Could thin clients cure your security headaches?

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS

When it comes to reliability and security, few people will argue that personal computing is at its peak. And it really doesn't matter what operating system or application software a computer runs; there will always be software flaws with the potential to cause problems.

Connect a few million PCs installed with buggy, unmaintained software to a network or the Internet, and you've got a much larger problem. Corporate networks protected by firewalls help, but even the best firewall can't stop problems from spreading inside networks.

For areas where high-security computer access is a necessity, a centralised approach to access control and authorisation may be the solution.

Many will argue that the mainframe era, despite the relatively simple character-based user interface, was a better paradigm for secure and reliable computing. While centralised, session-based computing that uses character terminals is somewhat dated, it remains stubbornly reliable, particularly when security is a more important factor than usability.

However, thin client computing makes it possible to combine the best of the mainframe terminal approach with the graphical interface required by modern software. You can apply thin client concepts to regular computers running specific software that provides a remote graphical desktop on a centralised system. A number of different methods and protocols are available, and the thin client concept, which uses session-based graphical desktops, offers corporations both security and usability.

Because most wide-scale security incidents occur on Windows machines, Windows thin clients could play an important role in an organization's network. Originally developed to provide remote Windows access, thin clients' protocols and concepts can help companies greatly improve Windows security.

However, I'm not advocating the wholesale replacement of Windows PCs with thin clients. What I am suggesting is that thin clients can improve overall security for specific purposes, especially when it comes to desktop consistency.

Under Windows, thin clients access a central server for multiple user sessions, and they generally use Citrix MetaFrame or Windows Terminal Services. These products provide multiple Windows sessions from one central system, just like the mainframe paradigm.

The improvement in overall security comes from not having to constantly maintain a network of hundreds of Windows-based PCs. Instead, the security focus is now on the main Windows servers that provide the sessions.

Of course, there are significant drawbacks to session-based remote desktops, most notably speed. Even across a fast network, remote desktop access is orders of magnitude slower than a PC. Therefore, I would argue that thin clients only make sense in specific situations, particularly when security and access control are essential (and, of course, when someone needs to access a Windows desktop from a remote location).

However, remote Windows desktops also offer benefits in addition to boosting security. It's generally a good practice to have a standardised, reproducible desktop in a corporation, and overall costs of security are generally lower when there are fewer computers to maintain.

Of course, it's typically not practical to run an entire corporation on thin clients. Deciding where and how to implement thin clients is something that each organization must figure out, but security and access control should be the deciding factors.

Talkback

Your article was right on target! Thin clients do substantially reduce the security threat to networks. However, they suffer from the fact that they, too, have some embedded software that can become infected or may need to be updated. Diskless thin client technology, on the other hand, removes the risk altogether by removing ALL embedded software from the workstations. The workstations power up via a server. Our company, Symbio Technologies, is an innovator in this field. Our products are making diskless thin client technology easy to install and manage. If you're interested in learning more about our work, please visit us at http://www.symbio-technologies.com or email us at support@symbio-technologies.com.

Diane Romm
VP of Marketing
Symbio Technologies
134 North Avenue Suites E and F
New Rochelle, NY 10801
USA

Tel: 914-576-1205
Fax: 914-576-0944

via Facebook 29 January, 2005 18:40
Reply

Also don't forget to calculate in the cost of downtime. Often on paper Thin Clients look great. Until you take into account the cost of, say, a company wide downtime for, say, 4 hours once every two years or so, because one of the critical and centralized systems went down. And that's just one aspect often forgotten by those that are blinded by the great looking figures on a piece of (sales) paper.

Another thing often overlooked are the benefits of keeping your options open. How many options do you have left when almost everything is Thin Client versus other scenario's. Now what if for some reason or another you want to gid rid of your Thin Client solution in just a few years from now? Ever took into account the costs needed to undo your choice? Because that's a risk investment your company might be interested in to know about.

via Facebook 5 November, 2005 00:06
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

8 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

16 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

18 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

18 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

22 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

24 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

24 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint