How secure and safe is biometric technology? The reason I bring this up is
because I was able to log in using my finger with a band-aid attached and
this definitely makes me question the security and safety of biometric
technology at least as far as laptops go. I imagine there probably is lots
of articles on this already but I wanted the opinions of this newsgroup.
Thanks in advance for the replies.

Re: Biometrics by Milo

Milo
Sun Jul 13 04:46:57 CDT 2008

Finger with the band aid on?....

For finger print technology it has to match a significant or set numbers of
marker points in your fingers to accept to validate you... Mind if we ask
what notebook are you using and including its model. ( for a test )

"Dan" <Dan@discussions.microsoft.com> wrote in message
news:711C6B3D-E988-4C54-870E-98B985992282@microsoft.com...
> How secure and safe is biometric technology? The reason I bring this up
> is
> because I was able to log in using my finger with a band-aid attached and
> this definitely makes me question the security and safety of biometric
> technology at least as far as laptops go. I imagine there probably is
> lots
> of articles on this already but I wanted the opinions of this newsgroup.
> Thanks in advance for the replies.


Re: Biometrics by Dan

Dan
Sun Jul 13 06:26:03 CDT 2008

Thank you for your feedback. This vulnerability must be reported through the
proper channels for safety and security reasons. Have a nice day.

"Milo" wrote:

> Finger with the band aid on?....
>
> For finger print technology it has to match a significant or set numbers of
> marker points in your fingers to accept to validate you... Mind if we ask
> what notebook are you using and including its model. ( for a test )
>
> "Dan" <Dan@discussions.microsoft.com> wrote in message
> news:711C6B3D-E988-4C54-870E-98B985992282@microsoft.com...
> > How secure and safe is biometric technology? The reason I bring this up
> > is
> > because I was able to log in using my finger with a band-aid attached and
> > this definitely makes me question the security and safety of biometric
> > technology at least as far as laptops go. I imagine there probably is
> > lots
> > of articles on this already but I wanted the opinions of this newsgroup.
> > Thanks in advance for the replies.
>
>

Re: Biometrics by ~BD~

~BD~
Sun Jul 13 07:31:51 CDT 2008

Dan

I think Milo works for Microsoft!

What harm can giving up the make and model of your laptop do?

Dave


"Dan" <Dan@discussions.microsoft.com> wrote in message
news:F987783D-FB49-49AE-8290-2325C6F5EBB5@microsoft.com...
> Thank you for your feedback. This vulnerability must be reported through
> the
> proper channels for safety and security reasons. Have a nice day.
>
> "Milo" wrote:
>
>> Finger with the band aid on?....
>>
>> For finger print technology it has to match a significant or set numbers
>> of
>> marker points in your fingers to accept to validate you... Mind if we ask
>> what notebook are you using and including its model. ( for a test )
>>
>> "Dan" <Dan@discussions.microsoft.com> wrote in message
>> news:711C6B3D-E988-4C54-870E-98B985992282@microsoft.com...
>> > How secure and safe is biometric technology? The reason I bring this
>> > up
>> > is
>> > because I was able to log in using my finger with a band-aid attached
>> > and
>> > this definitely makes me question the security and safety of biometric
>> > technology at least as far as laptops go. I imagine there probably is
>> > lots
>> > of articles on this already but I wanted the opinions of this
>> > newsgroup.
>> > Thanks in advance for the replies.
>>
>>



Re: Biometrics by Dan

Dan
Sun Jul 13 15:34:23 CDT 2008

I do volunteer work for US-Cert and so I must go through the proper channels.
Thanks for your feedback anyway, BD.

"~BD~" wrote:

> Dan
>
> I think Milo works for Microsoft!
>
> What harm can giving up the make and model of your laptop do?
>
> Dave
>
>
> "Dan" <Dan@discussions.microsoft.com> wrote in message
> news:F987783D-FB49-49AE-8290-2325C6F5EBB5@microsoft.com...
> > Thank you for your feedback. This vulnerability must be reported through
> > the
> > proper channels for safety and security reasons. Have a nice day.
> >
> > "Milo" wrote:
> >
> >> Finger with the band aid on?....
> >>
> >> For finger print technology it has to match a significant or set numbers
> >> of
> >> marker points in your fingers to accept to validate you... Mind if we ask
> >> what notebook are you using and including its model. ( for a test )
> >>
> >> "Dan" <Dan@discussions.microsoft.com> wrote in message
> >> news:711C6B3D-E988-4C54-870E-98B985992282@microsoft.com...
> >> > How secure and safe is biometric technology? The reason I bring this
> >> > up
> >> > is
> >> > because I was able to log in using my finger with a band-aid attached
> >> > and
> >> > this definitely makes me question the security and safety of biometric
> >> > technology at least as far as laptops go. I imagine there probably is
> >> > lots
> >> > of articles on this already but I wanted the opinions of this
> >> > newsgroup.
> >> > Thanks in advance for the replies.
> >>
> >>
>
>
>

Re: Biometrics by ~BD~

~BD~
Sun Jul 13 16:30:49 CDT 2008

You're welcome, Dan

"Dan" <Dan@discussions.microsoft.com> wrote in message
news:4F9FC3F4-2D95-4BC7-8FD8-07DC0FF07034@microsoft.com...
>I do volunteer work for US-Cert and so I must go through the proper
>channels.
> Thanks for your feedback anyway, BD.



