Security Basics mailing list archives

Re: Which Windows OS is Safest


From: Ranjeet Shetye <ranjeet.shetye2 () zultys com>
Date: Tue, 29 Jun 2004 10:36:17 -0700

* Barbara Filkins (filkins () impulse net) wrote:
I think just standardizing on one OS goes the most distance to achieving a
secure environment.

I have to disagree with this statement.

Standardizing on one OS only makes it EASY for an admin to go the most
distance. However, SHOULD a breakin happen, and it WILL one day, your
homogenous network will be completely at the mercy of the attacker.

A Heterogenous network is harder to lock down, and is also harder to take
down.

classic example: all the elm trees in the 1950s that got infected with some
disease and suddenly EVERY suburban area in America went bald.

----- Original Message ----- 
From: "Boaz" <boclark () cox net>
To: <security-basics () securityfocus com>
Sent: Monday, June 28, 2004 9:50 AM
Subject: RE: Which Windows OS is Safest


Wow what timing, I was going to post the following, I have a friend that
has
a small business, and is using Win 98 on two machines, Win 2000 pro on two
machines, XP Pro on one machine and XP Personal on another.  There is a
Linux firewall, and the server is running Novell.  Since he needs to
upgrade
the two machines running Win 98, he want to standardize on one OS.

He is leaning toward XP.  If I am reading the results of this original
post,
Win 2000 Pro (patched to current versions) would be a better choice.  Is
that correct?  If so should he also get rid of XP.  This is a business
that
needs security and confidentiality of files.

It is not possible to go to any other OS for the workstations other than
Windows.

Thank you in advance for any replies.

Bo Clark





--------------------------------------------------------------------------
-
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or
less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the
skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
--------------------------------------------------------------------------
--





---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


-- 
Ranjeet Shetye
Senior Software Engineer
Zultys Technologies
Ranjeet dot Shetye at Zultys dot com
http://www.zultys.com/
 
The views, opinions, and judgements expressed in this message are solely those of
the author. The message contents have not been reviewed or approved by Zultys.


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: