There'll never be a bulletproof OS
Posted on 30 Oct 2009 at 10:39
Davey Winder goes in search of the bulletproof operating system and discovers it doesn't exist
I have a vision of Google’s engineering director, Linus Upson, with a weird ginger Mr Whippy haircut bopping around singing “Chrome OS baby will be, Bulletproof” in a La Roux stylee. I can’t help it since he declared that Google was completely “redesigning the underlying security architecture of the OS”, so users “don’t have to deal with viruses, malware and security updates”.
Really? I don’t think so, because I don’t believe it’s actually possible for an operating system design to be bulletproof (and that includes Mac OS, says he flinching in anticipation). Ditto for web browsers, including Google’s own, what was it called, ah yes, Chrome…
At Secunia.com, home of application security advisories, you’ll discover no fewer than eight vulnerabilities leading to six advisories including: Google Chrome Cross-Site Scripting and Information Disclosure; Google Chrome URI Handler Registration Vulnerability; Google Chrome “ChromeHTML” URI Handler Vulnerability; Google Chrome Skia 2D Integer Overflow Vulnerabilities; Google Chrome WebKit SVGList Object Handling Memory Corruption; and the (unpatched at time of writing) Google Chrome WebKit Use-After-Free Vulnerability.
So Google’s track record isn’t exactly bulletproof in this regard, is it?I’m not knocking Google for trying to make a more secure OS, but to say that it will in effect bring an end to malware and viruses is plain daft
I’m with well-respected security guru and chief security technology officer at BT, Bruce Schneier, who called it “an idiotic claim” and stated that it’s been mathematically proven to be impossible to create a virus-immune OS.
I’m not knocking Google for trying to make a more secure OS, and doubt that Schneier is either, and building from scratch with security in mind has to be a good thing, but to say that it will in effect bring an end to malware and viruses is plain daft. Actually, it goes beyond daft and asks for trouble, just begging the Bad Guys to prove the Do No Evil company wrong.
I’m guessing that someone will point out that Apple has been implying much the same for Mac OS, and it has yet to become riddled with security bullet holes.
Go to Apple's website and you’ll find it states that “Mac OS X is designed with security in mind. Its built-in defences help keep you safe from viruses and malware without the hassle of constant alerts and sweeps.”
Yet when you get past all the bold claims on the Apple Security page about how Mac OS protects you from the bad stuff, you eventually find this inevitable disclaimer under the title of Security Advice: “The Mac is designed with built-in technologies that provide protection against malicious software and security threats right out of the box. However, since no system can be 100% immune from every threat, antivirus software may offer additional protection.” Ah right, not bulletproof either then.
Davey Winder
Davey is a contributing editor to PC Pro, having covered the internet as a topic since the magazine started in 1994. Since that time he's won numerous awards for his journalism, but remains a small-business consultant specialising in privacy, security and usability issues.
advertisement
- Getting to grips with Microsoft's IT Health Environment Scanner
- Virtualise your servers
- The changing face of travel gadgets
- Build your own distributed file system
- The bulletproof Dell that costs an arm and a leg
- Microsoft Office 2010 Technical Preview: Q&A
- Lawnmowers, the TyTN II and one odd insurance request
- How far can we trust apps?
- Five nice touches in Outlook 2010
- Building a better Google
- Why Britain's watchdogs have fewer teeth than goldfish
- Tabbed documents: how to make Office 2010 great
- Outlook 2010 People Pane – does it spell death to Xobni
- Microsoft Outlook 2010 screenshots
- Co-Authoring in Word 2010 and SharePoint Foundation 2010
- Microsoft Outlook 2010 screenshots: Backstage view
- Flash 10.1: Developing for Desktop and Device
- Microsoft Office 2010 screenshots: Recover unsaved items
- Microsoft Word 2010 screenshots: Text Effects
- Microsoft Word 2010: inserting screenshots
- Q&A: Why Conficker was a victim of its own success
- App developers losing faith in Android
- Biz Stone: Murdoch's Google veto will "fail fast"
- Google adds automatic captions to YouTube
- China ramps up cyber spying
- Mozilla maintains dependence on Google
- Windows 7 flying off the shelves
- Google Chrome OS: full details unveiled
- AOL slashes 2,500 jobs
- YouTube begins streaming full-length shows
advertisement
Printed from www.pcpro.co.uk