Re: Biometrics by Dan

Dan
Tue Jul 15 16:27:16 CDT 2008

Bingo! You solved the issue and yes it is one of those cheap fingerprint
scanners where you just swipe your finger so it must have already had the
image of my fingerprint on the scanner. It sounds like someone would need to
clean the fingerprint scanner each time and it does indeed seem very easy to
fool. So much for the security of Biometrics at least cheap Biometric devices

"Juergen Nieveler" wrote:

> Dan <Dan@discussions.microsoft.com> wrote:
>
> > How secure and safe is biometric technology? The reason I bring this
> > up is because I was able to log in using my finger with a band-aid
> > attached and this definitely makes me question the security and safety
> > of biometric technology at least as far as laptops go. I imagine
> > there probably is lots of articles on this already but I wanted the
> > opinions of this newsgroup. Thanks in advance for the replies.
>
> If this was one of those fingerprint readers where you simply put your
> finger on (as opposed to those where you rub your finger along the
> contact plate in a swipe motion), chances are that the camera inside
> picked up the latent fingerprint that was still on the glass - this is
> a common vulnerability of those cheap camera-based readers. All they do
> is notice "Oh, something is pushing on the glass, and I recognise the
> pattern" - if the person who last used it had greasy fingers, the
> fingerprint would still be on the glass, so putting something on the
> glass that doesn't have OTHER fingerprints will force the camera to use
> the weak fingerprint image still visible to it...
>
> The swipe-type readers are safer in that there can't be an image left
> on the reader... but many of them still can be fooled by a fake
> fingerprint made by taking the fingerprint off something somebody
> touched (lots of how-to's available for that...).
>
> Juergen Nieveler
> --
> A feature is a bug with seniority.
>

Re: Biometrics by Dan

Dan
Wed Jul 16 07:38:29 CDT 2008

Thank you, Steve. I appreciate your feedback. Another problem we face in
computing today is the industry is not fully backing tougher security and
safety protocols. An example of this is the American Express website which
will only allow me to input a password that is less than optimal according to
Microsoft's password checker. Microsoft is doing their part in many ways but
the rest of the industry must catch up.

http://www.microsoft.com/protect/yourself/password/checker.mspx

It is critical in this day and age to have alternatives to just the main
Windows operating system that includes Internet Explorer. I am very pleased
with Microsoft and their technologies so I will continue to use them
frequently. However, as a power user, I am very pleased that users have
alternatives such as Mozilla Firefox as an option and it does indeed remain
for use with Windows 98 Second Edition at least until December 2008 because
that is when Mozilla Firefox 2.x support is scheduled to end.

http://en.wikipedia.org/wiki/Mozilla_Firefox

This is most unfortunate in my view since the 9x source code has definite
advantages over the NT business line of source code. 9x computers were meant
as stand-a-lone machines and thus are great for consumers who do not need or
want the ability to have others tinker with their machines. The many
services provided in XP allow for their to many greater points of access to a
fully patched XP machine than a fully patched 98 Second Edition machine using
Mozilla Firefox compared to Internet Explorer since Internet Explorer patches
for Windows 98 Second Edition ended July 11, 2006. The NT source code is at
risk as can be seen by the postings of US-Cert which is the computer
readiness team and part of the Department of Homeland Security.

http://www.us-cert.gov/cas/bulletins/SB08-196.html

Microsoft -- windows-nt

Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, XP SP2 and
SP3, and Server 2003 SP1 and SP2 allows remote attackers to conduct cache
poisoning attacks via unknown vectors, aka "DNS Cache Poisoning
Vulnerability," a different vulnerability than CVE-2008-1447.

unknown
2008-07-08
9.4 CVE-2008-1454 MS

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1454

http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx

I know a fair amount about computer security and safety and helped beta test
Windows Vista Ultimate 32 bit edition for Microsoft as a volunteer. I got
the DVD with the ISO image from a friend named Jeff who was a systems
engineer and also testing Vista for Microsoft and then got approval from
Microsoft to test it and inputed the given product key that Microsoft gave me
for the evaluation version. The problem is that Microsoft has only one line
of code and that makes it that much easier for hackers to target many
machines and take them over.

With Windows 98 Second Edition, a single machine might have been compromised
but not the whole network. I have had problems with a workplace that I
recently worked at that stupidly switched to all XP machines and did not
leave any 98 Second Edition machines in place and that included my own
Windows 98 Second Edition machine there. That was a huge mistake that I
don't think the business will repeat. With the 98SE machine, I knew and I
was right that my machine would be very unlikely to be hacked compared to the
compromised machines of the NT (XP Professional) in this case. The incident
happened in the summer of 2007. I will give you more details via secure
email if you like.

I have read in a book about Microsoft that early system engineers complained
that NT did not have a true maintenance operating system like DOS. Chris
Quirke, MVP. has a good article about the safety and security concerns.
Windows 9x is safe at its core compared to Windows NT line which includes
2000, XP and Vista of course. There was also a rumor a while back that parts
of the NT source code were leaked over the Internet compared to the 9x source
code which was never leaked over the Internet, AFAIK.

http://cquirke.blogspot.com/

(Note: Chris Quirke's 9x website talks about the 9x compared to NT security
and safety discussion)

There is also Unix/Linux technologies and I have played around a little bit
with Ubuntu Linux but I am in no way proficient with it and have only read a
small portion of a big book about Ubuntu Linux.

Finally, my question to you is that I know about the economics and how
costly it would be for Microsoft to continue the 9x line or even overall it
to make it usable in today's environment but wouldn't the economic cost be
worth the great reward. I have friends of mine at summer camp who are
planning mainly on building 98 Second Edition machines just for the ability
to play older games and secondly because these friends feel as I do about how
it is harder to hack into a 9x machine with the proper safeguards applied
such as a wired router that has the wireless broadcast signal turned off so
as not to attract unwanted or uneeded attention from hackers.

If Microsoft will not develop the 9x source code then at least sell it to
the United States Military so that the Defense Department can more fully
protect their military infrastructure from external threats and even better
from potential internal threats from their network of computers from a
potential spy. The possibilities for 9x are endless and so please I ask you
as a professional to have Microsoft sell 9x kernel unless Microsoft is
willing which I think would be a smart business move to invest money in the
another Windows 9x that would not subtract features such as easy access to
DOS and ideally the ability to play old classic games like Windows Millennium
(ME) did.

