Next, the NTLMv2 authentication protocol is on by default and vulnerable to relay attacks and offline password guessing attacks. Plus: pass-the-hash vulnerable. Huge problem in corporate networks.
I'd argue the broadcast domain name resolution protocols like NBNS or mDNS are unsafe as well.
Disclaimer: if you were just talking about Windows on your home desktop PC, then yeah nevermind.
Just scanning on the things they are proud to list at https://learn.microsoft.com/en-us/windows/whats-new/windows-..., I'd be worried about Teams, Windows 365, and Widgets. I'd also be worried about all trial software that is on the machine. I could not find a list of that, though.
And again, this is not unique to Windows. It used to be OEM bloat that was added to all things. In linux land, it would have been all of the "power tools" included by default.
Generally users in most enterprises are going to need instant messaging and online meeting tools, so if it's not Teams then it will be something else with an equivalent attack surface area. Windows 365 appears to be highly secure.
I'm not trying to defend Microsoft here. They have had many security flaws and there will be more to come. It's just not clear whether the alternatives are significantly better.
Yes, this is common. You are generally given the option at install how "minimal" you wish to go (do you even want a GUI installed, etc). These are often listed on the distributions website.
For example here is a few from Arch:
- Base (bare minimum) install: https://archlinux.org/packages/core/any/base/
- Base-devel (what you need to run makepkg): https://archlinux.org/packages/core/any/base-devel/
I'd expect most attacks are still of the "what is your password" variety. That along with a giant shared drive that everyone just dumps everything into.
And I don't mean this as an offensive against just Microsoft. They are/were somewhat unique in the success they had with embrace/extend. That said, the blame almost as surely rests on typical "growth at all costs" mental model that is modern business.