The Mac Observer

A Network Administrator Responds to Winn Schwartau’s ‘Mad as Hell’ Declaration

July 20th, 2005 at 3:00 PM - News by Brad Cook

When computer security expert Winn Schwartau declared he was "mad as hell" and switching his company to Macs, many in the IT sector sat up and took notice. One of those people was Rich Rumble, a security administrator and network engineer for a large dot-com with over 3,000 employees worldwide and more than 700 servers in use.

In an interview with The Mac Observer conducted by e-mail, Mr. Rumble, who has little experience with Macs, said: "I think Winn has his finger on the pulse with most of these topics. Keep it simple, stupid (KISS) is a mantra recited over and over in the security field, especially in IT. I also think that Windows would be better off streamlining the kernel and cutting out the bloat with respect to the tasks you ask it to do, and the amount of code required to do them."

Unfortunately, he doesnit see Microsoftis upcoming OS upgrade, which is code-named Longhorn and will ship late in 2006 or early in 2007, changing that situation. "Thatis to be expected," he explained, "as they need to have interoperability with past Microsoft products, so it stands to reason that they will simply build off the predecessors. Reinventing the wheel would cost much more in every respect.

"Would a inew wheeli from Microsoft solve its problems?" Mr. Rumble asked. "Only if they did it right, whatever that may be. I do feel you can secure a Microsoft OS, without a doubt, but secure out of the box is still a ways off for them. It still astounds me that it took them 10+ years to add a firewall to the OS itself by default."

In addition to the lack of a firewall turned on by default for all Windows users, save those who have XP Service Pack 2 installed, Mr. Rumble cites several other problems with the OS, including: "Inherently insecure applications, such as ActiveX controls and Internet Explorer security settings and scripting set to a very low level by default. Antiquated authentication protocols: Microsoft is still using LanManager Hashes by default to authenticate connections to shares, Web sites and outside of AD domain credentials.

"Administrator by default," he added. "When you set up Windows, your account is placed in the administrators group by default, with no warning of the implications and/or security risks that having such an elevated privilege may have."

Pitfalls For the Average User

Mr. Rumble feels that corporate environments are now better equipped to secure their Windows usersi machines, but "the home user may not know what security risks theyire faced with. Windows, and third party vendors in my opinion, seem to apply band-aids on a cancer, rather than attack and remedy the issues at their root. Windows can be implemented and used securely, but that requires a level of knowledge that the average user may never have at his disposal, or level of comfort."

Among the security measures he thinks home users should implement are a firewall (assuming they donit have the latest version of Windows XP), anti-virus software and automatic downloading and installation of Windows patches. In addition, they should turn off system restore because anti-virus software canit clean its folder -- thus causing viruses to reappear upon reboot -- and they should turn off ActiveX controls and scripting, if possible. He also recommends using another Web browser, such as Firefox, and turning to Internet Explorer only when a Web page requires ActiveX.

He puts some responsibility on Microsoft, too, noting that the company "can educate users about the risks better and build off their MBSA products to walk users through some of the most critical security settings, such as the firewall and scripting level."

Overall, heis happy with the reliability of Windows, and, even though he estimates he uses Linux 80% of the time at work, he prefers that OS for most tasks. However, he said: "I feel Linux is going to catch up fast in the next few years, if they can keep improving the UI [user interface] and interoperability like they have so far. If the OS remains free, and if it can improve to the point that the average user will have little problem getting around and using the OS, Microsoft will suffer the most. Microsoft should find a way to KISS, and they would be able to benefit."

As for the vaunted "halo effect" caused by the iPod, Mr. Rumble believes "itis real, and has been for a long time. Iim sure it will get people into the Apple stores, or make them curious enough about Apple to try their other products."

As an analogy, he offers up an experience buying a car: "My brother bought a used Honda the same year I bought a new Ford. The Honda was four years older and had high mileage, but he only had to do regular maintenance to it, while I was replacing alternators and spark plugs and getting new header seals. I know my way around a car, so I wasnit snowed into those repairs; they were needed. Now the whole family is Honda owners, and we donit look back."

  • Related Entries
  • Email This
  • Tweet This
  • Brad Cook on Twitter
Login. Need an account? Register here.



Auto-login on future visits

Show my name in the online users list

Forgot your password?


Commenting is not available in this section entry.
 

Recent Headlines - Updated November 10th

Tue, 8:16 AM
News - Apple Releases Security Update 2009-006 for Leopard, Snow Leopard
Mon, 7:20 PM
Rumor - Apple May Update iPod touch in December
6:45 PM
Product News - MacUpdate Desktop Updated to 5.0.1 with New Features, Bug Fixes
5:16 PM
Apple Releases Mac OS X 10.6.2 - Guest Account Bug Fixed, Much More
4:12 PM
Games - New For iPhone: Star Rangers, Air Force Supremacy, Blood Beach, More
2:51 PM
Apple Stock Watch - Radio Shack Jumps 14% on iPhone Deal, Apple Up 3%
2:25 PM
Games - EA Scoops Up Social Games Publisher Playfish
1:51 PM
Deal Brothers - Western Digital 1TB SATA Intellipower Hard Drive:  $84.99
10:58 AM
News - StarHub Signs Singapore iPhone Deal
10:36 AM
Hot Forum Topic - Reader Speculation: What’s in Apple’s Tablet?
10:08 AM
News - Apple Kicks Off New Credit Program
9:26 AM
News - Apple Launches Reserve and Pick Up Program
 

The Mac Observer Reader Specials

  • TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
  • RamJet Memory: Mac Pro 8-core 8GB Kit $199.99, 4GB Kits $109.99! Sale on MacBook and MacBook Pro 8GB kits $549.99! New MacBook DDR3 2GB for $49.99. iMac and Mac mini 4GB Kits for $79.99! 1TB SATA Hard Drives for $109.99! Click here
  • OWC: Plug & Play Hardware RAID up to 8.0TB. High Performance, Data Redundant Solutions. FireWire 800, FireWire 400, USB2, or eSATA. Hot Swappable Bays, Data Rates over 200MB/s. Click here
  • Poker Mac If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!
  • For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.

  • Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.
  • Buy Stuff, Support TMO!
  • __________
  • Macworld Expo 2010 Hotel Deal
  • TMO on Twitter!

Apple Stock Quote

  • AAPL: $201.46. Change: 0.00.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features