I am a gamer who is a Generation X'er who got his start on an IBM PCjr
playing King's Quest 1 on a 5.25 inch floppy disk that was made by Sierra On
Line and had 16 colors and the speaker on the machine supported 3 sounds at
once which was cool. The game had 128 kilobytes on one disk and how is that
for compression despite the obvious limitations compared to today's games. I
still have this machine in storage and it still works! The interesting thing
is that a poster to Game Informer which I read posted about how he was 17 and
liked older classic games and his friends made fun of him for it and his
first name was Daniel too. <grin>

I also enjoy reading PC World, 2600 which is a hacker magazine (I must keep
up to prevent hackers from compromising all of us), and other computer and
network books. I took several computer classes in college and who knows I
may go back and get another undergraduate degree but this time in computer
science. I know that a dream will allow a little guy like me change the
world despite all the challenges life has thrown at me. Please feel free to
contact me by email or I can contact you by email. My email address is with
Microsoft and on their records. I can also give you an srx number on a
recent case with Microsoft if you need to confirm my identity. Thanks again
for all you do, Steve and Go Microsoft!

"Steve Riley [MSFT]" wrote:

> Biometrics can never replace passwords, because they aren't secrets.
>
> It's me, and here's my proof: why identity and authentication must remain
> distinct
> http://technet.microsoft.com/en-us/library/cc512578(TechNet.10).aspx
>
>
> --
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
>
> "Dan" <Dan@discussions.microsoft.com> wrote in message
> news:774EE7CB-CA2B-4E7B-82CD-20D2B56C04B4@microsoft.com...
> > Bingo! You solved the issue and yes it is one of those cheap fingerprint
> > scanners where you just swipe your finger so it must have already had the
> > image of my fingerprint on the scanner. It sounds like someone would need
> > to
> > clean the fingerprint scanner each time and it does indeed seem very easy
> > to
> > fool. So much for the security of Biometrics at least cheap Biometric
> > devices
> >
> > "Juergen Nieveler" wrote:
> >
> >> Dan <Dan@discussions.microsoft.com> wrote:
> >>
> >> > How secure and safe is biometric technology? The reason I bring this
> >> > up is because I was able to log in using my finger with a band-aid
> >> > attached and this definitely makes me question the security and safety
> >> > of biometric technology at least as far as laptops go. I imagine
> >> > there probably is lots of articles on this already but I wanted the
> >> > opinions of this newsgroup. Thanks in advance for the replies.
> >>
> >> If this was one of those fingerprint readers where you simply put your
> >> finger on (as opposed to those where you rub your finger along the
> >> contact plate in a swipe motion), chances are that the camera inside
> >> picked up the latent fingerprint that was still on the glass - this is
> >> a common vulnerability of those cheap camera-based readers. All they do
> >> is notice "Oh, something is pushing on the glass, and I recognise the
> >> pattern" - if the person who last used it had greasy fingers, the
> >> fingerprint would still be on the glass, so putting something on the
> >> glass that doesn't have OTHER fingerprints will force the camera to use
> >> the weak fingerprint image still visible to it...
> >>
> >> The swipe-type readers are safer in that there can't be an image left
> >> on the reader... but many of them still can be fooled by a fake
> >> fingerprint made by taking the fingerprint off something somebody
> >> touched (lots of how-to's available for that...).
> >>
> >> Juergen Nieveler
> >> --
> >> A feature is a bug with seniority.
> >>

Re: Biometrics by Daniel

Daniel
Wed Jul 16 08:36:22 CDT 2008

So, to make a long story short, you claim the the "Windows 9X" source code
and entire OS is far more secure than today's "Windows NT" - i.e. Vista?

