Follow the Australian Telecommunications scene NEWSLETTER- FREE TRIAL
The Linux distillery
Bringing the world of Linux to you, David cuts through the tech and shows you how it works and how to use it, in terms that apply to any distro. RSS
Technology news and Jobs arrow The Linux distillery arrow Why the latest IE flaw proves Linux got it right from the start
Why the latest IE flaw proves Linux got it right from the start E-mail
by David M Williams   
Sunday, 21 December 2008
I won’t repeat the comments made by others that using a different web browser, such as Mozilla Firefox, will protect you from problems like this, but I will comment on something else.

Microsoft note that users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

That makes sense; if a user runs with administrator privileges the rogue code can have full control of their system. If the user is unprivileged then the attack surface is much less.

Nevertheless, it’s a pipe dream. Unlike operating systems like Linux which have always encouraged users to have “ordinary” accounts and only claim administrator privileges when needed, and only for performing specific tasks, Windows has trained its users – and worse, its legion of developers – to always run as the local administrator.

Vista’s UAC was intended to help mitigate this problem but proved unpopular due to the great number of programs which necessitate elevated privileges.

Perhaps the ultimate solution for a safe online experience isn’t to just change your browser but to change your OS also.

Give thought to Linux; it is safe by design. This design has lasted the test of time. This design is now a major differentiation between it and Windows.

Microsoft are hoping to undo their bad security design by re-educating its horde of users to a Linux way of life. This re-education isn't working, largely because any attempts to run within a totally unprivileged environment mean the bulk of your programs no longer work.

Microsoft have to bite the bullet and obliterate the design goal of backward compatibility if they ever hope to genuinely have an operating system where administrator-level accounts aren't used for ordinary logins and usage. It's not going to be pretty.

Meanwhile, Linux just keep soldiering on. It got it right from the start. Its users are accustomed to running sudo if they temporarily require higher access as the following xkcd comic illustrates.

xkcd - sudo make me a sandwich

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!



 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter