Air Force now using super-secure version of Windows XP
Windows 7 might be getting all the attention lately, but Windows XP is having a quiet little renaissance of its own -- not only have sales of the venerable OS been extended until 2010, Microsoft is selling an ultra-secure version to the Air Force. The custom build ships with over 600 settings bolted down, and a security patch turnaround of just 72 hours compared to the standard edition's 57 days -- all because Steve Ballmer personally stepped in and approved the project at the Air Force's request. The effort's to standardize and preconfigure the OS has paid off: 85 percent of previous known exploits have been blocked, support call volume has dropped 40 percent, and the USAF has saved some $100 million in costs. Nice -- but don't get your hopes up, since it doesn't seem like Microsoft has any intention of selling this version to the public.
[Via Slashdot]
[Via Slashdot]



















Man does Ballmer look uncomfortable standing in that room.
wouldn't you be too, if you tried the mojave project on the airforce?
its....uh....xp, yeah...that's it!
You cannot blame him since the Air Force decides to trim down on cost on OS.
I believe Steve is having a flashback of the South Park episode where Bill Gates shows off Windows to the military.
...and the guy on the far right looks like Chief from BSG.
@Paul
That's because there are no chairs around...
Not to mention the fashion faux par. The belt doesn't match the shoes and jacket looks out of place. Just terrible Steve, terrible!
@Neary
Good spot that man.
That pic should be in an upcoming caption contest
It kinda looks like the guy in the pinkish shirt is copping a feel on that other guy in the suit.
Yeah, with his mutant backwards facing hand that just happens to change color at the wrist.
Officer on the left: "Sir, we actually ordered 98."
Ballmer: "Uh... How about ME?"
This might just the SECOND biggest mistake in the world...
Why is everyone trying to be subtle in their failing these days?
Back in the god old days it was simple:
Person A: "FIRST!!!11!!!1"
Person B: Insert witty sarcastic comment becoming highly ranked here
.........*Sigh*
Lol so true... It must be the 2009'ers...
=/
God old days? What the duck?
Err...I assumed the original post was a Get Smart reference?
Its a Get Smart reference
"Nice -- but don't get your hopes up, since it doesn't seem like Microsoft has any intention of selling this version to the public."
Just watch, its going to be up on the torrents in a week.
Sadly if you look at the numbers above, less calls, less flaws, happier customer... Microsoft could actually save money in the number of dumbass calls they get daily. could.
Well considering they charge you just to talk to them for support reasons, I doubt it.
Locked 600 settings and they get LESS calls? I guess their phone is just out of commission or they gave them the wrong number and they inadvertently assume the lack of calls is them being efficient.
lol UAC ftw.
In before "why not just use a Mac" comment /s
LOL, why? XP is sooo much better . Who needs a secure UNIX based OS with 'root' access to run any executable that can do anything... XP has no such feature to get in the way.
Any script or application can read/write ports below 1024 to do anything w/out, again, 'root' access. Who needs the speed of Interprocess Communication sockets when you have DDE and COM compontents that suck even more memory, open even more security holes. Why why why? When will they get it?
!!! Its about the software stupid !!!
I love how arrogant these Apple users are. The military chose something because they felt it was more secure, cost efficient and easy to work with, and STILL the Apple users can't just shut up. Seriously to think you are more intelligent than the United States military because you have a fruit on your computer is just ridiculous. Go edit a movie.
yea I don't necessarily see the military using iLife for flying a UAV.
but back to the linux issue - it seems that the air force goes with an operating system that is commercially supported for the purposes of reliability, and obviously in widespread, standardized use. Why not a commercially supported, secure linux distribution - Suse or RedHat?
Yup, I agree. As a Windows developer I can say that too. Linux and UNIX are way more secure, cost effective, and well documented. Period.
BTW, where are all these UNIX OS X users anyways?
FAIL
@Steve
You're a developer in the same way that I'm the Pope.
And since I was never a member of the Nazi party that means I'm not.
@patriotsn1
I don't why I would even try to argue with you since you are probably 12 or 13, but someone has to say it. you're an idiot.
The military has no business using a mainstream OS. Maybe I've just grownup on too many 80s movies with Unix mainframes. 85% secure is not secure.
The more proprietary their OS and build, the harder it is for Russian and Chinese hackers to interfere and disrupt things. I've used windows most of my life, not because it's secure, it's cheaper and more convenient.