--
Sincerely,

Daniel Petri
MVP, Senior IT consultant, trainer
www.petri.co.il

"Dan" <Dan@discussions.microsoft.com> wrote in message
news:175E7266-E50E-40A2-BE3C-305165779621@microsoft.com...
> Thank you, Steve. I appreciate your feedback. Another problem we face in
> computing today is the industry is not fully backing tougher security and
> safety protocols. An example of this is the American Express website
> which
> will only allow me to input a password that is less than optimal according
> to
> Microsoft's password checker. Microsoft is doing their part in many ways
> but
> the rest of the industry must catch up.
>
> http://www.microsoft.com/protect/yourself/password/checker.mspx
>
> It is critical in this day and age to have alternatives to just the main
> Windows operating system that includes Internet Explorer. I am very
> pleased
> with Microsoft and their technologies so I will continue to use them
> frequently. However, as a power user, I am very pleased that users have
> alternatives such as Mozilla Firefox as an option and it does indeed
> remain
> for use with Windows 98 Second Edition at least until December 2008
> because
> that is when Mozilla Firefox 2.x support is scheduled to end.
>
> http://en.wikipedia.org/wiki/Mozilla_Firefox
>
> This is most unfortunate in my view since the 9x source code has definite
> advantages over the NT business line of source code. 9x computers were
> meant
> as stand-a-lone machines and thus are great for consumers who do not need
> or
> want the ability to have others tinker with their machines. The many
> services provided in XP allow for their to many greater points of access
> to a
> fully patched XP machine than a fully patched 98 Second Edition machine
> using
> Mozilla Firefox compared to Internet Explorer since Internet Explorer
> patches
> for Windows 98 Second Edition ended July 11, 2006. The NT source code is
> at
> risk as can be seen by the postings of US-Cert which is the computer
> readiness team and part of the Department of Homeland Security.
>
> http://www.us-cert.gov/cas/bulletins/SB08-196.html
>
> Microsoft -- windows-nt
>
> Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, XP SP2 and
> SP3, and Server 2003 SP1 and SP2 allows remote attackers to conduct cache
> poisoning attacks via unknown vectors, aka "DNS Cache Poisoning
> Vulnerability," a different vulnerability than CVE-2008-1447.
>
> unknown
> 2008-07-08
> 9.4 CVE-2008-1454 MS
>
> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1454
>
> http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx
>
> I know a fair amount about computer security and safety and helped beta
> test
> Windows Vista Ultimate 32 bit edition for Microsoft as a volunteer. I got
> the DVD with the ISO image from a friend named Jeff who was a systems
> engineer and also testing Vista for Microsoft and then got approval from
> Microsoft to test it and inputed the given product key that Microsoft gave
> me
> for the evaluation version. The problem is that Microsoft has only one
> line
> of code and that makes it that much easier for hackers to target many
> machines and take them over.
>
> With Windows 98 Second Edition, a single machine might have been
> compromised
> but not the whole network. I have had problems with a workplace that I
> recently worked at that stupidly switched to all XP machines and did not
> leave any 98 Second Edition machines in place and that included my own
> Windows 98 Second Edition machine there. That was a huge mistake that I
> don't think the business will repeat. With the 98SE machine, I knew and I
> was right that my machine would be very unlikely to be hacked compared to
> the
> compromised machines of the NT (XP Professional) in this case. The
> incident
> happened in the summer of 2007. I will give you more details via secure
> email if you like.
>
> I have read in a book about Microsoft that early system engineers
> complained
> that NT did not have a true maintenance operating system like DOS. Chris
> Quirke, MVP. has a good article about the safety and security concerns.
> Windows 9x is safe at its core compared to Windows NT line which includes
> 2000, XP and Vista of course. There was also a rumor a while back that
> parts
> of the NT source code were leaked over the Internet compared to the 9x
> source
> code which was never leaked over the Internet, AFAIK.
>
> http://cquirke.blogspot.com/
>
> (Note: Chris Quirke's 9x website talks about the 9x compared to NT
> security
> and safety discussion)
>
> There is also Unix/Linux technologies and I have played around a little
> bit
> with Ubuntu Linux but I am in no way proficient with it and have only read
> a
> small portion of a big book about Ubuntu Linux.
>
> Finally, my question to you is that I know about the economics and how
> costly it would be for Microsoft to continue the 9x line or even overall
> it
> to make it usable in today's environment but wouldn't the economic cost be
> worth the great reward. I have friends of mine at summer camp who are
> planning mainly on building 98 Second Edition machines just for the
> ability
> to play older games and secondly because these friends feel as I do about
> how
> it is harder to hack into a 9x machine with the proper safeguards applied
> such as a wired router that has the wireless broadcast signal turned off
> so
> as not to attract unwanted or uneeded attention from hackers.
>
> If Microsoft will not develop the 9x source code then at least sell it to
> the United States Military so that the Defense Department can more fully
> protect their military infrastructure from external threats and even
> better
> from potential internal threats from their network of computers from a
> potential spy. The possibilities for 9x are endless and so please I ask
> you
> as a professional to have Microsoft sell 9x kernel unless Microsoft is
> willing which I think would be a smart business move to invest money in
> the
> another Windows 9x that would not subtract features such as easy access to
> DOS and ideally the ability to play old classic games like Windows
> Millennium
> (ME) did.
>
> I am a gamer who is a Generation X'er who got his start on an IBM PCjr
> playing King's Quest 1 on a 5.25 inch floppy disk that was made by Sierra
> On
> Line and had 16 colors and the speaker on the machine supported 3 sounds
> at
> once which was cool. The game had 128 kilobytes on one disk and how is
> that
> for compression despite the obvious limitations compared to today's games.
> I
> still have this machine in storage and it still works! The interesting
> thing
> is that a poster to Game Informer which I read posted about how he was 17
> and
> liked older classic games and his friends made fun of him for it and his
> first name was Daniel too. <grin>
>
> I also enjoy reading PC World, 2600 which is a hacker magazine (I must
> keep
> up to prevent hackers from compromising all of us), and other computer and
> network books. I took several computer classes in college and who knows I
> may go back and get another undergraduate degree but this time in computer
> science. I know that a dream will allow a little guy like me change the
> world despite all the challenges life has thrown at me. Please feel free
> to
> contact me by email or I can contact you by email. My email address is
> with
> Microsoft and on their records. I can also give you an srx number on a
> recent case with Microsoft if you need to confirm my identity. Thanks
> again
> for all you do, Steve and Go Microsoft!
>
> "Steve Riley [MSFT]" wrote:
>
>> Biometrics can never replace passwords, because they aren't secrets.
>>
>> It's me, and here's my proof: why identity and authentication must remain
>> distinct
>> http://technet.microsoft.com/en-us/library/cc512578(TechNet.10).aspx
>>
>>
>> --
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>> http://www.protectyourwindowsnetwork.com
>>
>>
>>
>> "Dan" <Dan@discussions.microsoft.com> wrote in message
>> news:774EE7CB-CA2B-4E7B-82CD-20D2B56C04B4@microsoft.com...
>> > Bingo! You solved the issue and yes it is one of those cheap
>> > fingerprint
>> > scanners where you just swipe your finger so it must have already had
>> > the
>> > image of my fingerprint on the scanner. It sounds like someone would
>> > need
>> > to
>> > clean the fingerprint scanner each time and it does indeed seem very
>> > easy
>> > to
>> > fool. So much for the security of Biometrics at least cheap Biometric
>> > devices
>> >
>> > "Juergen Nieveler" wrote:
>> >
>> >> Dan <Dan@discussions.microsoft.com> wrote:
>> >>
>> >> > How secure and safe is biometric technology? The reason I bring
>> >> > this
>> >> > up is because I was able to log in using my finger with a band-aid
>> >> > attached and this definitely makes me question the security and
>> >> > safety
>> >> > of biometric technology at least as far as laptops go. I imagine
>> >> > there probably is lots of articles on this already but I wanted the
>> >> > opinions of this newsgroup. Thanks in advance for the replies.
>> >>
>> >> If this was one of those fingerprint readers where you simply put your
>> >> finger on (as opposed to those where you rub your finger along the
>> >> contact plate in a swipe motion), chances are that the camera inside
>> >> picked up the latent fingerprint that was still on the glass - this is
>> >> a common vulnerability of those cheap camera-based readers. All they
>> >> do
>> >> is notice "Oh, something is pushing on the glass, and I recognise the
>> >> pattern" - if the person who last used it had greasy fingers, the
>> >> fingerprint would still be on the glass, so putting something on the
>> >> glass that doesn't have OTHER fingerprints will force the camera to
>> >> use
>> >> the weak fingerprint image still visible to it...
>> >>
>> >> The swipe-type readers are safer in that there can't be an image left
>> >> on the reader... but many of them still can be fooled by a fake
>> >> fingerprint made by taking the fingerprint off something somebody
>> >> touched (lots of how-to's available for that...).
>> >>
>> >> Juergen Nieveler
>> >> --
>> >> A feature is a bug with seniority.
>> >>


Re: Biometrics by Steve

Steve
Wed Jul 16 22:13:58 CDT 2008

Dan, I recommend you rethink your logic.

