What's Wrong With Microsoft Security? By David Raikow, Sm@rt Reseller January 28, 2000 12:58 PM PT URL: http://www.zdnet.com/sr/stories/column/0,4712,2429536,00.html "Microsoft's latest security glitch" has become a cliche. But it doesn't have to be. >From Melissa to BubbleBoy to the ODBC driver bug to the Hotmail fiasco, security problems with Microsoft products and technologies have come to be accepted as a given. But why? Microsoft has plenty of programmers, resources and expertise. The company certainly has more money than you can shake a stick at. So why does Microsoft keep dropping the ball? Microsoft employees are quick to claim that it's all an illusion--a case of an unfair reputation bolstered by a hostile press. Moreover, some say the wide deployment of Microsoft products makes them an extremely attractive target for hackers, white-hat and black-hat alike. There's a kernel of truth in these arguments, but not much more. Microsoft has issued 16 security alerts since the beginning of December alone, regarding its own products. Beyond these are even more alerts issued by third parties about Microsoft products and technologies. That is not acceptable. Microsoft's enviable position has provided the company with both the resources and the responsibility to make sure that its products can stand up to those hordes of hackers. My personal experience is that Microsoft's security people are, on the whole, top-notch, bright folks who know their business. Overworked, certainly; at the recent RSA 2000 security conference, Microsoft stated it had assigned a total of 15 programmers to security-test the 30-million-plus lines of code in Windows 2000. It really comes down to a question of philosophy. Microsoft always has viewed its software in terms of feature lists. To Microsoft, innovation is about adding new features and finding ways to interconnect them. In Microsoft's eyes, the best product is the one with the longest feature list. The problem is that security is not a feature. It is, rather, a function of how features respond to unexpected circumstances or combinations. Both Melissa and BubbleBoy, for example, erupted when virus writers found ways to combine features from Outlook and Internet Explorer that Microsoft programmers did not foresee. It follows that adding to a feature list greatly multiplies the potential for security problems, and tightly integrating those features multiplies that potential exponentially. Microsoft management has decided to treat its security problems as a matter of public relations, rather than as a technical issue. Instead of shipping NT with risky features disabled and leaving it up to sysadmins to turn on the services they need, Microsoft is shipping NT/Windows 2000 wide open, blaming problems on "misconfiguration." Instead of openly collaborating with the community of white-hat hackers that constantly seek out bugs, Microsoft ignores them whenever possible, often blaming them for problems it cannot ignore. So what can Microsoft do? First and foremost, the company needs to stop treating security as just another feature. Security testing and development at Microsoft needs a dramatic increase in resources, and specialists need to be involved--to some degree--at every level of feature development. Maybe they could be granted some kind of veto power over some features that are just more trouble than they will ever be worth. (Let's face it folks--Active Scripting has got to go.) It doesn't matter how many times we hear, "Microsoft cares about security." The company needs to be open, take responsibility for problems, and move on. If a vulnerability stems from a misconfiguration--don't blame users--make proper configuration easier. Reach out to the white-hat hacker community and enlist their help. Come on, Microsoft. We all know that security's tough, and no one's ever going to be perfect. That doesn't mean you can't do a lot better. =========================================================================== I Made Wiryana (0521-106 5328) Universitas Gunadarma - Indonesia Rechnernetze und Verteilte Systeme http://nakula.rvs.uni-bielefeld.de/made Universitaet Bielelfeld Check my e-zine : [EMAIL PROTECTED] http://nakula.rvs.uni-bielefeld.de/majalah =========================================================================== * Gunadarma Mailing List ----------------------------------------------- * Archives : http://milis-archives.gunadarma.ac.id * Langganan : Kirim Email kosong ke [EMAIL PROTECTED] * Berhenti : Kirim Email kosong ke [EMAIL PROTECTED] * Administrator: [EMAIL PROTECTED]
