantly are the Office apps. I do agree that Macs are viable alternatives, at least for smaller companies, but I suspect that they are not &#8220;cost effective&#8221;. I think people have a tendency to oversimplify costs and worry about the long-term viability of a switch like that described.</p>
<p>Perhaps even more importantly &#8211; I am not convinced it is a particularly effective strategy.</p>
<p>Thanks for the note about the design &#8211; I am still working on some details so look for more changes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=801&#038;cpage=1#comment-932</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Fri, 16 Oct 2009 14:48:24 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/?p=801#comment-932</guid>
		<description><![CDATA[@Steve -

Well said.

Pete]]></description>
		<content:encoded><![CDATA[<p>@Steve -</p>
<p>Well said.</p>
<p>Pete</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: peter</title>
		<link>http://spiresecurity.com/?p=801&#038;cpage=1#comment-931</link>
		<dc:creator>peter</dc:creator>
		<pubDate>Fri, 16 Oct 2009 14:47:58 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/?p=801#comment-931</guid>
		<description><![CDATA[I&#039;m not sure of I can agree.. A few months ago I switched to a Mac and what a difference. This week I had a Windows Vista experience. I know my way around in various OS, but when you make the user experience that frustrating and the time needed to start things up so time consuming it will also negatively impact the willingness of users to invest time in security. 

By the way..I like the new design, big improvement.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m not sure of I can agree.. A few months ago I switched to a Mac and what a difference. This week I had a Windows Vista experience. I know my way around in various OS, but when you make the user experience that frustrating and the time needed to start things up so time consuming it will also negatively impact the willingness of users to invest time in security. </p>
<p>By the way..I like the new design, big improvement.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve P.</title>
		<link>http://spiresecurity.com/?p=801&#038;cpage=1#comment-930</link>
		<dc:creator>Steve P.</dc:creator>
		<pubDate>Fri, 16 Oct 2009 13:49:38 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/?p=801#comment-930</guid>
		<description><![CDATA[I&#039;m personally a big Linux fan and use it personally, but would have a hard time recommending an organization of any size switch at the moment.
1) Active Directory is the crown jewel of MS at the moment in my opinion.  Group policy is much more powerful then anything we have on the Unix side, and it&#039;s well known by admins.
Which brings us to:
2)Your admins probably know Windows better.  If not, you&#039;re probably already using *nix, and don&#039;t need my recommendation in the first place.  You can secure what you know and have experience with better then some new system you&#039;ve never seen.  Yes, under administrated home or small business windows is crap, and in those situations Linux might in fact be better.  The enterprise is a whole different kettle of fish.  In defense of the original article, it seems targeted at the small enterprise set.

So, to the article, if you want to fire up and alternative browser just for banking, go for it.  If *you* want to run Linux, either as a live-cd (which is all the original article recommends) or as your main OS, go for it, but it&#039;s probably not the time to be recommending that enterprises mass migrate to Linux desktops.

For someone else&#039;s ranting on the topic, see http://risky.biz/news_and_opinion/metlstorm/2009-04-02/i-heart-windows]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m personally a big Linux fan and use it personally, but would have a hard time recommending an organization of any size switch at the moment.<br />
1) Active Directory is the crown jewel of MS at the moment in my opinion.  Group policy is much more powerful then anything we have on the Unix side, and it&#8217;s well known by admins.<br />
Which brings us to:<br />
2)Your admins probably know Windows better.  If not, you&#8217;re probably already using *nix, and don&#8217;t need my recommendation in the first place.  You can secure what you know and have experience with better then some new system you&#8217;ve never seen.  Yes, under administrated home or small business windows is crap, and in those situations Linux might in fact be better.  The enterprise is a whole different kettle of fish.  In defense of the original article, it seems targeted at the small enterprise set.</p>
<p>So, to the article, if you want to fire up and alternative browser just for banking, go for it.  If *you* want to run Linux, either as a live-cd (which is all the original article recommends) or as your main OS, go for it, but it&#8217;s probably not the time to be recommending that enterprises mass migrate to Linux desktops.</p>
<p>For someone else&#8217;s ranting on the topic, see <a href="http://risky.biz/news_and_opinion/metlstorm/2009-04-02/i-heart-windows" rel="nofollow">http://risky.biz/news_and_opinion/metlstorm/2009-04-02/i-heart-windows</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
