Skip to main content
GameDev.net gamedev.net
🔒 Locked

Windows OS: What the weaknesses that everyone talks about

Started by gretty Dec 18, 2010 at 4:45 AM 37 replies 7.8k views
Original Post
gretty
gretty
I always hear people bashing Windows about how flawed, lacking in security &/or unnecessarily complicated it is.

I know this is inviting a flame war, but I am trying to understand & learn the real reason the Windows Operating System is badly regarded, thats the reason I posted this question here & not the lounge.

So as much as it is possible, can you help me understand what aspects of the Windows Operating System causes it to be badly regarded. I especially would like to learn, for example, "Windows does X this way & it causes Y problem. And the Operating system Z does it F way & its better because ..."

owl
owl
There was a time when Windows was young and full of flaws and was the only usable OS system for PC with enough drivers to handle most popular hardware, so all the blaming used to go towards Microsoft. Now, time has passed, most flaws of the Windows OS have been taken care of, we have Linux now, which happens to have quite a lot (probably more) flaws for the desktop than the now old Windows XP.

For me, now, Windows XP is a rock solid OS for PC. And I'm grateful to have Linux as an alternative but after having used it extensively I had to admit that Windows works better for most of the things I need.
[size="2"]I like the Walrus best.
generaleskimo
generaleskimo
Another big flaw that I see with Windows is the lack of openness when compared to Linux. Because Linux is open source, there are many components in the OS, especially related to the user interface, that can be customized easily, while Windows is generally stuck the way it's built (I know there are systems like Windows Blinds to change the look and feel, but it doesn't make significant changes to the behavior and it is extremely slow).

Windows is also quite bloated because it is necessary for it to support many legacy API calls that were written over a decade ago when the OS had an extremely poor architecture.

The lack of a package manager for Windows is also a great disadvantage, as resolving dependencies either has to be done by the user or by bundling installers together and leaving behind a mess of libraries.

Lastly, the Windows driver interface often feels like a huge mess compared to the pseudo-file based drivers found in Linux and Unix systems.

To put this in perspective, I use Windows mostly for personal stuff and game development, and Linux systems for work.
===========================";" is the best key ever; you can use it to end lines when you are too lazy to use ENTER;
dave
dave
Quote:

* Windows, even Windows 7 keeps getting slower and slower over the time. And some point of time it is just a mess and requires a reinstall. I have not experienced a similar behavior under Linux.

I've not noticed this in the latest releases. Windows 7 still boots nicely for me and I have alot installed. I have not noticed slowness. However this statement validity depends entirely on your perception of slow or fast. You need numbers.

Quote:

* Windows updated are annoying. Some happen when you want to shutshown the pc, some configuration when you want to log in. Sometimes Windows tries to restart without asking you. There is the dialog that tells you the computer will be restarted in 10 minutes. I use the pc also for computation which might take a week to complete and don't want the pc to get restarted. It might be possible to change the behavior but as default it is just not acceptable for me.

They can be a little frustrating, but i have certainly never had Windows updates try to shut down my computer without asking. Why don't you just turn off Windows updates?

* Windows application are also bad behaving, they install them selves at strange locations and every application comes with it's own update utility. Those Adobe and Apple updates are very annoying. Under Linux the package manager does a great job.
Also when it comes to installing some small utility application like a pdf printer, under Windows I ended up installing a lot of toolbars as a side effect while looking for the right tool. Under Linux I just installed cups-pdf using the package manager.

Quote:

* Under Windows the active windows gets the mouse events while under Linux it is the window under the cursor. I found the behavior under Linux much better and more intuitive.

This is purely a matter of preference. In my opinion it is unintuitive to have the focus change as you move the mouse around. What if i want to move it out of the window to get out of the way of something im doing with the keyboard, or a movie? This doesn't make Windows worse than Linux.
[/quote]

Quote:

* Under Linux you can delete a file that is in use, even an executable without
causing any problems. I like that and make use of it.

My gut feeling is that i probably shouldnt be able to delete something that is in use. Just like i shouldn't be able to move my car with the handbrake on.