The Windows 3.1/9x code was designed and written in an entirely different
age -- one in which TCP/IP was not the standard networking protocol, one in
which indeed networks were rare, and one in which everyone (we and our
customers) assumed that only good guys used computers.

The world no longer lives in that age. If you take any kind of system
(operating system, engineering system, whatever) and place it in an
environment that is wildly different than the original assumptions, that
system will fail catastrophically. There is simply no way we can retrofit
that very old code to function correctly in today's world of intentional
attacks.

I'm not exactly sure how you can make the statement that "a 9x machine with
the proper safeguards such as a wired router that has wireless broadcast
signal turned off" is more secure than XP or Vista. Firstly, an XP or Vista
box behind such a router would be equally "safe" from attack. Secondly,
disabling SSID broadcast in reality does not accord you any security -- see
my article here:
http://blogs.technet.com/steriley/archive/2007/10/16/myth-vs-reality-wireless-ssids.aspx.

You quote a specific vulnerability below, about DNS, and you then make the
argument that this is a reason the military should be using 9x instead of
XP/Vista. How does that follow? How do you know that 9x doesn't have the
same vulnerability? No one can know, because we don't test 9x anymore. It's
simply too old.

And you mention our password checker. Actually, I think its recommendations
aren't strong enough, and I'm working with the folks who own that feature to
improve its strength.


--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com



"Dan" <Dan@discussions.microsoft.com> wrote in message
news:175E7266-E50E-40A2-BE3C-305165779621@microsoft.com...
> Thank you, Steve. I appreciate your feedback. Another problem we face in
> computing today is the industry is not fully backing tougher security and
> safety protocols. An example of this is the American Express website
> which
> will only allow me to input a password that is less than optimal according
> to
> Microsoft's password checker. Microsoft is doing their part in many ways
> but
> the rest of the industry must catch up.
>
> http://www.microsoft.com/protect/yourself/password/checker.mspx
>
> It is critical in this day and age to have alternatives to just the main
> Windows operating system that includes Internet Explorer. I am very
> pleased
> with Microsoft and their technologies so I will continue to use them
> frequently. However, as a power user, I am very pleased that users have
> alternatives such as Mozilla Firefox as an option and it does indeed
> remain
> for use with Windows 98 Second Edition at least until December 2008
> because
> that is when Mozilla Firefox 2.x support is scheduled to end.
>
> http://en.wikipedia.org/wiki/Mozilla_Firefox
>
> This is most unfortunate in my view since the 9x source code has definite
> advantages over the NT business line of source code. 9x computers were
> meant
> as stand-a-lone machines and thus are great for consumers who do not need
> or
> want the ability to have others tinker with their machines. The many
> services provided in XP allow for their to many greater points of access
> to a
> fully patched XP machine than a fully patched 98 Second Edition machine
> using
> Mozilla Firefox compared to Internet Explorer since Internet Explorer
> patches
> for Windows 98 Second Edition ended July 11, 2006. The NT source code is
> at
> risk as can be seen by the postings of US-Cert which is the computer
> readiness team and part of the Department of Homeland Security.
>
> http://www.us-cert.gov/cas/bulletins/SB08-196.html
>
> Microsoft -- windows-nt
>
> Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, XP SP2 and
> SP3, and Server 2003 SP1 and SP2 allows remote attackers to conduct cache
> poisoning attacks via unknown vectors, aka "DNS Cache Poisoning
> Vulnerability," a different vulnerability than CVE-2008-1447.
>
> unknown
> 2008-07-08
> 9.4 CVE-2008-1454 MS
>
> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1454
>
> http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx
>
> I know a fair amount about computer security and safety and helped beta
> test
> Windows Vista Ultimate 32 bit edition for Microsoft as a volunteer. I got
> the DVD with the ISO image from a friend named Jeff who was a systems
> engineer and also testing Vista for Microsoft and then got approval from
> Microsoft to test it and inputed the given product key that Microsoft gave
> me
> for the evaluation version. The problem is that Microsoft has only one
> line
> of code and that makes it that much easier for hackers to target many
> machines and take them over.
>
> With Windows 98 Second Edition, a single machine might have been
> compromised
> but not the whole network. I have had problems with a workplace that I
> recently worked at that stupidly switched to all XP machines and did not
> leave any 98 Second Edition machines in place and that included my own
> Windows 98 Second Edition machine there. That was a huge mistake that I
> don't think the business will repeat. With the 98SE machine, I knew and I
> was right that my machine would be very unlikely to be hacked compared to
> the
> compromised machines of the NT (XP Professional) in this case. The
> incident
> happened in the summer of 2007. I will give you more details via secure
> email if you like.
>
> I have read in a book about Microsoft that early system engineers
> complained
> that NT did not have a true maintenance operating system like DOS. Chris
> Quirke, MVP. has a good article about the safety and security concerns.
> Windows 9x is safe at its core compared to Windows NT line which includes
> 2000, XP and Vista of course. There was also a rumor a while back that
> parts
> of the NT source code were leaked over the Internet compared to the 9x
> source
> code which was never leaked over the Internet, AFAIK.
>
> http://cquirke.blogspot.com/
>
> (Note: Chris Quirke's 9x website talks about the 9x compared to NT
> security
> and safety discussion)
>
> There is also Unix/Linux technologies and I have played around a little
> bit
> with Ubuntu Linux but I am in no way proficient with it and have only read
> a
> small portion of a big book about Ubuntu Linux.
>
> Finally, my question to you is that I know about the economics and how
> costly it would be for Microsoft to continue the 9x line or even overall
> it
> to make it usable in today's environment but wouldn't the economic cost be
> worth the great reward. I have friends of mine at summer camp who are
> planning mainly on building 98 Second Edition machines just for the
> ability
> to play older games and secondly because these friends feel as I do about
> how
> it is harder to hack into a 9x machine with the proper safeguards applied
> such as a wired router that has the wireless broadcast signal turned off
> so
> as not to attract unwanted or uneeded attention from hackers.
>
> If Microsoft will not develop the 9x source code then at least sell it to
> the United States Military so that the Defense Department can more fully
> protect their military infrastructure from external threats and even
> better
> from potential internal threats from their network of computers from a
> potential spy. The possibilities for 9x are endless and so please I ask
> you
> as a professional to have Microsoft sell 9x kernel unless Microsoft is
> willing which I think would be a smart business move to invest money in
> the
> another Windows 9x that would not subtract features such as easy access to
> DOS and ideally the ability to play old classic games like Windows
> Millennium
> (ME) did.
>
> I am a gamer who is a Generation X'er who got his start on an IBM PCjr
> playing King's Quest 1 on a 5.25 inch floppy disk that was made by Sierra
> On
> Line and had 16 colors and the speaker on the machine supported 3 sounds
> at
> once which was cool. The game had 128 kilobytes on one disk and how is
> that
> for compression despite the obvious limitations compared to today's games.
> I
> still have this machine in storage and it still works! The interesting
> thing
> is that a poster to Game Informer which I read posted about how he was 17
> and
> liked older classic games and his friends made fun of him for it and his
> first name was Daniel too. <grin>
>
> I also enjoy reading PC World, 2600 which is a hacker magazine (I must
> keep
> up to prevent hackers from compromising all of us), and other computer and
> network books. I took several computer classes in college and who knows I
> may go back and get another undergraduate degree but this time in computer
> science. I know that a dream will allow a little guy like me change the
> world despite all the challenges life has thrown at me. Please feel free
> to
> contact me by email or I can contact you by email. My email address is
> with
> Microsoft and on their records. I can also give you an srx number on a
> recent case with Microsoft if you need to confirm my identity. Thanks
> again
> for all you do, Steve and Go Microsoft!
>
> "Steve Riley [MSFT]" wrote:
>
>> Biometrics can never replace passwords, because they aren't secrets.
>>
>> It's me, and here's my proof: why identity and authentication must remain
>> distinct
>> http://technet.microsoft.com/en-us/library/cc512578(TechNet.10).aspx
>>
>>
>> --
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>> http://www.protectyourwindowsnetwork.com
>>
>>
>>
>> "Dan" <Dan@discussions.microsoft.com> wrote in message
>> news:774EE7CB-CA2B-4E7B-82CD-20D2B56C04B4@microsoft.com...
>> > Bingo! You solved the issue and yes it is one of those cheap
>> > fingerprint
>> > scanners where you just swipe your finger so it must have already had
>> > the
>> > image of my fingerprint on the scanner. It sounds like someone would
>> > need
>> > to
>> > clean the fingerprint scanner each time and it does indeed seem very
>> > easy
>> > to
>> > fool. So much for the security of Biometrics at least cheap Biometric
>> > devices
>> >
>> > "Juergen Nieveler" wrote:
>> >
>> >> Dan <Dan@discussions.microsoft.com> wrote:
>> >>
>> >> > How secure and safe is biometric technology? The reason I bring
>> >> > this
>> >> > up is because I was able to log in using my finger with a band-aid
>> >> > attached and this definitely makes me question the security and
>> >> > safety
>> >> > of biometric technology at least as far as laptops go. I imagine
>> >> > there probably is lots of articles on this already but I wanted the
>> >> > opinions of this newsgroup. Thanks in advance for the replies.
>> >>
>> >> If this was one of those fingerprint readers where you simply put your
>> >> finger on (as opposed to those where you rub your finger along the
>> >> contact plate in a swipe motion), chances are that the camera inside
>> >> picked up the latent fingerprint that was still on the glass - this is
>> >> a common vulnerability of those cheap camera-based readers. All they
>> >> do
>> >> is notice "Oh, something is pushing on the glass, and I recognise the
>> >> pattern" - if the person who last used it had greasy fingers, the
>> >> fingerprint would still be on the glass, so putting something on the
>> >> glass that doesn't have OTHER fingerprints will force the camera to
>> >> use
>> >> the weak fingerprint image still visible to it...
>> >>
>> >> The swipe-type readers are safer in that there can't be an image left
>> >> on the reader... but many of them still can be fooled by a fake
>> >> fingerprint made by taking the fingerprint off something somebody
>> >> touched (lots of how-to's available for that...).
>> >>
>> >> Juergen Nieveler
>> >> --
>> >> A feature is a bug with seniority.
>> >>

