When it comes to reliability and security, few people will argue that personal computing is at its peak. And it really doesn't matter what operating system or application software a computer runs; there will always be software flaws with the potential to cause problems.
Connect a few million PCs installed with buggy, unmaintained software to a network or the Internet, and you've got a much larger problem. Corporate networks protected by firewalls help, but even the best firewall can't stop problems from spreading inside networks.
For areas where high-security computer access is a necessity, a centralised approach to access control and authorisation may be the solution.
Many will argue that the mainframe era, despite the relatively simple character-based user interface, was a better paradigm for secure and reliable computing. While centralised, session-based computing that uses character terminals is somewhat dated, it remains stubbornly reliable, particularly when security is a more important factor than usability.
However, thin client computing makes it possible to combine the best of the mainframe terminal approach with the graphical interface required by modern software. You can apply thin client concepts to regular computers running specific software that provides a remote graphical desktop on a centralised system. A number of different methods and protocols are available, and the thin client concept, which uses session-based graphical desktops, offers corporations both security and usability.
Because most wide-scale security incidents occur on Windows machines, Windows thin clients could play an important role in an organization's network. Originally developed to provide remote Windows access, thin clients' protocols and concepts can help companies greatly improve Windows security.
However, I'm not advocating the wholesale replacement of Windows PCs with thin clients. What I am suggesting is that thin clients can improve overall security for specific purposes, especially when it comes to desktop consistency.
Under Windows, thin clients access a central server for multiple user sessions, and they generally use Citrix MetaFrame or Windows Terminal Services. These products provide multiple Windows sessions from one central system, just like the mainframe paradigm.
The improvement in overall security comes from not having to constantly maintain a network of hundreds of Windows-based PCs. Instead, the security focus is now on the main Windows servers that provide the sessions.
Of course, there are significant drawbacks to session-based remote desktops, most notably speed. Even across a fast network, remote desktop access is orders of magnitude slower than a PC. Therefore, I would argue that thin clients only make sense in specific situations, particularly when security and access control are essential (and, of course, when someone needs to access a Windows desktop from a remote location).
However, remote Windows desktops also offer benefits in addition to boosting security. It's generally a good practice to have a standardised, reproducible desktop in a corporation, and overall costs of security are generally lower when there are fewer computers to maintain.
Of course, it's typically not practical to run an entire corporation on thin clients. Deciding where and how to implement thin clients is something that each organization must figure out, but security and access control should be the deciding factors.






Talkback
Your article was right on target! Thin clients do substantially reduce the security threat to networks. However, they suffer from the fact that they, too, have some embedded software that can become infected or may need to be updated. Diskless thin client technology, on the other hand, removes the risk altogether by removing ALL embedded software from the workstations. The workstations power up via a server. Our company, Symbio Technologies, is an innovator in this field. Our products are making diskless thin client technology easy to install and manage. If you're interested in learning more about our work, please visit us at http://www.symbio-technologies.com or email us at support@symbio-technologies.com.
Diane Romm
VP of Marketing
Symbio Technologies
134 North Avenue Suites E and F
New Rochelle, NY 10801
USA
Tel: 914-576-1205
Fax: 914-576-0944
Also don't forget to calculate in the cost of downtime. Often on paper Thin Clients look great. Until you take into account the cost of, say, a company wide downtime for, say, 4 hours once every two years or so, because one of the critical and centralized systems went down. And that's just one aspect often forgotten by those that are blinded by the great looking figures on a piece of (sales) paper.
Another thing often overlooked are the benefits of keeping your options open. How many options do you have left when almost everything is Thin Client versus other scenario's. Now what if for some reason or another you want to gid rid of your Thin Client solution in just a few years from now? Ever took into account the costs needed to undo your choice? Because that's a risk investment your company might be interested in to know about.