Quote:

* Programming is easier under Linux because headers and libraries have some default path they get installed to. Try getting a dozen libraries work nice together under Windows.

If the locations of the libraries are the only criteria by which you judge the ease of programming on a platform then you havn't done enough programming. Also, i have worked on projects with large amounts of libraries and never had an issue.

Quote:

* Under Windows "start->all programs" is a mess.

Maybe, maybe you have too much installed. Maybe you don't realise that you can use the quick launch bar and maybe you didnt know that you can customise it, pin things and create your own folders. I for one barely venture into the start menu because i use the task bar.

Quote:

* The concept of having a home folder works well for me under Linux and my home folder is on a different partition than the OS. Under Windows I ended up loosing data because for example I forgot to make a backup of some folder where my browser stores the bookmarks in C:\ .

Agreed. But the solution is to use another drive in windows. A partition doesn't save you from issues to do with the disk.

Quote:

* A lot of my thumbnails for video files are black under Windows because they are from the first few seconds of the video. Under Linux the thumbnail is from the middle of a video.

I've never noticed this, but if that is the case then i agree.

Quote:

* I think the window placement is better under Linux. The windows overlap less often and the window manager remembers my window placements by default.

I agree that the explorer windows management lacks some linux features that are handy. Such as your next statement.

Quote:

* I enjoy using multiple work spaces under Linux.

Agreed.

Quote:

* I have a keyboard from Microsoft but even after installing drivers some keys don't work. Under Linux they all work as expected without any manual configuration.

I've never experienced this.

Quote:

* Notification are annoying under Windows compared with Linux.

Define notifications.

Quote:

* Linux supports more file systems.

I've never understood the need for more filesystems. So long as my os works it can use what it likes. Most uses of windows wont care either.

Quote:

* My Windows 7 machine does not recognize my XP machine in the network. My Linux pc finds both!

We have a mixture of windows OSs at work, all recognise eachother on the network.

Quote:

* Linux comes with a lot of small, free and nifty utilities.

Yes there are alot of useful utils.

Antheus
Antheus
Quote:
Original post by gretty
"Windows does X this way & it causes Y problem. And the Operating system Z does it F way & its better because ..."


Windows is updated in fairly large and discrete chunks. First by service packs, then by Tuesday patches.

Most people don't update at all. Many companies don't upgrade as a matter of policy.

Under Linux, apt update can be set to automatically apply patches as they are made available.

Second issue are defaults. Especially pre-Vista, default installation left machine wide open. While they could be locked fairly tightly via policies, most machines were installed by kids "who knew computers". Many IT shops also didn't pay enough attention, or "the boss needs to be able to install Bonzi Buddy".

End result is, there is large install base of unpatched XP machines, some which are vulnerable to some fairly trivial and very old attacks.

A properly up-to-date Vista or 7 is about as secure as Linux or MacOS. The difference is in install base. Windows has still the largest surface area.


Other attack vector, especially before 7 are user-assisted exploits. Users themselves downloading and running malware. This latter part is still a problem, not so much regarding random attacks but mostly malware and adware (toolbars, search bars). There are very few serious user-space exploits. The biggest surface recently came from Acrobat Reader and there was a fairly big hole in JVM (that got patched).
Katie
Katie

"Under Linux you can delete a file that is in use, even an executable without causing any problems. I like that and make use of it."

"My gut feeling is that i probably shouldnt be able to delete something that is in use. Just like i shouldn't be able to move my car with the handbrake on."

There's actually an entirely good reason why it's possible on UNIX and conceptually it's perfectly logical; The disk file "goes away" with the last link to it is deleted. Files opened in running programs count as a link, as do the directory entries which represent the files in the disk.

The result is that you can delete a running executable or library off the disk and install a new version without affecting the running version.

This is why UNIX (by and large) gets away with less reboot required upgrades -- you can just switch out the files and kill/restart systems in one go. Generally, the kernel is the only upgrade which requires a reboot these days.