Sorry Steve, but you're a pretty shitty developer if you think that a "UNIX foundation" means anything.
OSX has consistently had a pretty crappy exploit record compared to Vista, and can't even properly randomize libraries (Which is why it went down first in the pwn2own contest)
And if you knew *anything* about the structure of NT, you'd know that it as at least 'as good' as a modern UNIX base. The foundation of the OS is not a problem for anything these days. The problems lie in three things: The users, the default security setup (Which is NOT a problem for businesses and military, because they don't let their users run as admin), and applications.
@billy
Too bad social engineering is the biggest problem they face these days, something every OS is susceptible to.
The great? LOL, more like mio the dumbsss. You are obviously not a developer much less a user. There is reason why M$ is considered an orange class OS and your fanboyism will never change that, too bad. :(
Meanwhile adobe's PS installs the apple communication service in windows, that opens ports for apps to chat left and right.
@billy bob - right claim, wrong reason. patriotsn1 *is* an idiot, not because of any OS argument, but because -
1) they say Mac users can't shut up, but it was actually the troll-bait original comment that started this thread, not a fanboy, and the original troll-bait was the usual straw-man crap ("hey, if I keep implying that all Apple fans are fanboys who can't shut up, then the dills in the Engadget comments section will eventually believe that all Apple fans are fanboys who can't shut up" ... they've been doing that for more than six months and SURPRISE all the dills in here now believe this piece of received wisdom).
2) Just because one person takes the troll-bait and responds, does not make all Apple users arrogant. How would you like to be judged by the absolute worst of the MS trolls or the linux fanboys?
If you want to challenge Steveorevo's comment and disparage them, that's fine - the problem is you asserting that Steveorevo somehow speaks for all Apple fans, and attacking all of us on the basis of one person's comment alone.
I am not arrogant because of what Steveorevo says, in the same way that you are not an uninformed troll just because of what some random MS fanboy says.
When are the heckers going to have a go at this?
Mr Balmer looks like he is in a court-martial.....
Thes marks like the 5th typo in the top 4 comments. Had to get my own in there too. ;-)
they must've been inspired by the _effort's_ of the article. nilay, apostrophes are not for plurals, they are for possessive.
A "super secure" version of XP is nowhere secure enough.
Mythical Creatures - Volume 2
It uses a black screen of death with black text on a black background. Super secure.
For added security it also makes use of write only memory. Write Once Read Never (WORN) memory is the ultimate in security.
Ain't that title an Oxymoron?
Why not sell this to the public sans 72 hour response time...?
They just locked down some security settings. They didn't modify the OS.
The upshot is that now, as their PCs are more consistently configured, they don't have to spend weeks testing security/OS updates before deployment. They can distribute them within a few days.
because a hacker could buy it and find the exploit that exists. Atleast w/ the crapware public version, the hacker has to guess at what backdoor is open for the airforce.
All it means is that the military will upgrade from Windows 2000 to Windows XP for some office building. Probably.
But I think in reality is that it comes down use what is old because all the flaws are known. Let's say they get Win7, instead of XP. Ok that is all nice, but what are the flaws? No one knows yet.
So that means they left 15% of the exploits unblocked? o.O
No, I think the 15% left require physical access and in a lot of cases access to the BIOS. You would have to get through a few Security Forces checkpoints and a number of passkey locks to get to anything sensitive enough for that to be a problem. Just try strolling onto Barksdale for no good reason and see how far you get.
super-secure version of Windows aka Ubuntu 9.04 with Bliss background
At this point, the stability is probably on par :p
Stick to 8.10 for a while. Maybe wait for 9.04
If you're really impatient, an OS X capable machine, while expensive, may be a good idea.
Maybe wait for 9.10**
Great idea having an OS used by the government with its source code laying around for anyone to pick through. I'm sure THAT won't cause any problems...
great idea giving the government an OS whose source code cant be seen.
actually you can get the source code for XP ... you can use it in for educational purposes iirc
for instance while xen (OS virtualization platform) doesn't work with stock XP a university modified XP to run xen ... the code can't be distributed in any manner as far as I now but what this means is that hackers than really wan the code can and will find the code like it or not...
Having your code out in the open and applying quick fixes is the best policy MS attemps to hide thier code and uses *update packs* fact is the updates are probably out of date before they are even applied (I mean new hacks have already beed discovered even without source)
also such fixed don't take that long to apply for instance for Haiku OS (BeOs clone) I recompile all the updates from source and apply them.. takes only a few minutes (like 15) since it doesn't rebuild everything (which takes about 2 hours or so iirc)
@Ignatius
arguably the safest OS is OpenBSD or a well configured Selinux.