Re: Biometrics by Dan

Dan
Wed Jul 16 22:16:00 CDT 2008



"Daniel Petri <MVP>" wrote:

> So, to make a long story short, you claim the the "Windows 9X" source code
> and entire OS is far more secure than today's "Windows NT" - i.e. Vista?
>
> --
> Sincerely,
>
> Daniel Petri
> MVP, Senior IT consultant, trainer
> www.petri.co.il

The NT source code has much more security. The external security of Windows
Vista is especially good. The internal safety and core of 9x is safer than
the core of NT being based upon MS-DOS which is the maintenance operating
system of 98 Second Edition. What maintenance operating system does Vista
have? Please see Chris Quirke, MVP website.

http://cquirke.spaces.live.com/blog/cns!C7DAB1E724AB8C23!336.entry

I am talking about the debate that Chris Quirke, MVP talks about the safety
and security comparison. The best example I can give is to think of a major
fortress with great fortifications that is extremely hard to break through.
This major fortress represents the Windows NT source code and is especially
good right now in Windows Vista Service Pack 1 which I am using right now and
writing this post from Windows Vista Service Pack 1. Heck, I would not have
been a volunteer tester for Windows Vista on security if I did not like
Microsoft products and did not feel Windows NT was secure. For mobile
technology such as laptops I would highly suggest Windows Vista over any
other Windows when a person is traveling. However, with the proper
safeguards Windows 98 Second Edition can be made fairly secure if a user is
connected by a wired router to the Internet with anti-spyware programs such
as Spybot Search and Destroy and SpywareBlaster and using a currently
supported browser in 98 SE such as Mozilla Firefox which is currently
supported 98SE at least until December 2008 with Mozilla Firefox 2.