It has the slightly strange corollary that you can have disk space occupied by files which are inaccessible from any other process... which often catches people out.

Katie
Katie
"Under Linux the package manager does a great job."

The package manager actually has very little to do with it -- it's just that Linux developers follow the rules as to where files go.

There's nothing to actually stop you putting your exe and shared objects under /etc, but people just don't.
the_edd
the_edd
From where I sit, the biggest issue is actually now with the software people/companies provide for it.

If I had a penny for every time I downloaded a bit of software that didn't allow me to install it on a non-admin account (and just for the use of that account), I'd be swimming in cash.

Off the top of my head, recent examples include Visual C++ 2010, World Community Grid's BOINC, a bunch of bit torrent clients and iTunes.
SymLinked
SymLinked
Quote:
Original post by Kambiz
* Windows, even Windows 7 keeps getting slower and slower over the time. And some point of time it is just a mess and requires a reinstall. I have not experienced a similar behavior under Linux.


If the user doesn't know how to install applications/games safely and properly, then sure it will get messy. But it depends entirely on the user. None of my Windows XP/Vista/Win7 installations are slow, and the XP install is several years old. If you install crap everywhere and do not pay attention to what you install, it will get.

Quote:
Original post by Kambiz
* Windows updated are annoying.


Agreed, but it's customizable.

Quote:
Original post by Kambiz
* Programming is easier under Linux because headers and libraries have some default path they get installed to. Try getting a dozen libraries work nice together under Windows.


Subjective. I find it much easier to program under Windows.

Quote:
Original post by Kambiz
* Under Windows "start->all programs" is a mess.


Compared to what? I love Linux and use it myself, but it's definatly not for its desktop features.
TheTroll
TheTroll
Most of the complaints are not about the Windows OS but about applications written for the OS. People don't follow the rules and bad things happen.

Windows slowing down is not inherit to the OS but because of the applications installed.

Same goes for messy Start, files not being in the right place, other things like viewers, etc.

Drivers are not part of the OS but from an outside source.

So where do the security issues come from? Two places, people attack the OS because it is the most popular in the world. If you have enough people beating on it you will find every flaw there is. Next, the easier you make something to use the less security there is. It is the nature of the beast.

theTroll
Decrius
Decrius
I'm having no troubles with Windows 7 so far, runs well and no noticeable slow downs yet. BSOD's nor virusses have I encountered so far.

I must admit with a few points though, Windows by default promotes disk chaos I find. It's not for nothing they had to implement better search capabilities (which I find still insufficient, if you ask me, the search functionality in directories is bugged...or incomplete...I always have to use Notepad++ to search). In this respect I really like Linux (like) systems where the home folder is yours to structure, easily migrated to a new installations. Windows' C drive is undeniably a mess...

Also, for Windows XP I have countlessly encountered serious slow downs after approximately a half to one year. Regular used XP's get slower quicker then sparsely used, but it is significant. Windows 7 on the other does a good job so far.

Most libraries or code bases are developed (around) the Unix way of folder naming and uses. it's become sort of a standard. And especially with GCC it might be easier to stick with their "original target/descendant platform". I barely ever use Linux / Mac / Amiga though.
[size="2"]SignatureShuffle: [size="2"]Random signature images on fora
gretty
gretty
Cool, thanks for all the replies. I thought that most of the problems(or bad feelings towards windows OS) would be related to functionality & algorithms(how windows searchs for files compared to Unix/Mac OS) but, it seems that windows is not badly regarded because it has inefficient algorithms compared to other OS's, but because of the users experience(annoying features/design etc.). Would this be correct?

In terms of file management(speed, efficiency, safety), operating system actions (opening an application, etc.) & pretty much the nuts & bolts of the OS is windows inefficient, insecure & etc? Maybe Windows doesn't reveal their logic & algorithms for doing those things, so we dont know?


Quote:
Original post by Antheus
Second issue are defaults. Especially pre-Vista, default installation left machine wide open. While they could be locked fairly tightly via policies, most machines were installed by kids "who knew computers". Many IT shops also didn't pay enough attention, or "the boss needs to be able to install Bonzi Buddy".