Besides, it's likely that some Russian or Chinese cracker already have some of Windows' source anyway: http://news.bbc.co.uk/2/hi/technology/3485545.stm
@Ignatius: Dude, your fanboism is showing!!!
It is secure because everybody can see it and audit it's security...
we're fucked
Microsoft SKYNET??
Excuse me, don't you mean "super secure" and SUPER AWESOME Windows Vista? Maybe they could get them to like it if the just called it Mojave?
How does Vista come in the picture?
Badly.
This would be funny if it they pulled a mojave and gave them windows vista with an xp theme.
They are migrating, douchebag.
You put your full name in the internets and call someone a douchebag? Big balls or little brains, either way, sir, you are a winner.
It's my name. I'm not afraid to be held accountable for what I say.
Besides it's a disposable gmail account so what the hell.
Correction: They're using a standard copy of Windows with some locked down security settings. Anyone can run the same damned thing they do. Try reading the article.
Where Can i pirate this version at??? anyone in the airforce make me an ISO
You want a windows with locked down settings? Why not simply use available utilities to lock down some settings yourself, like autorun for USB devices for starters, and netbios and UPNP broadcasting to the internet and WMP sending unique identifiers and windows search getting a XML from MS's each time you use search andsoforth.
I wonder if that secure XP comes with IE with everything disabled or simply with Firefox+noscript..
The "SS" version of XP. LOL... Looks like a Colonel Klink spearheaded this decision. I'm sure his head IT person Sergeant Schultz will run the operation perfectly.
Funny stuff.
But they didn't go with OSX. So show me your spin for that.
What? You guys want to save money? Shut down the Air Force then, reintegrate air units with the rest of the Armed Forces. You could save at least 50 to 60 billion getting rid of that problematic branch: Overweight/obese soldiers, overbudget programs, and near-complete inactivity in the two major conflicts going on right now.
you seriously did not just make a case for getting rid of the airforce!?
Overweight soldiers and near-inactivity?
I wish I could get my hands on you right now. Inactivity eh? I personally have lost 3 people I know defusing roadside bombs, and seen countless people hurt in combat and industrial accidents. Where did all this occur? In the AOR.
You need to shut the hell up.
So lets see. By your logic providing TACP's, air base security, supplemental EOD, close air support, and flying JSTARS are all a useless function of USAF. Now I'm only naming the few supplemental things AF does for infantry units. I forget how many AFSCs they have, but it covers a lot of ground. Just how would you purpose to roll all these functions into another service. And just who would you merge them with, the Army? The Army is already big enough to the point where they aren't quite sure of all of what they have. As it is we roll into battle with forgotten/underused assets all the time, just how exactly are commanders and their supporting officers supposed to remember all of what they have at their disposal with a branch that huge, with that many capabilities?
You are a part of the same crowd of clowns that have been trying to take the USMC and disassemble it while rolling its functions into the Army. You just can't do it, it's not possible. The arguments for doing it to the Marines is a stretch, trying to do that to the Air Force is beyond logic my friend.
I think you need reexamine you statements... or actually read up on the basic functions of each branch before you begin shooting your mouth off. Let me know when you decide to unfuck yourself and we will talk.
I know, I know, airmen lost their lives in combat. However, it does pale in comparison to the numbers that have been lost by the army and marine corp. Odds are, the airmen lost were pulled from their regular duty. I know when I was in the navy, they were pulling people from ships and shore duty to go to the sandbox. I think they gave a buddy of mine 2 months of basic infantry training and off to the sandbox he went.
The airforce has it easy though...seriously, you have to admit it. airforce=chairforce, generally speaking. I say it with jealousy because I have had to on occasion visit the AF bases and boy, was it nice. You can generally tell how nice it is through the rate of advancement. I was a nuke and my advancement rate was sky high, because the job sucked and people were getting out as soon as their 6 year obligation was up. Airforce? You had to wait till someone retired or died because no one wanted to leave.
@JKswiss:
I'm sure most Airmen would concede to that. I think it is just the nature of their branch that makes the work different. USAF is centered around a lot of technical and high maintenance equipment. Most of the AFSC center around maintaining all those systems or operating them. The only people who really run a whole lot of risks are Security Forces, CCTs, PJs, etc. USAFs brand of war is usually information warfare, their A-2 shops usually pass good information from what I understand.
