Linked by Eugenia Loli-Queru on Thu 2nd Sep 2004 19:56 UTC, submitted by Jon Cooper
Windows "We evaluated the security features of Windows XP SP2 on a test machine, following a clean install of XP Pro with no configuration changes and no third-party software or drivers installed. We installed XP with the NTFS file system, choosing all of the factory defaults, then patched it with each recommended security update including SP-1 (required), before installing SP2." Read the rest at TheRegister.
Permalink for comment
To read all comments associated with this story, please click here.
Not only MS's fault...
by vault on Thu 2nd Sep 2004 20:54 UTC

The firewall is useless, not because it's bad. Most users will just click "ok" or "unblock" without even reading the info, to get their work done. Yes, i have seen it done many times before.
Some friend of mine had installed "updates notification" on his w98. It showed up once, and he was like "oh, this? i never read this, what's it about?".
Blocking outgoing traffic? Oh, come on! It would be too annoying to them, and they would immidiately find a way to turn it off.

They said that 'secondary login' is unneded, and they complain about using administrator account. Well what's the point of secondary login service? So there would be no need to use an account with administrative rights. Programs that need it could be run with "run as" option.
Yes, most people do use administrators account, they just can't be bothered with limited priviledges. That would totally piss them off. "I can't install this pogram, why? I can't do {this, that, ...}!".
File and printer sharing disabled by defult? Most people i know can't live without it. And no, they don't care about it being insecure...

And what more could Security Center do? Even throwing 10 warnings in user's face won't change anything.

Automatic Updates disabled and updates installed manually? LOL. Tell it to people who don't even know that software should be patched. To that millions infected with blasters/sassers. Yes, i agree that some services should certainly be disabled, like remote registry (?), i also fail to see a point in QoS in desktop system, but not Automatic Updates!

(...) limited-access account (...). UNIX-compatible systems enforce this worthwhile discipline strictly

Really? Show me one. Beside some linux distributions, it was added to recently. Nothing stops you from logging in as root and doing 'rm -rf /'.

SP2 is certainly not perfect, it's *only* a service pack, but it IS an improvement. Thay had to make some compromises, XP is not 2003 server, where everything can be off by default.

I'm just sick of SP2 bashing ;) .