End result is, there is large install base of unpatched XP machines, some which are vulnerable to some fairly trivial and very old attacks.



Could you explain this further? This is a flaw that windows has in security but I dont understand what exactly, are you saying having default installations(what is that?) allow a program to install, snoop & delete the users files because they now have the security level approval to make changes in the C:/ directory?

reptor
reptor
Secunia published a Half-Year Report 2010 (under "Resources - Reports") which talks about a switch from Microsoft to 3rd-party programs regarding security problems / threats.

To put it simply, as the operating system has improved, attackers are targeting 3rd-party programs more. So they just go after the weak link which is natural.

Games belong to this group as well. Put a reasonably successful game on-line and it will be attacked. Would you like your game to be used as a security hole into a user's system? It's about time for people to wake up to this problem.
nobodynews
nobodynews
Quote:
Original post by gretty
Quote:
Original post by Antheus
Second issue are defaults. Especially pre-Vista, default installation left machine wide open. While they could be locked fairly tightly via policies, most machines were installed by kids "who knew computers". Many IT shops also didn't pay enough attention, or "the boss needs to be able to install Bonzi Buddy".

End result is, there is large install base of unpatched XP machines, some which are vulnerable to some fairly trivial and very old attacks.



Could you explain this further? This is a flaw that windows has in security but I dont understand what exactly, are you saying having default installations(what is that?) allow a program to install, snoop & delete the users files because they now have the security level approval to make changes in the C:/ directory?
I'm sure there's more to it, but Antheus is probably referring to most users having full admininistration rights on their OS pre-Vista because, from what I gather, any user profile set up during installation was given full admin rights. This meant anything the user installed *also* had full admin rights, including that screensaver installer that contained a virus that Bob in accounting just had to install (as a hypothetical).
C++: A Dialog | C++0x Features: Part1 (lambdas, auto, static_assert) , Part 2 (rvalue references) ,
taby
taby
IMHO, the biggest security hole in Windows has been and still is that it binds the Client for Microsoft Networks and File and Printer Sharing modules to your network device by default. It was outright dangerous 15 years ago, and it's kind of silly now. People might say that the built-in Windows firewall solves this problem, but it's obviously just plain smarter to not cause the problem in the first place -- enable the bindings as required, not by default!

P.S. I use Windows primarily, Ubuntu once in a while. Love them both.
Antheus
Antheus
Quote:
Original post by gretty

Could you explain this further? This is a flaw that windows has in security but I dont understand what exactly, are you saying having default installations(what is that?) allow a program to install, snoop & delete the users files because they now have the security level approval to make changes in the C:/ directory?


Install Linux. It will come with no services running, with permissions locked down, defaulting to local user. Admin account often needs to be created.

Want to add a service - it comes with no permissions, not running, with no access. Each of these must be granted specifically.

Install an app - it can only be installed into a single well-defined path, with no permissions for anything.

It depends from distro to distro, Debian used to be pretty draconic. Ubuntu and other popular distros install much more, but still use conservative defaults.


Enter Windows.
- Standard installation requires creation of admin account, and XP-era didn't really offer much anything else
- Any application shat all over the disk, look at how DLLs are handled - just install anything anywhere
- Fresh install ran a bunch of admin-level services, from RPC to network sharing. Most of them were usable out-of-box without authentication remotely. I mean, the whole local DCOM was open to network by default.
- There was no file system level security. Anything can overwrite anything, with exception of some files which might have been in use. No problem, put something into startup
- Registry - just change associations, handlers, system parameters. Permissions? We don't need no stinking permissions.
- One word: BHO
- Two words: Thread injection
- Administrative shares (undeletable)
- Autorun
- Alerter spam
- .inf, .jpg and other extension renaming exploits

And probably lots of more stuff I don't remember.


All of this is solvable and was even in XP days. A good installation will be fairly locked down and safe. Vista and 7 solved most of these and went with safer defaults. But there was still too much disabling or configuring each feature from default (unrestricted, open) to something safer or disabling it alltogether. Fairly good for IT departments with custom installs, horrible for home users, who didn't even patch.