As an Airmen in the AOR currently... (yes checking engadget daily is a perk of the AF) We do not see the war the same as a Soldier or a Marine. If you were to get rid of us those guys on the ground would be in a world of hurt. Also working 12-14 hour days 6 or 7 days a week isn't exactly my idea of relaxing... Yeah I haven't been shot at but with the general instability in the region my heart still skips a few beats every time they test the Air Raid sirens. So while I am sure you didn't intend to be derogatory towards the Air Force and our mission please realize that if you haven't been there you can't know what it is like.
Yes. Let's fire 80% of the Air Force. All of the officers hold college degrees and would command a boatload more money in economy. Wouldn't that be great for a jobs market.
The rest of the "grunts" either hold a college degree or credits that would get them one. More job seekers.
Great plan. Why not just close down all of the security contracts the US sells out to pay for our government too. Don't you think you're smart now? You know who fills our security contracts? Our military and quite a few of them are filled by the Air Force.
(not a military member, just hate idiots)
Turning the Airforce back into the Army Air Corps would help us with CAS coordination. Mabe we could actually get an aircraft to drop ordnance when we are getting shot at.
Right now as a foot soldier in Afghanistan I have no faith in Airforce CAS. I do however know that the Apaches, and Kiawas will be there when I need them -- why, they are Army and we can actually communicate with them.
Whoa there. Somebody needs to think before they speak.
Yes...please do that.
So then hackers will invade the cyberspace.
You wouldn't have no GPS satelittes
You wouldn't have the missile sites that we obtain
I mean...they're called the Air Force, but it's idiots like you that only think "OMG, they just supposed to fly planes"
Get a clue, only an officer can become a pilot in the first place.
And without the Air Force alot of things would be closed down.
You do know NASA is a part of the Air Force...right???
Those planes that are used...the Air Force test them...
Next time....think before you type.
You'll look like less of a douchebag.
Why the eff are they even using that crappy OS...?
...Games?
Ah Flight Simulator is probably mandatory on every computer. Perhaps they get some sort of a discount from Mr Ball-mer himself? Or they just like malfunctioning computers and annoying anti-virus software... I'm sure there is a fetish for that.
Chinese & Russian hackers are probably laughing their asses off right about now!
bet ur arse that they arent using internet explorer
Bet your arse they are.
I know for a fact they are. It's locked down like a mofo, but they're using it.
Just an FYI, you can get the same exact "security" tweaks that are in this XP build (and actually, for most of the popular OS's) directly from the NSA.. see here:
http://www.nsa.gov/ia/guidance/security_configuration_guides/operating_systems.shtml
Why didn't they just make their own Windows image?
I guess the USAF didn't read about the French military problems...
Windows machines - fail
Mac OS machine still up...
Oh, Well...
To Serve and Protect is the LAPD motto
Air Farce is "Right Man for the Right Job" = in this case Ballmer is giving somebody a "job" but not sure who.
apple's motto is "no refunds"
i didnt see anything like that.... link?
Ahem. References?
Also, since when did the French military ever equate to ours in the last, oh, 50 years or so? Sure we make some mistakes, but last I checked the main species staffing most positions were humans, we tend to make a few mistakes from time to time (unless of course you're a Marine, in which case it's not an error, just a tactical decision;) Just thought I'd pass that piece of info along for you.
Errare humanum est.
Ah, someone finally mentions Mac OS!
We have a winner! or is it spelt whiner
Yea, because Mac's are known for their server capabilities.
LOL!! French military + problems? They have no problems ... just surrender at first opportunity
Funny thing is that french commandos are actually some of the most brutal in the world, actively commiting acts of terrorism and doing stuff much worse than what's going on in Guantanamo...
Not to justify them or Guantanamo, just saying the french aren't really pussies. You guys have to remember, only the top ranks decide to surrender, and they may have very well been Nazi simpathizers.
I love how the Airforce guys are all standing perfect, with their hands crossed, and then all the Microsoft guys are just sorta standing however they want... and Balmer looks REALLY uncomfortable in that pic...
we call that an ad hominem argument ... that is ... when you have no facts, when logic is not on your side ... attack the figure. Attack their looks, attack their demeanor. Just stay away from the fact the USAF has chosen XP as their operating system of choice. That's so ... non-applet.
that's the 'friendly'/welcoming posture. Had their hands crossed at their back, it would have been a defensive posture, a more appropriate one for this occasion me thinks...