The problem here is that the Windows NT source code that includes Windows
2000, Windows XP and Windows Vista is meant to be managed by the IT
Professional and not by individual users. This is usually great in an office
environment that needs to limit the user's rights and grant usually the
majority of users a standard account and a few limited users an administrator
account. However, for home users such as when I am at home and not at work,
I like Windows 98 Second Edition because I enjoy playing older DOS games and
using older DOS programs that will not run in XP or Vista. In addition, if
someone does manage to break through all the external security of XP (not
sure about Vista since it is so new and indeed more secure than XP) then the
hacker(s) can wreck havoc on the network. This is what happened at my old
workplace when I went away on vacation during the summer and the higher-ups
decided it was time to get rid of Windows 98 Second Edition for good and only
have Windows XP Professional computers at my workplace.

Apparently, during the summer someone hacked the network and whether it was
an inside job (which I now suspect) or an outside job the individual(s) knew
their stuff really well. They undid all my work that took me a full year to
implement and bring the workplace from really bad computer problems to a well
functioning network and undid it in a matter of 3 months while I was gone.
If you have not figured it out yet, it was indeed a school that according to
the main computer network administrator Stephanie she said that former
individual(s) had left the school prior and destroyed the computer network
because these individual(s) were mad at the school and took their vengeance
on the computer network since they did not want to physically hurt the
children but it certainly hurt the children's ability to learn which really
makes me annoyed. Perhaps these individual(s) still had some prior access
that had not been revoked and were able to wreck havoc on the network during
the summer and it seems like they may have had to get on site and what better
opportunity while the main computer guy was out of the city.

However, if the few Windows 98 Second Edition machines had not been phased
out that summer then I would have been able to lean back upon those machines
since they were not accessible via the general school network and indeed did
not rely upon remote access which can be problematic when turned on as it was
with Windows XP Professional and with the Public School Network. I am
deliberately being vague about the specifics because this may end up being a
legal issue. In addition, Chris Quirke, MVP talks about the problem that
Windows Vista has because it lacks a true maintenance operating system like
MS-DOS in 98 Second Edition which had easy access to MS-DOS and good
backwards compatibility which Windows ME lacked. Windows ME looked good and
worked okay and did have better general USB support than 98SE but it really
was a joke and crippled operating system in my opinion since it lacked so
much and broke so easily. Finally, this proves the importance of the 9x
source code for the safety such as using one 98 Second Edition computer for
backup of the workplace that only one trusted individual who has been with
the company for many years is allowed to access. I have heard from my friend
John about how some businesses in New York State have used a 98 Second
Edition machine in the past as a gateway to the computer network which sounds
like a really smart idea. Windows 98 Second Edition also allowed consumers
who want to play old games to play the older games and individuals like
myself to work in a true text based interface and do away with the
limitations of a GUI interface. Just my two cents for what it is worth.

Re: Biometrics by Dan

Dan
Wed Jul 16 22:20:00 CDT 2008

Exactly. Thank you for your feedback.

"Juergen Nieveler" wrote:

> Dan <Dan@discussions.microsoft.com> wrote:
>
> > Bingo! You solved the issue and yes it is one of those cheap
> > fingerprint scanners where you just swipe your finger so it must have
> > already had the image of my fingerprint on the scanner. It sounds
> > like someone would need to clean the fingerprint scanner each time and
> > it does indeed seem very easy to fool. So much for the security of
> > Biometrics at least cheap Biometric devices
>
> There's a reason why Microsoft warns not to use their fingerprint
> reader for any security-sensitive stuff, it won't allow you to log on
> to a domain, for example...
>
> Juergen Nieveler
> --
> Line noise provided by German Telekom!
>

Re: Biometrics by Daniel

Daniel
Thu Jul 17 06:56:49 CDT 2008

Just like Steve Riley said, I strongly suggest you re-think your security
concepts Dan. Sitting behind my desk and reading your post about how your
school network was hacked all I can think of is that someone should have
done a better job in protecting their network. How can you even begin to
compare the strength of a properly-configured (I emphasize
"propery-configured"!!!) Windows XP/Vista machine with ANY Windows 9X
machine, when related to security??? Saying that 9X is better just because
someone hacked into a poorly-protected and wrongfully-configured network is
like claiming that a VW Beatle is far better than a modern car because
modern cars use computers to control almost any aspect of their engine and
behavior, therefore if someone hacks into that computer, all modern cars
will stop working. Right. Let's all just use MS-DOS because you "like to
play DOS games"... Sorry. Posting long answers doesn't qualify them as
correct.

