What's Wrong With Microsoft Security?
By David Raikow, Sm@rt Reseller
January 28, 2000 12:58 PM PT
URL: http://www.zdnet.com/sr/stories/column/0,4712,2429536,00.html

"Microsoft's latest security glitch" has become a cliche. But it doesn't
have to be.

>From Melissa to BubbleBoy to the ODBC driver bug to the Hotmail fiasco,
security problems with Microsoft products and technologies have come to be
accepted as a given. But why? Microsoft has plenty of programmers,
resources and expertise. The company certainly has more money than you can
shake a stick at. So why does Microsoft keep dropping the ball?

Microsoft employees are quick to claim that it's all an illusion--a case
of an unfair reputation bolstered by a hostile press. Moreover, some say
the wide deployment of Microsoft products makes them an extremely
attractive target for hackers, white-hat and black-hat alike.

There's a kernel of truth in these arguments, but not much more. Microsoft
has issued 16 security alerts since the beginning of December alone,
regarding its own products. Beyond these are even more alerts issued by
third parties about Microsoft products and technologies.

That is not acceptable. Microsoft's enviable position has provided the
company with both the resources and the responsibility to make sure that
its products can stand up to those hordes of hackers.

My personal experience is that Microsoft's security people are, on the
whole, top-notch, bright folks who know their business. Overworked,
certainly; at the recent RSA 2000 security conference, Microsoft stated it
had assigned a total of 15 programmers to security-test the
30-million-plus lines of code in Windows 2000.

It really comes down to a question of philosophy. Microsoft always has
viewed its software in terms of feature lists. To Microsoft, innovation is
about adding new features and finding ways to interconnect them. In
Microsoft's eyes, the best product is the one with the longest feature
list.

The problem is that security is not a feature. It is, rather, a function
of how features respond to unexpected circumstances or combinations. Both
Melissa and BubbleBoy, for example, erupted when virus writers found ways
to combine features from Outlook and Internet Explorer that Microsoft
programmers did not foresee. It follows that adding to a feature list
greatly multiplies the potential for security problems, and tightly
integrating those features multiplies that potential exponentially.

Microsoft management has decided to treat its security problems as a
matter of public relations, rather than as a technical issue. Instead of
shipping NT with risky features disabled and leaving it up to sysadmins to
turn on the services they need, Microsoft is shipping NT/Windows 2000 wide
open, blaming problems on "misconfiguration." Instead of openly
collaborating with the community of white-hat hackers that constantly seek
out bugs, Microsoft ignores them whenever possible, often blaming them for
problems it cannot ignore.

So what can Microsoft do? First and foremost, the company needs to stop
treating security as just another feature. Security testing and
development at Microsoft needs a dramatic increase in resources, and
specialists need to be involved--to some degree--at every level of feature
development. Maybe they could be granted some kind of veto power over some
features that are just more trouble than they will ever be worth. (Let's
face it folks--Active Scripting has got to go.)

It doesn't matter how many times we hear, "Microsoft cares about
security." The company needs to be open, take responsibility for problems,
and move on. If a vulnerability stems from a misconfiguration--don't blame
users--make proper configuration easier. Reach out to the white-hat hacker
community and enlist their help.

Come on, Microsoft. We all know that security's tough, and no one's ever
going to be perfect. That doesn't mean you can't do a lot better.


===========================================================================
I Made Wiryana (0521-106 5328)            Universitas Gunadarma - Indonesia
Rechnernetze und Verteilte Systeme  http://nakula.rvs.uni-bielefeld.de/made
Universitaet Bielelfeld                                   Check my e-zine :
[EMAIL PROTECTED]    http://nakula.rvs.uni-bielefeld.de/majalah
===========================================================================


* Gunadarma Mailing List -----------------------------------------------
* Archives     : http://milis-archives.gunadarma.ac.id
* Langganan    : Kirim Email kosong ke [EMAIL PROTECTED]
* Berhenti     : Kirim Email kosong ke [EMAIL PROTECTED]
* Administrator: [EMAIL PROTECTED]

Kirim email ke