Assuming you are given that option, many applications require these features just to function.


Most of this isn't as relevant as it used to be. With move towards cloud and browser becoming main application the usefulness of local exploits waned. People have also learned to not download things or at least not run them.


But at the height of botwars, you would do a fresh install of XP. Plug it into net on a public IP to download latest patches, and during those 10 minutes it would get infected (real link from there seems down right now). It really was that bad, it was a running joke. In the days of Blaster, I had a USB key and a floppy in pocket all the time, so I could just fix random people's computer on the spot. It was later followed by trying to get them to download and install 300MB of patches, which they never did.


As said, most of this isn't relevant anymore and things have improved. Firewall on by default, better and more fine-grained permissions, better applications, more restrictions, better sandboxing, better IE and other browsers, ...

But yes, it was that bad.
taby
taby
Quote:
Original post by Antheus
But at the height of botwars, you would do a fresh install of XP. Plug it into net on a public IP to download latest patches, and during those 10 minutes it would get infected (real link from there seems down right now). It really was that bad, it was a running joke.


If I recall correctly, the problem was that the Client for Microsoft Networks and File and Printer Sharing modules were/are bound to the network device by default. Disabling those bindings manually on a fresh install before plugging in the network cable usually kept the problem in check until the patches could be downloaded. Of course, like you say, none of our friends actually followed this procedure, and we always ended up cleaning up the mess. :)

Let's not be too harsh on Windows file security though. It was around in the early 90's in the NT version, you just had to pay a lot of money for it. ;)
Antheus
Antheus
Quote:
Original post by taby

Let's not be too harsh on Windows file security though.


For the record, my ecosystem has always been Windows. There was that awkward phase when I was using Windows machine in a Linux shop...

The reason is very pragmatic: drivers work. I have yet to see a Linux desktop machine or laptop where *every* hardware would be fully supported. And Linux is really happy running inside virtual machines, so why not take the best of both worlds.

But I've learned to tame it, to disable 90% of stuff that isn't needed, and haven't administered anything in years. The only thing I still do is update video drivers and patches usually install themselves.


But I also know what Windows means in more casual setting.
SimonForsman
SimonForsman
Quote:
Original post by TheTroll
Most of the complaints are not about the Windows OS but about applications written for the OS. People don't follow the rules and bad things happen.

Windows slowing down is not inherit to the OS but because of the applications installed.

Same goes for messy Start, files not being in the right place, other things like viewers, etc.

Drivers are not part of the OS but from an outside source.

So where do the security issues come from? Two places, people attack the OS because it is the most popular in the world. If you have enough people beating on it you will find every flaw there is. Next, the easier you make something to use the less security there is. It is the nature of the beast.

theTroll


Actally a significant amount of security flaws are from third party software, having a central update system is a huge advantage from a security point of view since it keeps everything up to date, not just the OS itself.

The problem with the Windows start menu is that everyone insists on putting their application links in startmenu->companyname->productname->link while on Linux they're put in startmenu->category->link

For games things have improved with Vista (the new separate game listing is great as long as developers support it).

Basically 99% of todays problems with Windows is due to third party developers thinking that their product is somehow more important than anything else on the system. (When every single vendor absolutely has to have their own update manager running in the systray, their own browser extensions to "aid" the user, and ofcourse the expectance that you'll remember the name of the company that released the product rather than what the product does when its time for you to use it)
[size="1"]I don't suffer from insanity, I'm enjoying every minute of it.
The voices in my head may not be real, but they have some good ideas!
Beyond_Repair
Beyond_Repair
Agree Windows could do with more logical categorization. It's not just the start menu and 3rd party software - it's also the default folders given by Microsoft such as C:\"really long path"\My Pictures (all in localized spelling), or just C:\Program Files without any further categorization..

Disclaimer: Did not use Win 7 yet.

Topic Locked

This topic has been locked by a moderator. New replies are not allowed.

Sign in to reply to this topic.