--
Sincerely,

Daniel Petri
MVP, Senior IT consultant, trainer
www.petri.co.il

"Dan" <Dan@discussions.microsoft.com> wrote in message
news:B7ECB637-506D-4DF7-B636-923D0520D1BD@microsoft.com...
>
>
> "Daniel Petri <MVP>" wrote:
>
>> So, to make a long story short, you claim the the "Windows 9X" source
>> code
>> and entire OS is far more secure than today's "Windows NT" - i.e. Vista?
>>
>> --
>> Sincerely,
>>
>> Daniel Petri
>> MVP, Senior IT consultant, trainer
>> www.petri.co.il
>
> The NT source code has much more security. The external security of
> Windows
> Vista is especially good. The internal safety and core of 9x is safer
> than
> the core of NT being based upon MS-DOS which is the maintenance operating
> system of 98 Second Edition. What maintenance operating system does Vista
> have? Please see Chris Quirke, MVP website.
>
> http://cquirke.spaces.live.com/blog/cns!C7DAB1E724AB8C23!336.entry
>
> I am talking about the debate that Chris Quirke, MVP talks about the
> safety
> and security comparison. The best example I can give is to think of a
> major
> fortress with great fortifications that is extremely hard to break
> through.
> This major fortress represents the Windows NT source code and is
> especially
> good right now in Windows Vista Service Pack 1 which I am using right now
> and
> writing this post from Windows Vista Service Pack 1. Heck, I would not
> have
> been a volunteer tester for Windows Vista on security if I did not like
> Microsoft products and did not feel Windows NT was secure. For mobile
> technology such as laptops I would highly suggest Windows Vista over any
> other Windows when a person is traveling. However, with the proper
> safeguards Windows 98 Second Edition can be made fairly secure if a user
> is
> connected by a wired router to the Internet with anti-spyware programs
> such
> as Spybot Search and Destroy and SpywareBlaster and using a currently
> supported browser in 98 SE such as Mozilla Firefox which is currently
> supported 98SE at least until December 2008 with Mozilla Firefox 2.
>
> The problem here is that the Windows NT source code that includes Windows
> 2000, Windows XP and Windows Vista is meant to be managed by the IT
> Professional and not by individual users. This is usually great in an
> office
> environment that needs to limit the user's rights and grant usually the
> majority of users a standard account and a few limited users an
> administrator
> account. However, for home users such as when I am at home and not at
> work,
> I like Windows 98 Second Edition because I enjoy playing older DOS games
> and
> using older DOS programs that will not run in XP or Vista. In addition,
> if
> someone does manage to break through all the external security of XP (not
> sure about Vista since it is so new and indeed more secure than XP) then
> the
> hacker(s) can wreck havoc on the network. This is what happened at my old
> workplace when I went away on vacation during the summer and the
> higher-ups
> decided it was time to get rid of Windows 98 Second Edition for good and
> only
> have Windows XP Professional computers at my workplace.
>
> Apparently, during the summer someone hacked the network and whether it
> was
> an inside job (which I now suspect) or an outside job the individual(s)
> knew
> their stuff really well. They undid all my work that took me a full year
> to
> implement and bring the workplace from really bad computer problems to a
> well
> functioning network and undid it in a matter of 3 months while I was gone.
> If you have not figured it out yet, it was indeed a school that according
> to
> the main computer network administrator Stephanie she said that former
> individual(s) had left the school prior and destroyed the computer network
> because these individual(s) were mad at the school and took their
> vengeance
> on the computer network since they did not want to physically hurt the
> children but it certainly hurt the children's ability to learn which
> really
> makes me annoyed. Perhaps these individual(s) still had some prior access
> that had not been revoked and were able to wreck havoc on the network
> during
> the summer and it seems like they may have had to get on site and what
> better
> opportunity while the main computer guy was out of the city.
>
> However, if the few Windows 98 Second Edition machines had not been phased
> out that summer then I would have been able to lean back upon those
> machines
> since they were not accessible via the general school network and indeed
> did
> not rely upon remote access which can be problematic when turned on as it
> was
> with Windows XP Professional and with the Public School Network. I am
> deliberately being vague about the specifics because this may end up being
> a
> legal issue. In addition, Chris Quirke, MVP talks about the problem that
> Windows Vista has because it lacks a true maintenance operating system
> like
> MS-DOS in 98 Second Edition which had easy access to MS-DOS and good
> backwards compatibility which Windows ME lacked. Windows ME looked good
> and
> worked okay and did have better general USB support than 98SE but it
> really
> was a joke and crippled operating system in my opinion since it lacked so
> much and broke so easily. Finally, this proves the importance of the 9x
> source code for the safety such as using one 98 Second Edition computer
> for
> backup of the workplace that only one trusted individual who has been with
> the company for many years is allowed to access. I have heard from my
> friend
> John about how some businesses in New York State have used a 98 Second
> Edition machine in the past as a gateway to the computer network which
> sounds
> like a really smart idea. Windows 98 Second Edition also allowed
> consumers
> who want to play old games to play the older games and individuals like
> myself to work in a true text based interface and do away with the
> limitations of a GUI interface. Just my two cents for what it is worth.


Re: Biometrics by Dan

Dan
Thu Jul 17 12:50:01 CDT 2008

Thank you for your feedback, Steve. I was wondering since the Windows 9x
source code is now so old and not really useful then would Microsoft be
willing to sell it. I can think of some buyers who would be willing to pay
good money for the 9x source code and since it is no longer useful to
Microsoft because it is so old then why not just get rid of it and be done
with this now useless technology.


The NT source code was leaked:

http://www.microsoft.com/presspass/press/2004/Feb04/02-12windowssource.mspx

"Steve Riley [MSFT]" wrote:

> Dan, I recommend you rethink your logic.
>
> The Windows 3.1/9x code was designed and written in an entirely different
> age -- one in which TCP/IP was not the standard networking protocol, one in
> which indeed networks were rare, and one in which everyone (we and our
> customers) assumed that only good guys used computers.
>
> The world no longer lives in that age. If you take any kind of system
> (operating system, engineering system, whatever) and place it in an
> environment that is wildly different than the original assumptions, that
> system will fail catastrophically. There is simply no way we can retrofit
> that very old code to function correctly in today's world of intentional
> attacks.
>
> I'm not exactly sure how you can make the statement that "a 9x machine with
> the proper safeguards such as a wired router that has wireless broadcast
> signal turned off" is more secure than XP or Vista. Firstly, an XP or Vista
> box behind such a router would be equally "safe" from attack. Secondly,
> disabling SSID broadcast in reality does not accord you any security -- see
> my article here:
> http://blogs.technet.com/steriley/archive/2007/10/16/myth-vs-reality-wireless-ssids.aspx.
>
> You quote a specific vulnerability below, about DNS, and you then make the
> argument that this is a reason the military should be using 9x instead of
> XP/Vista. How does that follow? How do you know that 9x doesn't have the
> same vulnerability? No one can know, because we don't test 9x anymore. It's
> simply too old.
>
> And you mention our password checker. Actually, I think its recommendations
> aren't strong enough, and I'm working with the folks who own that feature to
> improve its strength.
>
>
> --
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>

Re: Biometrics by Paul

Paul
Fri Jul 18 03:13:02 CDT 2008

On Thu, 17 Jul 2008 10:50:01 -0700, Dan wrote:

> Thank you for your feedback, Steve. I was wondering since the Windows 9x
> source code is now so old and not really useful then would Microsoft be
> willing to sell it. I can think of some buyers who would be willing to pay
> good money for the 9x source code and since it is no longer useful to
> Microsoft because it is so old then why not just get rid of it and be done
> with this now useless technology.

Intellectual Property is not all about bits and lines of source code. You